π¨ CVE-2026-81402
The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lead to remote code execution.
π@cveNotify
The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lead to remote code execution.
π@cveNotify
WPScan
DS Ad Rotator <= 0.8 - Unauthenticated Arbitrary File Upload
See details on DS Ad Rotator <= 0.8 - Unauthenticated Arbitrary File Upload CVE 2026-81402. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81429
The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a crafted template via a forged request that results in Stored Cross-Site Scripting executed in the administrator's session.
π@cveNotify
The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a crafted template via a forged request that results in Stored Cross-Site Scripting executed in the administrator's session.
π@cveNotify
WPScan
Export & Import WPBakery Page Builder <= 1.0.2 - Stored XSS via CSRF
See details on Export & Import WPBakery Page Builder <= 1.0.2 - Stored XSS via CSRF CVE 2026-81429. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81742
The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any user visiting the site.
π@cveNotify
The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any user visiting the site.
π@cveNotify
WPScan
BE REST Endpoints <= 1.0.0 - Unauthenticated Stored XSS and Widget Manipulation
See details on BE REST Endpoints <= 1.0.0 - Unauthenticated Stored XSS and Widget Manipulation CVE 2026-81742. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-82845
The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the same issue is reachable without an account and yields an arbitrary file write rather than code execution.
π@cveNotify
The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the same issue is reachable without an account and yields an arbitrary file write rather than code execution.
π@cveNotify
WPScan
Masteriyo LMS < 3.4.1 - Subscriber+ PHP Object Injection
See details on Masteriyo LMS < 3.4.1 - Subscriber+ PHP Object Injection CVE 2026-82845. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-82847
The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators.
π@cveNotify
The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators.
π@cveNotify
WPScan
Masteriyo LMS < 3.4.1 - Instructor+ Stored XSS via Course Highlights
See details on Masteriyo LMS < 3.4.1 - Instructor+ Stored XSS via Course Highlights CVE 2026-82847. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-83532
The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.
π@cveNotify
The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.
π@cveNotify
WPScan
Custom Menu Wizard <= 3.3.1 - Contributor+ Stored XSS via Shortcode Attributes
See details on Custom Menu Wizard <= 3.3.1 - Contributor+ Stored XSS via Shortcode Attributes CVE 2026-83532. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-84023
The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in privileged user into visiting a crafted page.
π@cveNotify
The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in privileged user into visiting a crafted page.
π@cveNotify
WPScan
BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Taxonomy Term Modification via CSRF
See details on BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Taxonomy Term Modification via CSRF CVE 2026-84023. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-84024
The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration by tricking a logged-in administrator into visiting a crafted page.
π@cveNotify
The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration by tricking a logged-in administrator into visiting a crafted page.
π@cveNotify
WPScan
BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Meta Field Configuration Update via CSRF
See details on BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Meta Field Configuration Update via CSRF CVE 2026-84024. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-84025
The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product information, including protected downloadable file URLs and private product metadata.
π@cveNotify
The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product information, including protected downloadable file URLs and private product metadata.
π@cveNotify
WPScan
BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosureβ¦
See details on BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOR CVE 2026-84025. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-84047
The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
π@cveNotify
The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
π@cveNotify
WPScan
Album Cover Finder <= 0.7.0 - Unauthenticated SQLi via and_action
See details on Album Cover Finder <= 0.7.0 - Unauthenticated SQLi via and_action CVE 2026-84047. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-84099
The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.
π@cveNotify
The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.
π@cveNotify
WPScan
IDB Ecommerce (wpStoreCart 5) <= 5.0.7 - Unauthenticated PHP Object Injection via bundled wpsc-membership-pro paypal.php
See details on IDB Ecommerce (wpStoreCart 5) <= 5.0.7 - Unauthenticated PHP Object Injection via bundled wpsc-membership-pro paypal.php CVE 2026-84099. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-84171
The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.
π@cveNotify
The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.
