|
321
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' shortcode attribute in the 'my-email' shortcode in all versions up to, and including, 0.91 d…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8048
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
322
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0. This is due to insufficient output escaping in the as_get_coin_shortcode(…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8698
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
323
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the `title-ticker-slide`, `title-ticker-fade`, and `title-ticker-typing` shortcodes. Th…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8701
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
324
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the 'div' attribute of the 'gbitoprint' shortcode. This is due to insufficient output escaping in…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8702
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
325
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.0.0 due to insufficient input sanitization and ou…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8703
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
326
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versions up to, and including, 1.2.4 due to insufficient input sanitization and outp…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8707
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
327
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the _options…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-8708
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
328
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adid' Shortcode Attribute in all versions up to, and including, 1.1 due to insuffi…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8837
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
329
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Google+ Link Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gplusnamelink' shortcode in versions up to, and including, 1.0. This is due to insufficient input sani…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8842
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
330
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplete fix for CVE-2024-11178: the rate-limit/lockout c…
New
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-8760
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|