Plugin Pulse

Plugin vulnerabilities

Recently disclosed security vulnerabilities in WordPress plugins, newest first: what the issue is, which versions it hits, and the release that fixes it. The plugin directory itself never shows you any of this.

200 shown

  1. A ACPT (Premium) Critical

    ACPT (Premium) <= 2.0.66 - Unauthenticated Privilege Escalation via 'acpt_form_post_id' Parameter

    2026-09-03 CVE-2026-15354 Affects <= 2.0.66 Patched in 2.0.67 Full record on Wordfence ↗
  2. D Divi Ajax Filter Critical

    Divi Ajax Filter <= 5.1.2 - Unauthenticated Local File Inclusion via 'custom_loop_template' Parameter

    2026-09-03 CVE-2026-11613 Affects <= 5.1.2 Patched in 5.1.3 Full record on Wordfence ↗
  3. L LearnDash LMS High

    LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler

    2026-09-03 CVE-2026-12483 Affects <= 5.1.5 Patched in 5.1.5.1 Full record on Wordfence ↗
  4. JetFormBuilder <= 3.6.2 - Missing Authorization to Unauthenticated JetEngine Options Page Modification

    2026-09-03 Affects <= 3.6.2 Patched in 3.6.2.1 Full record on Wordfence ↗
  5. GutenKit <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'postBodyCss'

    2026-09-02 CVE-2026-2573 Affects <= 2.4.4 Patched in 2.4.5 Full record on Wordfence ↗
  6. Easy Waveform Player <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode_easywaveformplayer Function

    2026-09-01 CVE-2025-7963 Affects <= 1.2.2 Patched in 1.2.3 Full record on Wordfence ↗
  7. Broken Link Checker <= 2.4.13 - Unauthenticated Stored Cross-Site Scripting via Comment Author URL / Link Log

    2026-09-01 CVE-2026-75528 Affects <= 2.4.13 Patched in 2.4.13.1 Full record on Wordfence ↗
  8. S SigmaForms Pro – AI Generated Forms Critical

    SigmaForms Pro <= 1.4.11 - Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field

    2026-09-01 CVE-2026-78657 Affects <= 1.4.11 Patched in 1.4.12 Full record on Wordfence ↗
  9. D DevKit Pro High

    DevKit Pro <= 2.3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Theme Installation / Remote Code Execution via 'qqfile' Parameter

    2026-09-01 CVE-2026-14357 Affects <= 2.3.0 Patched in 2.3.1 Full record on Wordfence ↗
  10. W WP File Download High

    WP File Download <= 6.3.4 - Authenticated (Subscriber+) Arbitrary File Deletion via 'remoteurl' Parameter

    2026-09-01 CVE-2026-14982 Affects <= 6.3.4 Patched in 6.3.5 Full record on Wordfence ↗
  11. G Gravity Forms High

    Gravity Forms <= 3.0.2 - Unauthenticated Arbitrary File Upload via State/Chunk Hash Confusion

    2026-09-01 CVE-2026-19513 Affects <= 3.0.2 Patched in 3.0.3 Full record on Wordfence ↗
  12. Booking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId'

    2026-09-01 CVE-2026-9055 Affects 8.0 - 9.6.2 Patched in 9.6.3 Full record on Wordfence ↗
  13. W WPBakery Page Builder Medium

    WPBakery Page Builder <= 8.7.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'data' Parameter

    2026-08-31 CVE-2026-15101 Affects <= 8.7.4 Patched in 9.0 Full record on Wordfence ↗
  14. Welcart e-Commerce <= 2.12.1 - Unauthenticated Stored Cross-Site Scripting via 'custom_order' Parameter

    2026-08-31 CVE-2026-19914 Affects <= 2.12.1 Patched in 2.12.2 Full record on Wordfence ↗
  15. Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode

    2026-08-31 CVE-2026-16786 Affects <= 2.1.19 Patched in 2.1.20 Full record on Wordfence ↗
  16. Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via dslc_module_projects_output Shortcode

