|
2851
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Linksy Search and Replace para WordPress es vulnerable a la modificación no autorizada de datos debido a una falta de verificación de capacidad en la función 'linksy_search_and_replace_item…
|
CWE-862
Missing Authorization
|
CVE-2026-2941
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2852
|
7.2 |
HIGH
Network
|
-
|
-
|
The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ parameter in all versions up to, and including, 0.3 due to insufficient input sanitiz…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3003
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2853
|
7.2 |
HIGH
Network
|
-
|
-
|
El plugin Vagaro Booking Widget para WordPress es vulnerable a cross-site scripting almacenado a través del parámetro 'vagaro_code' en todas las versiones hasta la 0.3, inclusive, debido a una saniti…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3003
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2854
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Lobot Slider Administrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.0. This is due to missing or incorrect nonce validation on the fo…
|
CWE-352
Origin Validation Error
|
CVE-2026-3331
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2855
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Lobot Slider Administrator para WordPress es vulnerable a la falsificación de petición en sitios cruzados en versiones hasta la 0.6.0, inclusive. Esto se debe a la validación de nonce falta…
|
CWE-352
Origin Validation Error
|
CVE-2026-3331
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2856
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Xhanch - My Advanced Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing nonce validation in the `xms_set…
|
CWE-352
Origin Validation Error
|
CVE-2026-3332
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2857
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linkgate' shortcode in all versions up to, and including, 3.6.1 due to insufficient input…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3333
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2858
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin MinhNhut Link Gateway para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode 'linkgate' del plugin en todas las versiones hasta la 3.6.1, inclusive, debido a …
|
CWE-79
Cross-site Scripting
|
CVE-2026-3333
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2859
|
8.8 |
HIGH
Network
|
-
|
-
|
The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and 'or_admin_email' parameters in all versions up to, and including, 2.288. This is…
|
CWE-89
SQL Injection
|
CVE-2026-3334
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2860
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Comment SPAM Wiper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' setting in all versions up to, and including, 1.2.1. This is due to insufficient input sanit…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3353
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|