🚨 CVE-2026-84046
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validate a user-supplied URL before fetching it server-side, allowing users with the subscriber role and above to make the server issue requests to internal addresses.
🎖@cveNotify
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validate a user-supplied URL before fetching it server-side, allowing users with the subscriber role and above to make the server issue requests to internal addresses.
🎖@cveNotify
WPScan
Directorist < 8.9.5 - Subscriber+ SSRF via Avatar URL
See details on Directorist < 8.9.5 - Subscriber+ SSRF via Avatar URL CVE 2026-84046. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84098
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated attackers with Subscriber-level access and above to delete arbitrary listings, including ones belonging to other users.
This is an incomplete fix of CVE-2023-1889 / CVE-2023-35052: a separate, unaddressed listing-deletion path allows the same impact, from at least version 3.1.0 through the current release.
🎖@cveNotify
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated attackers with Subscriber-level access and above to delete arbitrary listings, including ones belonging to other users.
This is an incomplete fix of CVE-2023-1889 / CVE-2023-35052: a separate, unaddressed listing-deletion path allows the same impact, from at least version 3.1.0 through the current release.
🎖@cveNotify
WPScan
Directorist 3.1.0 - 8.9.4 - Subscriber+ Arbitrary Listing Deletion via remove_listing
See details on Directorist 3.1.0 - 8.9.4 - Subscriber+ Arbitrary Listing Deletion via remove_listing CVE 2026-84098. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84150
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not verify that the target user of a REST route matches the authenticated caller before reading and modifying that user's saved favorites, allowing any authenticated user with subscriber-level access to view and alter another user's favorites.
🎖@cveNotify
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not verify that the target user of a REST route matches the authenticated caller before reading and modifying that user's saved favorites, allowing any authenticated user with subscriber-level access to view and alter another user's favorites.
🎖@cveNotify
WPScan
Directorist < 8.9.5 - Subscriber+ Cross-User Favorites Read and Write via REST Favorites Endpoint
See details on Directorist < 8.9.5 - Subscriber+ Cross-User Favorites Read and Write via REST Favorites Endpoint CVE 2026-84150. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84741
The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the contents of records that have never been published.
🎖@cveNotify
The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the contents of records that have never been published.
🎖@cveNotify
WPScan
The Events Calendar 4.5 - 6.17.4.1 - Unauthenticated Non-Public Venue and Organizer Disclosure via REST API
See details on The Events Calendar 4.5 - 6.17.4.1 - Unauthenticated Non-Public Venue and Organizer Disclosure via REST API CVE 2026-84741. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84742
The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, allowing users with a role that cannot normally publish, such as contributor, to publish content directly and bypass editorial review.
🎖@cveNotify
The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, allowing users with a role that cannot normally publish, such as contributor, to publish content directly and bypass editorial review.
🎖@cveNotify
WPScan
The Events Calendar 6.15.0 - 6.17.4.1 - Contributor+ Content Publication via TEC V1 REST API
See details on The Events Calendar 6.15.0 - 6.17.4.1 - Contributor+ Content Publication via TEC V1 REST API CVE 2026-84742. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84743
The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify, unpublish, trash and take ownership of records belonging to other users, including administrators.
🎖@cveNotify
The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify, unpublish, trash and take ownership of records belonging to other users, including administrators.
🎖@cveNotify
WPScan
The Events Calendar 6.15.16.1 - 6.17.4.1 - Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug…
See details on The Events Calendar 6.15.16.1 - 6.17.4.1 - Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug REST Routes CVE 2026-84743. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-85006
The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an HTML attribute, allowing users with Contributor-level access and above to inject event-handler attributes that execute JavaScript in the browser of anyone who views the page, including higher-privileged users reviewing the content, even though such users do not hold the unfiltered_html capability.
🎖@cveNotify
The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an HTML attribute, allowing users with Contributor-level access and above to inject event-handler attributes that execute JavaScript in the browser of anyone who views the page, including higher-privileged users reviewing the content, even though such users do not hold the unfiltered_html capability.
🎖@cveNotify
WPScan
Happy Addons for Elementor < 3.50.0 - Contributor+ Stored XSS via Creative Button Widget
See details on Happy Addons for Elementor < 3.50.0 - Contributor+ Stored XSS via Creative Button Widget CVE 2026-85006. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-86602
The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the full content of unpublished recipes.