    2026-08-31 CVE-2026-16788 Affects <= 2.1.19 Patched in 2.1.20 Full record on Wordfence ↗
  17. Blocksy Companion <= 2.1.51 - Authenticated (Author+) Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data)

    2026-08-31 CVE-2026-18488 Affects <= 2.1.51 Patched in 2.1.52 Full record on Wordfence ↗
  18. User Profile Builder <= 4.0.0 - Unauthenticated Stored Cross-Site Scripting via 'email' Parameter

    2026-08-31 CVE-2026-75964 Affects <= 4.0.0 Patched in 4.0.1 Full record on Wordfence ↗
  19. Charitable <= 1.8.12.1 - Authenticated (Contributor+) SQL Injection via 'order' Shortcode Attribute

    2026-08-31 CVE-2026-77189 Affects <= 1.8.12.1 Patched in 1.8.12.2 Full record on Wordfence ↗
  20. BetterDocs <= 4.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Heading 'id' Attribute in Post Content

    2026-08-31 CVE-2026-75980 Affects <= 4.8.1 Patched in 4.8.2 Full record on Wordfence ↗
  21. User Profile Builder <= 4.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'date' Shortcode Attribute

    2026-08-31 CVE-2026-75965 Affects <= 4.0.0 Patched in 4.0.1 Full record on Wordfence ↗
  22. Support Genix <= 1.4.52 - Authenticated (Subscriber+) Authentication Bypass to Administrator Account Takeover via 'p' Parameter Forged Guest Token

    2026-08-31 CVE-2026-19806 Affects <= 1.4.52 Patched in 1.4.53 Full record on Wordfence ↗
  23. Shopping Cart & eCommerce Store <= 5.9.2 - Authenticated (Administrator+) SQL Injection via 'product_order' Parameter

    2026-08-31 CVE-2026-17589 Affects <= 5.9.2 Patched in 5.9.3 Full record on Wordfence ↗
  24. Cozy Blocks <= 2.2.17 - Missing Authorization to Unauthenticated Unpublished Product Information Disclosure via 'wishlistData' Parameter

    2026-08-31 CVE-2026-19948 Affects <= 2.2.17 Patched in 2.2.18 Full record on Wordfence ↗
  25. Affiliate Super Assistent <= 1.10.2 - Unauthenticated Stored Cross-Site Scripting via ‘doCommentShortcode’ function

    2026-08-31 CVE-2026-19573 Affects <= 1.10.2 Patched in 1.10.3 Full record on Wordfence ↗
  26. Photo Gallery by Ays <= 6.8.2 - Authenticated (Administrator+) SQL Injection via 's' Parameter

    2026-08-31 CVE-2026-76006 Affects <= 6.8.2 Patched in 6.8.3 Full record on Wordfence ↗
  27. Persistent Login <= 3.1.0 - Authenticated (Subscriber+) SQL Injection via 'wppl_device_id' Cookie

    2026-08-31 CVE-2026-18752 Affects <= 3.1.0 Patched in 3.1.1 Full record on Wordfence ↗
  28. Master Addons for Elementor <= 3.1.9 - Incorrect Authorization to Authenticated (Editor+) Arbitrary File Upload via upload_template_kit AJAX ZIP Extraction

    2026-08-31 CVE-2026-75921 Affects <= 3.1.9 Patched in 3.2.0 Full record on Wordfence ↗
  29. Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode

    2026-08-31 CVE-2026-16787 Affects <= 2.1.19 Patched in 2.1.20 Full record on Wordfence ↗
  30. Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_id' Shortcode Attribute

    2026-08-31 CVE-2026-13203 Affects <= 2.1.19 Patched in 2.1.20 Full record on Wordfence ↗
  31. Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 5.8.1 - Unauthenticated Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter

    2026-08-31 CVE-2026-19796 Affects <= 5.8.1 Patched in 5.9.0 Full record on Wordfence ↗
  32. LearnPress <= 4.4.4 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter

    2026-08-31 CVE-2026-77823 Affects <= 4.4.4 Patched in 4.4.5 Full record on Wordfence ↗
  33. Frontend Admin by DynamiApps <= 3.29.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Shortcode Attribute

