|
971
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The scratchblocks for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' attribute of the 'scratchblocks' shortcode in all versions up to, and including, 1.0.1 due…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6247
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
972
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Credits Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the 'credits' shortcode in all versions up to, and including, 1.2 due to insufficie…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6256
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
973
|
4.8 |
MEDIUM
Network
|
-
|
-
|
The GWD Connect plugin for WordPress is vulnerable to missing authorization to limited code execution in all versions up to, and including, 2.9. This is due to the plugin's standalone agent endpoints…
New
|
CWE-862
Missing Authorization
|
CVE-2026-6663
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
974
|
7.2 |
HIGH
Network
|
-
|
-
|
The LifePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'n' parameter of the lp_update_mds AJAX action in all versions up to, and including, 2.2.2. This is due to the …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6690
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
975
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.3. This is due to a missing capability che…
New
|
CWE-862
Missing Authorization
|
CVE-2026-6708
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
976
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Coinbase Commerce for Contact Form 7 plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.1.2. This is due to a missing capability check and missing nonce…
New
|
CWE-862
Missing Authorization
|
CVE-2026-6709
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
977
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Skysa Text Ticker App plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the Skysa…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-6710
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
978
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Pricing Tables for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.1.0. This is due to insufficient input …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6808
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
979
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Shortcodely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'widget_area' parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization an…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6913
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
980
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Woo Commerce Minimum Weight plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 3.0.1. This is due to missing nonce verification on the settings u…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-6932
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|