|
3091
|
4.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Review Map by RevuKangaroo para WordPress es vulnerable a cross-site scripting almacenado a través de la configuración del plugin en todas las versiones hasta la 1.7, inclusive, debido a un…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4161
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3092
|
8.8 |
HIGH
Network
|
-
|
-
|
The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2. This is due to the plugin allowing a user to update the 'on_expire_default_to_…
|
CWE-862
Missing Authorization
|
CVE-2026-4261
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3093
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Expire Users para WordPress es vulnerable a escalada de privilegios en todas las versiones hasta la 1.2.2, inclusive. Esto se debe a que el plugin permite a un usuario actualizar el meta 'o…
|
CWE-862
Missing Authorization
|
CVE-2026-4261
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3094
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black …
|
CWE-183 CWE-184
Permissive List of Allowed Inputs Incomplete Blacklist
|
CVE-2026-4509
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3095
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Ad Short plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ad' shortcode's 'client' attribute in all versions up to and including 2.0.1. This is due to insufficient input…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4067
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3096
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Ad Short para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del atributo 'client' del shortcode 'ad' en todas las versiones hasta la 2.0.1 inclusive. Esto se debe a una…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4067
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3097
|
6.1 |
MEDIUM
Network
|
-
|
-
|
El plugin Alfie – Feed Plugin para WordPress es vulnerable a Stored Cross-Site Scripting a través del parámetro 'naam' en todas las versiones hasta la 1.2.1, inclusive. Esto se debe a la falta de val…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4069
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3098
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WordPress PayPal Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'donate' shortcode in all versions up to, and including, 1.01. This is due to insufficient inpu…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4072
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3099
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin WordPress PayPal Donation para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode 'donate' en todas las versiones hasta la 1.01, inclusive. Esto se debe a una …
|
CWE-79
Cross-site Scripting
|
CVE-2026-4072
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3100
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The fyyd podcast shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fyyd-podcast', 'fyyd-episode', and 'fyyd' shortcodes in all versions up to, and including, 0.3.1…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4084
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|