    2026-08-31 CVE-2026-12747 Affects <= 3.29.11 Patched in 3.29.12 Full record on Wordfence ↗
  34. Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Arbitrary File Deletion via Path Traversal via custom_directory_name Merge Tag

    2026-08-31 CVE-2026-19952 Affects <= 3.29.12 Patched in 3.29.13 Full record on Wordfence ↗
  35. WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint

    2026-08-31 CVE-2026-75865 Affects <= 4.4.1 Patched in 4.4.2 Full record on Wordfence ↗
  36. U Uix UserCenter High

    Uix UserCenter <= 1.0.3 - Unauthenticated Privilege Escalation

    2026-08-31 CVE-2026-16259 Affects <= 1.0.3 No patch available Full record on Wordfence ↗
  37. MemberHero – Simple User Registration & Login <= 6.9 - Unauthenticated Privilege Escalation

    2026-08-31 CVE-2026-10522 Affects <= 6.9 No patch available Full record on Wordfence ↗
  38. WCFM Marketplace – Multivendor Marketplace for WooCommerce <= 3.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

    2026-08-31 CVE-2026-83562 Affects <= 3.8.2 Patched in 3.8.3 Full record on Wordfence ↗
  39. bbPress Medium

    bbPress <= 2.6.14 - Missing Authorization

    2026-08-31 CVE-2026-74010 Affects <= 2.6.14 No patch available Full record on Wordfence ↗
  40. F FS Poster - WordPress Social media Auto Poster & Scheduler [Facebook, Instagram, Twitter, Pinterest] High

    FS Poster <= 8.0.1 - Authenticated (Subscriber+) Remote Code Execution via FFmpeg Path Setting

    2026-08-31 CVE-2026-10195 Affects <= 8.0.1 Patched in 8.0.2 Full record on Wordfence ↗
  41. Rest Routes – Custom Endpoints for WordPress REST API <= 5.5.5 - Unauthenticated SQL Injection

    2026-08-31 CVE-2026-16061 Affects <= 5.5.5 No patch available Full record on Wordfence ↗
  42. WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode <= 4.4.1 - Unauthenticated Arbitrary File Upload

    2026-08-31 CVE-2026-82970 Affects <= 4.4.1 Patched in 4.4.2 Full record on Wordfence ↗
  43. W WP Recipe Maker Premium Medium

    WP Recipe Maker Premium <= 10.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wprm-call-to-action' Shortcode

    2026-08-31 CVE-2026-7877 Affects <= 10.5.0 Patched in 10.6.0 Full record on Wordfence ↗
  44. B Breakdance Medium

    Breakdance <= 2.8.1 - Missing Authorization

    2026-08-31 Affects <= 2.8.1 Patched in 2.8.2 Full record on Wordfence ↗
  45. Total processing card payments for WooCommerce <= 7.3 - Unauthenticated Server-Side Request Forgery

    2026-08-31 CVE-2026-16947 Affects <= 7.3 No patch available Full record on Wordfence ↗
  46. H HEL Online Classroom: AI-powered Online Classrooms Medium

    HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Information Exposure

    2026-08-31 CVE-2026-77010 Affects <= 1.0.3 No patch available Full record on Wordfence ↗
  47. User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor < 4.0.1 - Missing Authorization

    2026-08-31 CVE-2026-76548 Affects < 4.0.1 Patched in 4.0.1 Full record on Wordfence ↗
  48. Customer Reviews for WooCommerce < 5.118.0 - Unauthenticated Stored Cross-Site Scripting

    2026-08-31 CVE-2026-76585 Affects < 5.118.0 Patched in 5.118.0 Full record on Wordfence ↗
  49. Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) < 9.8.0 - Authenticated (Custom Role+) Remote Code Execution

    2026-08-31 CVE-2026-81766 Affects < 9.8.0 Patched in 9.8.0 Full record on Wordfence ↗
  50. O Oxygen Medium

    Oxygen 6.0 - 6.1.1 - Missing Authorization

    2026-08-31 Affects 6.0 - 6.1.1 Patched in 6.1.2 Full record on Wordfence ↗
  51. Groundhogg — CRM, Newsletters, and Marketing Automation < 4.5.13 - Unauthenticated Stored Cross-Site Scripting

