|
1181
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.2. This is due to missing nonce verification in the rd_ic_settings_page fun…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-4090
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1182
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.4. This is due to the settings form on the admin page (wpo_admin…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-4131
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1183
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The DX Unanswered Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing nonce validation on the plugin's settings…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-4138
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1184
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Quran Live Multilanguage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cheikh' and 'lang' shortcode attributes in all versions up to, and including, 1.0.3. This is du…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-4074
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1185
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Slider Bootstrap Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'category' and 'template' shortcode attributes in all versions up to and including 1.0.7. This …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-4076
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1186
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Easy Social Photos Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper_class' shortcode attribute of the 'my-instagram-feed' shortcode in all versions up to…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-4085
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1187
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Switch CTA Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wppw_cta_box' shortcode in all versions up to, and including, 1.1. This is due to insufficient input sani…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-4088
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1188
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Twittee Text Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute in all versions up to and including 1.0.8. This is due to insufficient input …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-4089
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1189
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The CI HUB Connector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `cihub_metadata` shortcode in all versions up to, and including, 1.2.106 due to in…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-4353
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1190
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Text Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ts` shortcode in all versions up to, and including, 0.0.1 due to insufficient input sanitization …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-5748
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|