🎖@cveNotify
The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the full content of unpublished recipes.
🎖@cveNotify
WPScan
WP Recipe Maker 10.3.0 - 10.8.1 - Subscriber+ Draft and Private Recipe Content Disclosure via wprm_shortcode_preview
See details on WP Recipe Maker 10.3.0 - 10.8.1 - Subscriber+ Draft and Private Recipe Content Disclosure via wprm_shortcode_preview CVE 2026-86602. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-86603
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists.
🎖@cveNotify
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists.
🎖@cveNotify
WPScan
WP Recipe Maker < 10.8.2 - Subscriber+ Non-Public List Title Disclosure via wprm_search_lists
See details on WP Recipe Maker < 10.8.2 - Subscriber+ Non-Public List Title Disclosure via wprm_search_lists CVE 2026-86603. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-86608
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what that route stores, allowing unauthenticated users to write unlimited data into any user's metadata and to permanently prevent that account, including an administrator's, from loading.
🎖@cveNotify
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what that route stores, allowing unauthenticated users to write unlimited data into any user's metadata and to permanently prevent that account, including an administrator's, from loading.
🎖@cveNotify
WPScan
WP Recipe Maker 9.8.0 - 10.8.1 - Unauthenticated DoS via Unbounded User Meta Insertion
See details on WP Recipe Maker 9.8.0 - 10.8.1 - Unauthenticated DoS via Unbounded User Meta Insertion CVE 2026-86608. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-86783
The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose the custom field key names of arbitrary posts, including private, draft, pending, scheduled and password-protected posts.
🎖@cveNotify
The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose the custom field key names of arbitrary posts, including private, draft, pending, scheduled and password-protected posts.
🎖@cveNotify
WPScan
PostX < 5.0.41 - Unauthenticated Custom Field Key Disclosure via REST API
See details on PostX < 5.0.41 - Unauthenticated Custom Field Key Disclosure via REST API CVE 2026-86783. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-86785
The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its REST API endpoints, allowing unauthenticated users to update Social Commerce for WooCommerce WordPress plugin through 2.5.4 configuration and product synchronisation state.
🎖@cveNotify
The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its REST API endpoints, allowing unauthenticated users to update Social Commerce for WooCommerce WordPress plugin through 2.5.4 configuration and product synchronisation state.
🎖@cveNotify
WPScan
Social Commerce for WooCommerce <= 2.5.4 - Unauthenticated Plugin Option and Product Sync Status Update
See details on Social Commerce for WooCommerce <= 2.5.4 - Unauthenticated Plugin Option and Product Sync Status Update CVE 2026-86785. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-86842
The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flipbook management actions, allowing users with Author-level access and above to delete other users' flipbook content and overwrite administrator-only global settings, which can be leveraged to store JavaScript that executes in the context of any visitor or administrator viewing the site.
🎖@cveNotify
The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flipbook management actions, allowing users with Author-level access and above to delete other users' flipbook content and overwrite administrator-only global settings, which can be leveraged to store JavaScript that executes in the context of any visitor or administrator viewing the site.
🎖@cveNotify
WPScan
Real3D Flipbook Lite < 5.4 - Author+ Content Deletion and Stored XSS via Global Settings Overwrite
See details on Real3D Flipbook Lite < 5.4 - Author+ Content Deletion and Stored XSS via Global Settings Overwrite CVE 2026-86842. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-87069
The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction of one of its admin screens, and that construction happens on every wp-admin request for any logged-in user. Any authenticated user, including a Subscriber with no permissions in the Forminator Forms WordPress plugin before 1.57.2.1, can therefore rewrite the saved field configuration of any form on the site, including a live payment form.
🎖@cveNotify
The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction of one of its admin screens, and that construction happens on every wp-admin request for any logged-in user. Any authenticated user, including a Subscriber with no permissions in the Forminator Forms WordPress plugin before 1.57.2.1, can therefore rewrite the saved field configuration of any form on the site, including a live payment form.
