๐จ CVE-2026-85002
The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post.
๐@cveNotify
The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post.
๐@cveNotify
WPScan
EmbedPress < 4.6.7 - Contributor+ Stored XSS via Instagram Carousel Block Attributes
See details on EmbedPress < 4.6.7 - Contributor+ Stored XSS via Instagram Carousel Block Attributes CVE 2026-85002. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-86609
The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature.
๐@cveNotify
The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature.
๐@cveNotify
WPScan
Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription
See details on Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription CVE 2026-86609. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-86839
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information.
๐@cveNotify
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information.
๐@cveNotify
WPScan
Bookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and Deletion via IDOR
See details on Bookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and Deletion via IDOR CVE 2026-86839. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-86841
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly assign, to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets.
๐@cveNotify
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly assign, to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets.
๐@cveNotify
WPScan
Bookly 23.2 - 28.2 - Bookly Administrator+ PHP Object Injection via Diagnostics Advanced Options
See details on Bookly 23.2 - 28.2 - Bookly Administrator+ PHP Object Injection via Diagnostics Advanced Options CVE 2026-86841. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-89000
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to internal-only resources and read the responses back.
๐@cveNotify
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to internal-only resources and read the responses back.
๐@cveNotify
WPScan
WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run
See details on WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run CVE 2026-89000. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-89001
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing users with contributor-level access and above to publish posts live and set any registered user, including an administrator, as the post author.
๐@cveNotify
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing users with contributor-level access and above to publish posts live and set any registered user, including an administrator, as the post author.
๐@cveNotify
WPScan
WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Post Publication and Author Spoofing via Campaign Settings
See details on WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Post Publication and Author Spoofing via Campaign Settings CVE 2026-89001. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-89003
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses back.
๐@cveNotify
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses back.
๐@cveNotify
WPScan
WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Preview
See details on WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Preview CVE 2026-89003. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-92436
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents.
๐@cveNotify
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents.
๐@cveNotify
WPScan
Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via IDOR
See details on Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via IDOR CVE 2026-92436. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-92995
The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization.
๐@cveNotify
The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization.
๐@cveNotify
WPScan
Verge3D < 4.13.1 - Unauthenticated Product Download Disclosure via v3d_download_file
See details on Verge3D < 4.13.1 - Unauthenticated Product Download Disclosure via v3d_download_file CVE 2026-92995. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-96895
The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
๐@cveNotify
The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
๐@cveNotify
WPScan
WP YouTube Lyte < 1.7.31 - Contributor+ Stored XSS via Embed Block Attributes
See details on WP YouTube Lyte < 1.7.31 - Contributor+ Stored XSS via Embed Block Attributes CVE 2026-96895. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-96896
The Malcure Malware Shield โ Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.
๐@cveNotify
The Malcure Malware Shield โ Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.
๐@cveNotify
WPScan
Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Write and Deletion via wpmr_ajax_request
See details on Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Write and Deletion via wpmr_ajax_request CVE 2026-96896. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-96897
The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that is available to logged-out users, allowing unauthenticated attackers to force the creation of a fixed author-role account and to repeatedly rotate its application password on any connected install.
๐@cveNotify
The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that is available to logged-out users, allowing unauthenticated attackers to force the creation of a fixed author-role account and to repeatedly rotate its application password on any connected install.
๐@cveNotify
WPScan
Optima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Application Password Rotation via ihf_clear_cache
See details on Optima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Application Password Rotation via ihf_clear_cache CVE 2026-96897. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-96899
The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it and echoing it into the document head when the post is rendered, allowing users with a role as low as author to perform Stored Cross-Site Scripting attacks.
๐@cveNotify
The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it and echoing it into the document head when the post is rendered, allowing users with a role as low as author to perform Stored Cross-Site Scripting attacks.
๐@cveNotify
WPScan
Optima Express 8.6.0 - 8.7.5 - Author+ Stored XSS via faq_script
See details on Optima Express 8.6.0 - 8.7.5 - Author+ Stored XSS via faq_script CVE 2026-96899. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-97227
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials, delete arbitrary posts and reset the NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8's configuration.
๐@cveNotify
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials, delete arbitrary posts and reset the NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8's configuration.
