|
3391
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all versions up to, and including, 3.0.2. This is due to missing capability checks…
|
CWE-94
Code Injection
|
CVE-2026-4004
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3392
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin Task Manager para WordPress es vulnerable a la ejecución arbitraria de shortcodes a través de la acción AJAX 'search' en todas las versiones hasta la 3.0.2, inclusive. Esto se debe a la fal…
|
CWE-94
Code Injection
|
CVE-2026-4004
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3393
|
4.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Review Map by RevuKangaroo para WordPress es vulnerable a cross-site scripting almacenado a través de la configuración del plugin en todas las versiones hasta la 1.7, inclusive, debido a un…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4161
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3394
|
8.8 |
HIGH
Network
|
-
|
-
|
The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2. This is due to the plugin allowing a user to update the 'on_expire_default_to_…
|
CWE-862
Missing Authorization
|
CVE-2026-4261
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3395
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Expire Users para WordPress es vulnerable a escalada de privilegios en todas las versiones hasta la 1.2.2, inclusive. Esto se debe a que el plugin permite a un usuario actualizar el meta 'o…
|
CWE-862
Missing Authorization
|
CVE-2026-4261
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3396
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black …
|
CWE-183 CWE-184
Permissive List of Allowed Inputs Incomplete Blacklist
|
CVE-2026-4509
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3397
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Ad Short plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ad' shortcode's 'client' attribute in all versions up to and including 2.0.1. This is due to insufficient input…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4067
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3398
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Ad Short para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del atributo 'client' del shortcode 'ad' en todas las versiones hasta la 2.0.1 inclusive. Esto se debe a una…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4067
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3399
|
6.1 |
MEDIUM
Network
|
-
|
-
|
El plugin Alfie – Feed Plugin para WordPress es vulnerable a Stored Cross-Site Scripting a través del parámetro 'naam' en todas las versiones hasta la 1.2.1, inclusive. Esto se debe a la falta de val…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4069
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3400
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WordPress PayPal Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'donate' shortcode in all versions up to, and including, 1.01. This is due to insufficient inpu…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4072
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|