|
1721
|
9.8 |
CRITICAL
Network
|
-
|
-
|
El plugin Contact Form by Supsystic para WordPress es vulnerable a la inyección de plantillas del lado del servidor (SSTI) lo que lleva a la ejecución remota de código (RCE) en todas las versiones ha…
|
CWE-94
Code Injection
|
CVE-2026-4257
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1722
|
8.8 |
HIGH
Network
|
-
|
-
|
The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up to and including 1.3.2. This was due to the plugin accepting the wp_debug_trou…
|
CWE-565
Reliance on Cookies without Validation and Integrity Checking
|
CVE-2026-5130
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1723
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Debugger & Troubleshooter para WordPress era vulnerable a una escalada de privilegios no autenticada en versiones hasta la 1.3.2 inclusive. Esto se debía a que el plugin aceptaba el val…
|
CWE-565
Reliance on Cookies without Validation and Integrity Checking
|
CVE-2026-5130
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1724
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_f…
|
CWE-94
Code Injection
|
CVE-2026-3300
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1725
|
9.8 |
CRITICAL
Network
|
-
|
-
|
El plugin Everest Forms Pro para WordPress es vulnerable a ejecución remota de código a través de inyección de código PHP en todas las versiones hasta la 1.9.12, inclusive. Esto se debe a que la func…
|
CWE-94
Code Injection
|
CVE-2026-3300
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1726
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 through views php files. Thi…
|
CWE-862
Missing Authorization
|
CVE-2026-1797
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1727
|
5.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Appointment Booking and Scheduler Plugin – Truebooker para WordPress es vulnerable a la Exposición de Información Sensible en todas las versiones hasta la 1.1.4, inclusive, a través de los …
|
CWE-862
Missing Authorization
|
CVE-2026-1797
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1728
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Loco Translate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_href’ parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitizat…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4146
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1729
|
7.5 |
HIGH
Network
|
-
|
-
|
The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmt…
|
CWE-200
Information Exposure
|
CVE-2026-4020
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1730
|
7.5 |
HIGH
Network
|
-
|
-
|
El plugin Gravity SMTP para WordPress es vulnerable a la Exposición de Información Sensible en todas las versiones hasta la 2.1.4, inclusive. Esto se debe a un endpoint de la API REST registrado en /…
|
CWE-200
Information Exposure
|
CVE-2026-4020
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|