🎖@cveNotify
WPScan
Forminator Forms < 1.57.2.1 - Subscriber+ Form Stripe Field Migration via migrate_stripe
See details on Forminator Forms < 1.57.2.1 - Subscriber+ Form Stripe Field Migration via migrate_stripe CVE 2026-87069. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-87074
The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail configuration to any address, carrying a link of their choosing inside the site's own template. The token that authorises the send is handed to the anonymous caller by the Forminator Forms WordPress plugin before 1.57.2.1 itself and can be replayed without limit.
🎖@cveNotify
The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail configuration to any address, carrying a link of their choosing inside the site's own template. The token that authorises the send is handed to the anonymous caller by the Forminator Forms WordPress plugin before 1.57.2.1 itself and can be replayed without limit.
🎖@cveNotify
WPScan
Forminator Forms < 1.57.2.1 - Unauthenticated Arbitrary Recipient Email Sending with Attacker-Controlled Link
See details on Forminator Forms < 1.57.2.1 - Unauthenticated Arbitrary Recipient Email Sending with Attacker-Controlled Link CVE 2026-87074. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-87979
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch of its payment webhook, allowing unauthenticated attackers to write a card-token record to any user's account and to enumerate registered accounts.
🎖@cveNotify
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch of its payment webhook, allowing unauthenticated attackers to write a card-token record to any user's account and to enumerate registered accounts.
🎖@cveNotify
WPScan
Paymob for WooCommerce < 4.1.14 - Unauthenticated Saved Card Token Write to Any User via Webhook
See details on Paymob for WooCommerce < 4.1.14 - Unauthenticated Saved Card Token Write to Any User via Webhook CVE 2026-87979. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-87981
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not perform a capability check on several admin AJAX actions that manage its payment-gateway configuration, allowing users with contributor-level access to delete, wipe, or modify that configuration, including the stored payment credentials.
🎖@cveNotify
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not perform a capability check on several admin AJAX actions that manage its payment-gateway configuration, allowing users with contributor-level access to delete, wipe, or modify that configuration, including the stored payment credentials.
🎖@cveNotify
WPScan
Paymob for WooCommerce < 4.1.14 - Contributor+ Payment Gateway Configuration Deletion and Modification via Multiple AJAX Actions
See details on Paymob for WooCommerce < 4.1.14 - Contributor+ Payment Gateway Configuration Deletion and Modification via Multiple AJAX Actions CVE 2026-87981. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-88929
The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description and price of draft, pending and private products.
🎖@cveNotify
The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description and price of draft, pending and private products.
🎖@cveNotify
WPScan
Sale Booster 7.0.0 - 7.5.1 - Unauthenticated Non-Public Product Disclosure
See details on Sale Booster 7.0.0 - 7.5.1 - Unauthenticated Non-Public Product Disclosure CVE 2026-88929. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-88997
The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute in an admin-facing meta box, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of a higher-privileged user who reviews the affected post.
🎖@cveNotify
The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute in an admin-facing meta box, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of a higher-privileged user who reviews the affected post.
🎖@cveNotify
WPScan
JSM Show Post Metadata < 4.9.1 - Contributor+ Stored XSS via Custom Field Meta Key
See details on JSM Show Post Metadata < 4.9.1 - Contributor+ Stored XSS via Custom Field Meta Key CVE 2026-88997. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-89331
The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose the email addresses of a shared board's members, typically including administrators.
🎖@cveNotify
The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose the email addresses of a shared board's members, typically including administrators.
🎖@cveNotify
WPScan
FluentBoards 1.95 - 2.0.15 - Unauthenticated Board Member Email Address Disclosure via Public Board Endpoints
See details on FluentBoards 1.95 - 2.0.15 - Unauthenticated Board Member Email Address Disclosure via Public Board Endpoints CVE 2026-89331. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-90951
The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that member's checkout state.
🎖@cveNotify
The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that member's checkout state.
🎖@cveNotify
WPScan
Paid Member Subscriptions < 3.1.0 - Unauthenticated In-Flight Checkout State Deletion via pms_process_payment
See details on Paid Member Subscriptions < 3.1.0 - Unauthenticated In-Flight Checkout State Deletion via pms_process_payment CVE 2026-90951. View the latest Plugin Vulnerabilities on WPScan.