|
1471
|
7.5 |
HIGH
Network
|
-
|
-
|
The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is due to insufficient path validation in the qckply_zip_theme() function, which …
|
CWE-22
Path Traversal
|
CVE-2026-6403
|
2026-05-15 23:09 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1472
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.0.2. This is due to insufficient input validation of JSON …
|
CWE-79
Cross-site Scripting
|
CVE-2026-6415
|
2026-05-15 23:09 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1473
|
4.9 |
MEDIUM
Network
|
-
|
-
|
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'table' parameter in all versions up to, and including, 9.1.12 due to …
|
CWE-89
SQL Injection
|
CVE-2026-7046
|
2026-05-15 23:09 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1474
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.3.10. This is due to t…
|
CWE-862
Missing Authorization
|
CVE-2026-7563
|
2026-05-15 23:09 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1475
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the _updateSettin…
|
CWE-352
Origin Validation Error
|
CVE-2026-8425
|
2026-05-15 23:08 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1476
|
5.8 |
MEDIUM
Network
|
-
|
-
|
Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.
|
CWE-200
Information Exposure
|
CVE-2026-41960
|
2026-05-15 23:08 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1477
|
5.9 |
MEDIUM
Local
|
-
|
-
|
Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availability.
|
CWE-840
Business Logic Errors
|
CVE-2026-41961
|
2026-05-15 23:08 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1478
|
3.6 |
LOW
Local
|
-
|
-
|
Permission control vulnerability in the app management and control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2026-41962
|
2026-05-15 23:08 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1479
|
2.8 |
LOW
Local
|
-
|
-
|
Stack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerability may affect availability.
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-41963
|
2026-05-15 23:08 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1480
|
8.4 |
HIGH
Local
|
-
|
-
|
Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability.
|
CWE-362
Race Condition
|
CVE-2026-41964
|
2026-05-15 23:08 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|