|
1541
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_f…
|
CWE-94
Code Injection
|
CVE-2026-3300
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1542
|
9.8 |
CRITICAL
Network
|
-
|
-
|
El plugin Everest Forms Pro para WordPress es vulnerable a ejecución remota de código a través de inyección de código PHP en todas las versiones hasta la 1.9.12, inclusive. Esto se debe a que la func…
|
CWE-94
Code Injection
|
CVE-2026-3300
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1543
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 through views php files. Thi…
|
CWE-862
Missing Authorization
|
CVE-2026-1797
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1544
|
5.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Appointment Booking and Scheduler Plugin – Truebooker para WordPress es vulnerable a la Exposición de Información Sensible en todas las versiones hasta la 1.1.4, inclusive, a través de los …
|
CWE-862
Missing Authorization
|
CVE-2026-1797
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1545
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Loco Translate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_href’ parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitizat…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4146
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1546
|
7.5 |
HIGH
Network
|
-
|
-
|
The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmt…
|
CWE-200
Information Exposure
|
CVE-2026-4020
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1547
|
7.5 |
HIGH
Network
|
-
|
-
|
El plugin Gravity SMTP para WordPress es vulnerable a la Exposición de Información Sensible en todas las versiones hasta la 2.1.4, inclusive. Esto se debe a un endpoint de la API REST registrado en /…
|
CWE-200
Information Exposure
|
CVE-2026-4020
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1548
|
6.1 |
MEDIUM
Network
|
-
|
-
|
El plugin Loco Translate para WordPress es vulnerable a cross-site scripting reflejado a través del parámetro 'update_href' en todas las versiones hasta la 2.8.2, inclusive, debido a una sanitización…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4146
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1549
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This affects an unknown part of the file /admin/login.php. The manipulation of the argument Username results in s…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5179
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1550
|
7.3 |
HIGH
Network
|
-
|
-
|
Se detectó una vulnerabilidad en SourceCodester Simple Doctors Appointment System 1.0. Esto afecta una parte desconocida del archivo /admin/login.php. La manipulación del argumento Username resulta e…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5179
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|