    2026-08-31 CVE-2026-81660 Affects < 4.5.13 Patched in 4.5.13 Full record on Wordfence ↗
  52. Simple Membership <= 4.8.1 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Multisite Identity Binding

    2026-08-31 CVE-2026-77194 Affects <= 4.8.1 Patched in 4.8.2 Full record on Wordfence ↗
  53. WPvivid — Backup, Migration & Staging < 0.9.133 - Authenticated (Administrator+) Remote Code Execution

    2026-08-30 CVE-2026-19722 Affects < 0.9.133 Patched in 0.9.133 Full record on Wordfence ↗
  54. SOGO Add Script to Individual Pages Header Footer <= 3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

    2026-08-30 CVE-2026-14835 Affects <= 3.9 No patch available Full record on Wordfence ↗
  55. M MyHome Core Critical

    MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token

    2026-08-29 CVE-2026-15980 Affects <= 4.4.5 Patched in 4.4.6 Full record on Wordfence ↗
  56. C Custom User Registration Fields for WooCommerce Critical

    Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout

    2026-08-29 CVE-2026-15369 Affects <= 2.2.3 Patched in 2.2.4 Full record on Wordfence ↗
  57. SAML Single Sign On <= 5.4.6 - Unauthenticated Authentication Bypass via X.509 Certificate Poisoning

    2026-08-29 CVE-2026-75807 Affects <= 5.4.6 Patched in 5.4.7 Full record on Wordfence ↗
  58. SmartAIPress <= 1.2.0 - Authenticated (Subscriber+) Server-Side Request Forgery

    2026-08-29 CVE-2026-16600 Affects <= 1.2.0 No patch available Full record on Wordfence ↗
  59. MasterStudy LMS WordPress Plugin – for Online Courses and Education < 3.7.42 - Authenticated (Custom Role+) Insecure Direct Object Reference

    2026-08-29 CVE-2026-81200 Affects < 3.7.42 Patched in 3.7.42 Full record on Wordfence ↗
  60. User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor < 4.0.1 - Authenticated (Administrator+) PHP Object Injection

    2026-08-29 CVE-2026-76547 Affects < 4.0.1 Patched in 4.0.1 Full record on Wordfence ↗
  61. Newsletters < 4.17 - Cross-Site Request Forgery

    2026-08-29 CVE-2026-17522 Affects < 4.17 Patched in 4.17 Full record on Wordfence ↗
  62. WP Ultimate CSV Importer – WordPress CSV, XML & Excel Import < 9.0 - Authenticated (Administrator+) SQL Injection

    2026-08-29 CVE-2026-80488 Affects < 9.0 Patched in 9.0 Full record on Wordfence ↗
  63. H HEL Online Classroom: AI-powered Online Classrooms Medium

    HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Information Exposure

    2026-08-29 CVE-2026-77007 Affects <= 1.0.3 No patch available Full record on Wordfence ↗
  64. C Catfolders Document Gallery Pro Medium

    Catfolders Document Gallery Pro < 2.0.7 - Missing Authorization

    2026-08-29 CVE-2026-19430 Affects < 2.0.7 Patched in 2.0.7 Full record on Wordfence ↗
  65. Rank Math SEO – AI SEO Tools to Dominate SEO Rankings < 1.0.277 - Missing Authorization

    2026-08-29 CVE-2026-77786 Affects < 1.0.277 Patched in 1.0.277 Full record on Wordfence ↗
  66. Booking for Appointments and Events Calendar – Amelia 1.2.32 - 2.4.8 - Missing Authorization

    2026-08-29 CVE-2026-77704 Affects 1.2.32 - 2.4.8 Patched in 2.4.9 Full record on Wordfence ↗
  67. User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor < 4.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

    2026-08-29 CVE-2026-76546 Affects < 4.0.1 Patched in 4.0.1 Full record on Wordfence ↗
  68. A Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress High

    Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress 1.5.6 - 1.6.2 - Unauthenticated Booking Price Manipulation