๐@cveNotify
WPScan
NextScripts: Social Networks Auto-Poster < 4.4.8 - Authenticated Social Account Credential Disclosure and Data Deletion
See details on NextScripts: Social Networks Auto-Poster < 4.4.8 - Authenticated Social Account Credential Disclosure and Data Deletion CVE 2026-97227. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-97319
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
๐@cveNotify
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
๐@cveNotify
WPScan
PowerPress < 11.17.2 - Contributor+ Stored XSS via Podcast Player Block
See details on PowerPress < 11.17.2 - Contributor+ Stored XSS via Podcast Player Block CVE 2026-97319. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-100893
A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
is.yuum.me
SSRF Vulnerability in VoceChat Server โค v0.5.20 | YumeIsland
๐จ CVE-2026-100894
A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This issue affects some unknown processing of the file updateguest.php. The manipulation of the argument gname leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This issue affects some unknown processing of the file updateguest.php. The manipulation of the argument gname leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
GitHub
GitHub - JaconiasDev/Advisory-CloundClassroom-PHP-Project-1.0
Contribute to JaconiasDev/Advisory-CloundClassroom-PHP-Project-1.0 development by creating an account on GitHub.
๐จ CVE-2026-100895
A security flaw has been discovered in Trusted Domain Project OpenARC up to 1.0.0.Beta1. Impacted is the function arc_parse_canon_t in the library libopenarc/arc-canon.c of the component libopenarc. The manipulation results in null pointer dereference. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.0.0.Beta0 is recommended to address this issue. Upgrading the affected component is advised.
๐@cveNotify
A security flaw has been discovered in Trusted Domain Project OpenARC up to 1.0.0.Beta1. Impacted is the function arc_parse_canon_t in the library libopenarc/arc-canon.c of the component libopenarc. The manipulation results in null pointer dereference. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.0.0.Beta0 is recommended to address this issue. Upgrading the affected component is advised.
๐@cveNotify
GitHub
Release OpenARC release 1.0.0.Beta0 ยท trusteddomainproject/OpenARC
Initial public test release of OpenARC.
This is the first version being released as a tarball for use by distributions or in live installations. It is up to date and complete with version 15 of the...
This is the first version being released as a tarball for use by distributions or in live installations. It is up to date and complete with version 15 of the...
๐จ CVE-2026-100896
A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
๐@cveNotify
A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
๐@cveNotify
Gist
TOTOLINK N150RT V3.4.0-B20201030 - Command Injection in /boafrm/formWlSiteSurvey
TOTOLINK N150RT V3.4.0-B20201030 - Command Injection in /boafrm/formWlSiteSurvey - TOTOLINK-N150RT_VULN2.md
๐จ CVE-2026-100897
A security vulnerability has been detected in fuzui StudentInfo up to fcc42a639ec7cef620651bfd0f07ebb660529e3f. The impacted element is an unknown function of the file /StudentInfo/StudentHandler/moditypasswordstu of the component Password Change Endpoint. Such manipulation of the argument sid/tid leads to authorization bypass. The attack can be executed remotely. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
A security vulnerability has been detected in fuzui StudentInfo up to fcc42a639ec7cef620651bfd0f07ebb660529e3f. The impacted element is an unknown function of the file /StudentInfo/StudentHandler/moditypasswordstu of the component Password Change Endpoint. Such manipulation of the argument sid/tid leads to authorization bypass. The attack can be executed remotely. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
๐จ CVE-2026-100898
A vulnerability was detected in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/2.0.0-beta1. This affects the function whereRaw of the file app/Filament/Widgets/Timesheet/ActivitiesReport.php of the component Timesheet Dashboard. Performing a manipulation of the argument filter results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
A vulnerability was detected in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/2.0.0-beta1. This affects the function whereRaw of the file app/Filament/Widgets/Timesheet/ActivitiesReport.php of the component Timesheet Dashboard. Performing a manipulation of the argument filter results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
GitHub
CVE/Timesheet Dashboard Chart Filter SQL Injection (ActivitiesReport).md at main ยท dddwmr/CVE
Contribute to dddwmr/CVE development by creating an account on GitHub.