|
231
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.5. This is due to missing or incorrect nonce validation on th…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-8423
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
232
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'rybb_a…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-8424
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
233
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.4. This is due to the plugin not properly verifying that a user…
New
|
CWE-862
Missing Authorization
|
CVE-2026-8610
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
234
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.97.1 due to insufficient input san…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8624
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
235
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_content_editor function in all versio…
New
|
CWE-862
Missing Authorization
|
CVE-2025-15369
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
236
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.5.2 due to insufficient input sanitization and output…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8626
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
237
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] variable in versions up to and including 1.0. This is due to the correct_prices_pa…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8627
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
238
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all versions up to, and including, 2.15.16. This is due to insufficient escaping on…
New
|
CWE-89
SQL Injection
|
CVE-2026-8685
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
239
|
7.5 |
HIGH
Network
|
-
|
-
|
The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3 due to insufficient escaping on the u…
New
|
CWE-89
SQL Injection
|
CVE-2026-9010
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
240
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This mak…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-7637
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|