    2026-08-29 CVE-2026-76586 Affects 1.5.6 - 1.6.2 Patched in 1.6.3 Full record on Wordfence ↗
  69. Tailored Tools <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting

    2026-08-28 CVE-2026-81765 Affects <= 3.0.2 Patched in 3.0.3 Full record on Wordfence ↗
  70. G GeotargetingWP Medium

    GeotargetingWP < 3.5.6.2 - Reflected Cross-Site Scripting

    2026-08-28 CVE-2026-14307 Affects < 3.5.6.2 Patched in 3.5.6.2 Full record on Wordfence ↗
  71. KiviCare – Clinic & Patient Management System (EHR) <= 4.5.4 - Unauthenticated Information Exposure

    2026-08-28 CVE-2026-13611 Affects <= 4.5.4 Patched in 4.5.5 Full record on Wordfence ↗
  72. User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission < 4.3.10 - Unauthenticated Information Exposure

    2026-08-28 CVE-2026-14567 Affects < 4.3.10 Patched in 4.3.10 Full record on Wordfence ↗
  73. OwnerRez Medium

    OwnerRez <= 1.2.6 - Missing Authorization

    2026-08-28 CVE-2026-81758 Affects <= 1.2.6 Patched in 1.3.0 Full record on Wordfence ↗
  74. S Super Store Finder High

    Super Store Finder <= 7.10 - Unauthenticated Stored Cross-Site Scripting

    2026-08-28 CVE-2026-81768 Affects <= 7.10 Patched in 7.11 Full record on Wordfence ↗
  75. WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards <= 5.5.81 - Unauthenticated SQL Injection

    2026-08-28 CVE-2026-81293 Affects <= 5.5.81 Patched in 5.5.82 Full record on Wordfence ↗
  76. Email Essentials <= 6.0.6 - Unauthenticated Stored Cross-Site Scripting

    2026-08-28 CVE-2026-81764 Affects <= 6.0.6 Patched in 6.0.7 Full record on Wordfence ↗
  77. Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress < 4.17.1 - Unauthenticated Arbitrary Shortcode Execution

    2026-08-28 CVE-2026-19848 Affects < 4.17.1 Patched in 4.17.1 Full record on Wordfence ↗
  78. Smart Marketing SMS and Newsletters Forms <= 5.1.24 - Unauthenticated SQL Injection

    2026-08-28 CVE-2026-81756 Affects <= 5.1.24 Patched in 5.1.25 Full record on Wordfence ↗
  79. Forminator Forms – Contact Form, Payment Form & Custom Form Builder < 1.57.1 - Unauthenticated Privilege Escalation

    2026-08-28 CVE-2026-19220 Affects < 1.57.1 Patched in 1.57.1 Full record on Wordfence ↗
  80. Forminator Forms – Contact Form, Payment Form & Custom Form Builder < 1.57.0.7 - Authenticated (Custom Role+) Privilege Escalation

    2026-08-28 CVE-2026-19222 Affects < 1.57.0.7 Patched in 1.57.0.7 Full record on Wordfence ↗
  81. Booking for Appointments and Events Calendar – Amelia 9.0 - 9.7 - Authenticated (Provider+) Arbitrary Provider Password Update

    2026-08-28 CVE-2026-14212 Affects 9.0 - 9.7 Patched in 9.8 Full record on Wordfence ↗
  82. Tickera – Sell Tickets & Manage Events <= 3.6.0.2 - Unauthenticated PHP Object Injection

    2026-08-28 CVE-2026-82226 Affects <= 3.6.0.2 Patched in 3.6.0.3 Full record on Wordfence ↗
  83. User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission < 4.3.10 - Authenticated (Editor+) PHP Object Injection

    2026-08-28 CVE-2026-14558 Affects < 4.3.10 Patched in 4.3.10 Full record on Wordfence ↗
  84. Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy < 5.0.14 - Authenticated (Shop Manager+) Remote Code Execution

    2026-08-28 CVE-2026-16576 Affects < 5.0.14 Patched in 5.0.14 Full record on Wordfence ↗
  85. Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment <= 2.7.6 - Missing Authorization

