|
1891
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and a nonce validation logic flaw in the saab_cancel_booking(…
New
|
CWE-862
Missing Authorization
|
CVE-2026-5693
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1892
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Voyage Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the 'post-content' shortcode in all versions up to, and including, 1.0.6 due to insuffic…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-5715
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1893
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Quick Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' attribute of the 'qtbl' shortcode in all versions up to, and including, 1.0.0 due to insufficient inp…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6237
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1894
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The scratchblocks for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' attribute of the 'scratchblocks' shortcode in all versions up to, and including, 1.0.1 due…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6247
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1895
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Credits Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the 'credits' shortcode in all versions up to, and including, 1.2 due to insufficie…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6256
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1896
|
4.8 |
MEDIUM
Network
|
-
|
-
|
The GWD Connect plugin for WordPress is vulnerable to missing authorization to limited code execution in all versions up to, and including, 2.9. This is due to the plugin's standalone agent endpoints…
New
|
CWE-862
Missing Authorization
|
CVE-2026-6663
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1897
|
7.2 |
HIGH
Network
|
-
|
-
|
The LifePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'n' parameter of the lp_update_mds AJAX action in all versions up to, and including, 2.2.2. This is due to the …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6690
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1898
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.3. This is due to a missing capability che…
New
|
CWE-862
Missing Authorization
|
CVE-2026-6708
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1899
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Coinbase Commerce for Contact Form 7 plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.1.2. This is due to a missing capability check and missing nonce…
New
|
CWE-862
Missing Authorization
|
CVE-2026-6709
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1900
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Skysa Text Ticker App plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the Skysa…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-6710
|
2026-05-12 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|