|
3081
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Games Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [game] shortcode in all versions up to and including 0.1beta. This is due to insufficient input sanitizati…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3996
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3082
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin Pre* Party Resource Hints para WordPress es vulnerable a inyección SQL a través del parámetro 'hint_ids' de la acción AJAX pprh_update_hints en todas las versiones hasta e incluyendo la 1.8…
|
CWE-89
SQL Injection
|
CVE-2026-4087
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3083
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Neos Connector for Fakturama plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.0.14. This is due to missing nonce validation in the ncff_add_p…
|
CWE-352
Origin Validation Error
|
CVE-2026-4143
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3084
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Neos Connector for Fakturama para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta la 0.0.14 inclusive. Esto se debe a la falta de vali…
|
CWE-352
Origin Validation Error
|
CVE-2026-4143
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3085
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Review Map by RevuKangaroo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.7 due to insufficient input sanitizati…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4161
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3086
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin WP Games Embed para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode [game] en todas las versiones hasta la 0.1beta inclusive. Esto se debe a una sanitizació…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3996
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3087
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Text Toggle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute of the [tt_part] and [tt] shortcodes in all versions up to and including 1.1. Thi…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3997
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3088
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Text Toggle para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del atributo 'title' del shortcode de los shortcodes [tt_part] y [tt] en todas las versiones hasta la 1.1…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3997
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3089
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all versions up to, and including, 3.0.2. This is due to missing capability checks…
|
CWE-94
Code Injection
|
CVE-2026-4004
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3090
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin Task Manager para WordPress es vulnerable a la ejecución arbitraria de shortcodes a través de la acción AJAX 'search' en todas las versiones hasta la 3.0.2, inclusive. Esto se debe a la fal…
|
CWE-94
Code Injection
|
CVE-2026-4004
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|