|
1081
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Canto plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 3.1.1. This is due to the absence of any capability check or nonce verification in the updateOpti…
|
CWE-862
Missing Authorization
|
CVE-2026-6441
|
2026-04-17 16:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1082
|
7.5 |
HIGH
Network
|
-
|
-
|
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up to, and including, 2.0.6. This is due to insuffic…
|
CWE-22
Path Traversal
|
CVE-2026-4659
|
2026-04-17 16:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1083
|
7.0 |
HIGH
Local
|
-
|
-
|
A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library msimg32.dll. The manipulation leads to uncontrolled search path. An attack has…
|
CWE-426 CWE-427
Untrusted Search Path Uncontrolled Search Path Element
|
CVE-2026-6421
|
2026-04-17 15:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1084
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to insufficient input sanitization and the execution…
|
CWE-74
Injection
|
CVE-2026-5797
|
2026-04-17 15:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1085
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to insufficient escaping on the 'date' parameter combined with direct interpolatio…
|
CWE-89
SQL Injection
|
CVE-2026-6080
|
2026-04-17 14:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1086
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content manipulation in versions up to and including 3.9.8. This is due to a missing aut…
|
CWE-862
Missing Authorization
|
CVE-2026-5502
|
2026-04-17 14:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1087
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Kubio plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 2.7.2. This is due to insufficient capability checks in the kubio_rest_pre_insert_import_assets()…
|
CWE-862
Missing Authorization
|
CVE-2026-5427
|
2026-04-17 14:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1088
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.3.2. The vulnerability exists because the OsStripeConnectController::creat…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-5234
|
2026-04-17 14:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1089
|
4.9 |
MEDIUM
Network
|
-
|
-
|
The JetBackup – Backup, Restore & Migrate plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary Directory Deletion in versions up to and including 3.1.19.8. This is due to insuffi…
|
CWE-22
Path Traversal
|
CVE-2026-4853
|
2026-04-17 14:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1090
|
4.9 |
MEDIUM
Network
|
-
|
-
|
The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate', 'username_search', and 'useremail_search' parameters in all versions up to, an…
|
CWE-89
SQL Injection
|
CVE-2026-3330
|
2026-04-17 14:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|