|
1441
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.0.0 due to insufficient input sanitization and ou…
|
CWE-79
Cross-site Scripting
|
CVE-2026-8703
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1442
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versions up to, and including, 1.2.4 due to insufficient input sanitization and outp…
|
CWE-79
Cross-site Scripting
|
CVE-2026-8707
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1443
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the _options…
|
CWE-352
Origin Validation Error
|
CVE-2026-8708
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1444
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adid' Shortcode Attribute in all versions up to, and including, 1.1 due to insuffi…
|
CWE-79
Cross-site Scripting
|
CVE-2026-8837
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1445
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Google+ Link Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gplusnamelink' shortcode in versions up to, and including, 1.0. This is due to insufficient input sani…
|
CWE-79
Cross-site Scripting
|
CVE-2026-8842
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1446
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspcheck' shortcode in versions up to, and including, 0.0.3. This is due to insufficient input sanitiza…
|
CWE-79
Cross-site Scripting
|
CVE-2026-8844
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1447
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplete fix for CVE-2024-11178: the rate-limit/lockout c…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-8760
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1448
|
8.8 |
HIGH
Network
|
-
|
-
|
The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.1.1. This is due to the `firebase_auth()` function authentica…
|
CWE-269
Improper Privilege Management
|
CVE-2026-8787
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1449
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Islamic Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'islamicDB-roqya' shortcode in versions up to, and including, 1.0. This is due to insufficient input san…
|
CWE-79
Cross-site Scripting
|
CVE-2026-8845
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1450
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Tuxquote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'TUXQUOTE' shortcode in versions up to, and including, 1.3. This is due to insufficient input sanitization and o…
|
CWE-79
Cross-site Scripting
|
CVE-2026-8846
|
2026-05-27 23:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|