|
1191
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The SlideShowPro SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `slideShowProSC` shortcode in all versions up to, and including, 1.0.2 due to insufficient input…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-5767
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1192
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The CalJ plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5. This is due to a missing capability check in the CalJSettingsPage class constructor, wh…
New
|
CWE-862
Missing Authorization
|
CVE-2026-4117
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1193
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Call To Action Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.3. This is due to missing nonce validation in the cbox_options_pag…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-4118
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1194
|
9.1 |
CRITICAL
Network
|
-
|
-
|
The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin_post action hooks for creating tables (admin_post…
New
|
CWE-862
Missing Authorization
|
CVE-2026-4119
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1195
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Kcaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.0.1. This is due to missing nonce validation in the plugin's settings page handler …
New
|
CWE-352
Origin Validation Error
|
CVE-2026-4121
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1196
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WPMK Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in all versions up to and including 1.0.1. This is due to insufficient input sanit…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-4125
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1197
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Zypento Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents block in all versions up to, and including, 1.0.6. This is due to the front-end TOC rend…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-5820
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1198
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Buzz Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom Buzz Avatar' (buzz_comments_avatar_image) setting in all versions up to, and including, 0.9.4. This…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6041
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1199
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This is due to the plug…
New
|
CWE-862
Missing Authorization
|
CVE-2026-6235
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1200
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Posts map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' shortcode attribute in all versions up to, and including, 0.1.3 due to insufficient input sanitization a…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6236
|
2026-04-23 05:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|