π@cveNotify
WPScan
WP Images Upload on Piclect <= 1.0 - Unauthenticated Arbitrary File Upload
See details on WP Images Upload on Piclect <= 1.0 - Unauthenticated Arbitrary File Upload CVE 2026-84171. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-85681
The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unauthenticated attackers to overwrite any of the site's options. On a single site installation this leads to a full takeover, as registration can be enabled with a default role of administrator.
π@cveNotify
The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unauthenticated attackers to overwrite any of the site's options. On a single site installation this leads to a full takeover, as registration can be enabled with a default role of administrator.
π@cveNotify
WPScan
WP Component <= 2.2.4 - Unauthenticated Privilege Escalation via Arbitrary Blog Option Update
See details on WP Component <= 2.2.4 - Unauthenticated Privilege Escalation via Arbitrary Blog Option Update CVE 2026-85681. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-86790
The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
π@cveNotify
The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
π@cveNotify
WPScan
WP Highlight Box <= 1.0 - Contributor+ Stored XSS via highlight-box Shortcode
See details on WP Highlight Box <= 1.0 - Contributor+ Stored XSS via highlight-box Shortcode CVE 2026-86790. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-87759
The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to grant themselves the administrator role on a multisite installation.
π@cveNotify
The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to grant themselves the administrator role on a multisite installation.
π@cveNotify
WPScan
Add User Autocomplete < 1.2 - Subscriber+ Privilege Escalation
See details on Add User Autocomplete < 1.2 - Subscriber+ Privilege Escalation CVE 2026-87759. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-87797
The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber to overwrite private notes on records belonging to other users.
π@cveNotify
The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber to overwrite private notes on records belonging to other users.
π@cveNotify
WPScan
Client Invoicing by Sprout Invoices < 20.8.16 - Subscriber+ Private Note Overwrite via si_edit_private_note
See details on Client Invoicing by Sprout Invoices < 20.8.16 - Subscriber+ Private Note Overwrite via si_edit_private_note CVE 2026-87797. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-87842
The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.
π@cveNotify
The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.
π@cveNotify
WPScan
Zonify < 1.0.5 - Unauthenticated Account Login Token Disclosure
See details on Zonify < 1.0.5 - Unauthenticated Account Login Token Disclosure CVE 2026-87842. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-87888
The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing WordPress plugin before 3.5.7's settings page.
π@cveNotify
The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing WordPress plugin before 3.5.7's settings page.
π@cveNotify
WPScan
YayPricing < 3.5.7 - Subscriber+ Stored XSS via save_page_data REST Route
See details on YayPricing < 3.5.7 - Subscriber+ Stored XSS via save_page_data REST Route CVE 2026-87888. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-87891
The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner intended to keep closed.
π@cveNotify
The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner intended to keep closed.
π@cveNotify
WPScan
Rox Appointment Booking < 1.2.0 - Unauthenticated Holiday Schedule Modification via REST API
See details on Rox Appointment Booking < 1.2.0 - Unauthenticated Holiday Schedule Modification via REST API CVE 2026-87891. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-87892
The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to bypass the site's configured payment-method restrictions.
π@cveNotify
The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to bypass the site's configured payment-method restrictions.
π@cveNotify
WPScan
Rox Appointment Booking < 1.2.0 - Unauthenticated Price Manipulation and Payment Method Restriction Bypass
See details on Rox Appointment Booking < 1.2.0 - Unauthenticated Price Manipulation and Payment Method Restriction Bypass CVE 2026-87892. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-87894
The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any customer's name, email, phone, booking details and payment status by enumerating that identifier.
π@cveNotify
The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any customer's name, email, phone, booking details and payment status by enumerating that identifier.
π@cveNotify
WPScan
Rox Appointment Booking 1.0.9 - 1.2.2 - Unauthenticated Customer PII Disclosure via IDOR
See details on Rox Appointment Booking 1.0.9 - 1.2.2 - Unauthenticated Customer PII Disclosure via IDOR CVE 2026-87894. View the latest Plugin Vulnerabilities on WPScan.