|
3031
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Ricerca – advanced search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in all versions up to, and including, 1.1.12 due to insufficient input sanitizati…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2837
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3032
|
4.4 |
MEDIUM
Network
|
-
|
-
|
El plugin de búsqueda avanzada Ricerca para WordPress es vulnerable a cross-site scripting almacenado a través de la configuración del plugin en todas las versiones hasta la 1.1.12, inclusive, debido…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2837
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3033
|
8.8 |
HIGH
Network
|
-
|
-
|
The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_and_replace_item_details' function in all…
|
CWE-862
Missing Authorization
|
CVE-2026-2941
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3034
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Linksy Search and Replace para WordPress es vulnerable a la modificación no autorizada de datos debido a una falta de verificación de capacidad en la función 'linksy_search_and_replace_item…
|
CWE-862
Missing Authorization
|
CVE-2026-2941
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3035
|
7.2 |
HIGH
Network
|
-
|
-
|
The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ parameter in all versions up to, and including, 0.3 due to insufficient input sanitiz…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3003
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3036
|
7.2 |
HIGH
Network
|
-
|
-
|
El plugin Vagaro Booking Widget para WordPress es vulnerable a cross-site scripting almacenado a través del parámetro 'vagaro_code' en todas las versiones hasta la 0.3, inclusive, debido a una saniti…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3003
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3037
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Lobot Slider Administrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.0. This is due to missing or incorrect nonce validation on the fo…
|
CWE-352
Origin Validation Error
|
CVE-2026-3331
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3038
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Lobot Slider Administrator para WordPress es vulnerable a la falsificación de petición en sitios cruzados en versiones hasta la 0.6.0, inclusive. Esto se debe a la validación de nonce falta…
|
CWE-352
Origin Validation Error
|
CVE-2026-3331
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3039
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Xhanch - My Advanced Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing nonce validation in the `xms_set…
|
CWE-352
Origin Validation Error
|
CVE-2026-3332
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3040
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linkgate' shortcode in all versions up to, and including, 3.6.1 due to insufficient input…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3333
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|