    2026-08-28 CVE-2026-81762 Affects <= 2.7.6 Patched in 2.7.7 Full record on Wordfence ↗
  86. StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce < 2.1.2 - Unauthenticated Arbitrary Price Manipulation

    2026-08-28 CVE-2026-78137 Affects < 2.1.2 Patched in 2.1.2 Full record on Wordfence ↗
  87. F Fluent Forms Pro Add On Pack Medium

    Fluent Forms Pro Add On Pack <= 6.2.12 - Missing Authorization

    2026-08-28 CVE-2026-81296 Affects <= 6.2.12 Patched in 6.2.13 Full record on Wordfence ↗
  88. Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates – WPLP Legal Pages < 3.7.1 - Unauthenticated Information Exposure

    2026-08-28 CVE-2026-16984 Affects < 3.7.1 Patched in 3.7.1 Full record on Wordfence ↗
  89. MW WP Form < 5.1.6 - Authenticated (Editor+) Stored Cross-Site Scripting

    2026-08-28 CVE-2026-78364 Affects < 5.1.6 Patched in 5.1.6 Full record on Wordfence ↗
  90. Affiliate Program Suite — SliceWP Affiliates <= 1.2.10 - Unauthenticated Stored Cross-Site Scripting

    2026-08-28 CVE-2026-82224 Affects <= 1.2.10 Patched in 1.2.11 Full record on Wordfence ↗
  91. WPBulky – WordPress Bulk Edit Post Types <= 1.2.2 - Authenticated (Contributor+) SQL Injection

    2026-08-28 CVE-2026-82227 Affects <= 1.2.2 Patched in 1.2.3 Full record on Wordfence ↗
  92. S SigmaForms Pro – AI Generated Forms Critical

    Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field

    2026-08-28 CVE-2026-14494 Affects <= 1.4.5 Patched in 1.4.6 Full record on Wordfence ↗
  93. GiveWP – Donation Plugin and Fundraising Platform <= 4.16.7.1 - Unauthenticated PHP Object Injection to Remote Code Execution

    2026-08-28 CVE-2026-82222 Affects <= 4.16.7.1 Patched in 4.16.7.2 Full record on Wordfence ↗
  94. WP OAuth Server ( Login with WordPress ) < 6.3.1 - Unauthenticated Information Exposure

    2026-08-28 CVE-2026-19715 Affects < 6.3.1 Patched in 6.3.1 Full record on Wordfence ↗
  95. Security Optimizer – The All-In-One Protection Plugin <= 1.6.6 - 2-Factor Authentication Bypass

    2026-08-28 CVE-2026-82228 Affects <= 1.6.6 Patched in 1.6.7 Full record on Wordfence ↗
  96. Hash Form – Drag & Drop Form Builder <= 1.4.2 - Unauthenticated Arbitrary File Upload

    2026-08-28 CVE-2026-81780 Affects <= 1.4.2 Patched in 1.4.3 Full record on Wordfence ↗
  97. LeadConnector <= 4.0.5 - Unauthenticated Stored Cross-Site Scripting

    2026-08-28 CVE-2026-81298 Affects <= 4.0.5 Patched in 4.0.6 Full record on Wordfence ↗
  98. Breeze Cache < 2.5.13 - Unauthenticated File Creation via Path Traversal

    2026-08-28 CVE-2026-79706 Affects < 2.5.13 Patched in 2.5.13 Full record on Wordfence ↗
  99. User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder < 5.2.5 - Authenticated (Subscriber+) Insecure Direct Object Reference

    2026-08-28 CVE-2026-79995 Affects < 5.2.5 Patched in 5.2.5 Full record on Wordfence ↗
  100. RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.9.8 - Authentication Bypass

    2026-08-28 CVE-2026-82225 Affects <= 6.0.9.8 Patched in 6.0.9.9 Full record on Wordfence ↗
  101. Content Mask 1.8.0 - 1.8.5.4 - Missing Authorization

