|
3461
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Paypal Shortcode para WordPress es vulnerable a cross-site scripting almacenado a través de los atributos de shortcode 'amount' y 'name' en todas las versiones hasta la 0.3, inclusive. Esto…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3617
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3462
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Sheets2Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titles' shortcode attribute in the [sheets2table-render-table] shortcode in all versions up to and includin…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3619
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3463
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Sheets2Table para WordPress es vulnerable a cross-site scripting almacenado a través del atributo de shortcode 'titles' en el shortcode [sheets2table-render-table] en todas las versiones ha…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3619
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3464
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Appmax plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.0.3. This is due to the plugin registering a public REST API webhook endpoint at /we…
|
CWE-20
Improper Input Validation
|
CVE-2026-3641
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3465
|
5.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Appmax para WordPress es vulnerable a la Validación de Entrada Inadecuada en todas las versiones hasta la 1.0.3, inclusive. Esto se debe a que el plugin registra un endpoint de webhook de A…
|
CWE-20
Improper Input Validation
|
CVE-2026-3641
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3466
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Ecover Builder For Dummies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'ecover' shortcode in all versions up to and including 1.0. This is due …
|
CWE-79
Cross-site Scripting
|
CVE-2026-4077
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3467
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Ecover Builder For Dummies para WordPress es vulnerable a cross-site scripting almacenado a través del parámetro 'id' del shortcode 'ecover' en todas las versiones hasta la 1.0 inclusive. E…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4077
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3468
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Pre* Party Resource Hints plugin for WordPress is vulnerable to SQL Injection via the 'hint_ids' parameter of the pprh_update_hints AJAX action in all versions up to, and including, 1.8.20. This …
|
CWE-89
SQL Injection
|
CVE-2026-4087
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3469
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Punnel – Landing Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.1. The save_config() function, which handles the 'punnel_save_c…
|
CWE-862
Missing Authorization
|
CVE-2026-3645
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3470
|
5.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Punnel – Landing Page Builder para WordPress es vulnerable a la falta de autorización en todas las versiones hasta la 1.3.1, inclusive. La función save_config(), que maneja la acción AJAX '…
|
CWE-862
Missing Authorization
|
CVE-2026-3645
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|