    2026-08-28 CVE-2026-77003 Affects 1.8.0 - 1.8.5.4 Patched in 1.8.5.5 Full record on Wordfence ↗
  102. Directorist: AI-Powered Business Directory, Listings & Classified Ads 8.5 - 8.9.2 - Authenticated (Subscriber+) Arbitrary Image Move

    2026-08-28 CVE-2026-77757 Affects 8.5 - 8.9.2 Patched in 8.9.3 Full record on Wordfence ↗
  103. Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.57.1 - Unauthenticated Payment Bypass

    2026-08-28 CVE-2026-82220 Affects <= 1.57.1 Patched in 1.57.2 Full record on Wordfence ↗
  104. Tutor LMS – eLearning and online course solution < 4.0.6 - Authenticated (Custom Role+) Arbitrary File Read

    2026-08-28 CVE-2026-19093 Affects < 4.0.6 Patched in 4.0.6 Full record on Wordfence ↗
  105. F Fluent Forms Pro Add On Pack Medium

    Fluent Forms Pro Add On Pack <= 6.2.12 - Authenticated (Subscriber+) Privilege Escalation

    2026-08-28 CVE-2026-81297 Affects <= 6.2.12 Patched in 6.2.13 Full record on Wordfence ↗
  106. Return Refund and Exchange For WooCommerce < 4.6.4 - Missing Authorization

    2026-08-28 CVE-2026-77695 Affects < 4.6.4 Patched in 4.6.4 Full record on Wordfence ↗
  107. W WP Rocket Medium

    WP Rocket 3.23.1 - 3.23.3.2 - Unauthenticated Information Exposure

    2026-08-28 Affects 3.23.1 - 3.23.3.2 Patched in 3.23.3.3 Full record on Wordfence ↗
  108. Shared Files Pro < 1.7.68 & Shared Files Free < 1.7.67 - Unauthenticated Arbitrary File Deletion

    2026-08-28 CVE-2026-12513 Affects < 1.7.67 Patched in 1.7.67 Full record on Wordfence ↗
  109. S Shared Files Pro Critical

    Shared Files Pro < 1.7.68 & Shared Files Free < 1.7.67 - Unauthenticated Arbitrary File Deletion

    2026-08-28 CVE-2026-12513 Affects < 1.7.68 Patched in 1.7.68 Full record on Wordfence ↗
  110. Social Login, Social Sharing by miniOrange <= 7.8.2 - Unauthenticated Stored Cross-Site Scripting

    2026-08-28 CVE-2026-82229 Affects <= 7.8.2 Patched in 7.9.0 Full record on Wordfence ↗
  111. Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation

    2026-08-28 CVE-2026-19423 Affects 2.6.7 - 2.12.1 Patched in 2.13.0 Full record on Wordfence ↗
  112. 12 Step Meeting List 3.17 - 3.19.16 - Unauthenticated Stored Cross-Site Scripting

    2026-08-28 CVE-2026-78333 Affects 3.17 - 3.19.16 Patched in 3.19.17 Full record on Wordfence ↗
  113. Throws SPAM Away <= 3.8.2 - Unauthenticated SQL Injection

    2026-08-28 CVE-2026-81763 Affects <= 3.8.2 Patched in 3.9 Full record on Wordfence ↗
  114. CMP – Coming Soon & Maintenance Plugin by NiteoThemes < 4.1.18 - Authenticated (Editor+) Privilege Escalation

    2026-08-28 CVE-2026-13415 Affects < 4.1.18 Patched in 4.1.18 Full record on Wordfence ↗
  115. Pods – Custom Content Types and Fields < 3.3.9.1 - Authenticated (Author+) Remote Code Execution

    2026-08-28 CVE-2026-74851 Affects < 3.3.9.1 Patched in 3.3.9.1 Full record on Wordfence ↗
  116. Document Embedder – let visitors read files without downloading < 2.3.1 - Unauthenticated Arbitrary Document Download

    2026-08-28 CVE-2026-16567 Affects < 2.3.1 Patched in 2.3.1 Full record on Wordfence ↗
  117. S Simple Payment Medium

    Simple Payment <= 2.5.2 - Missing Authorization

    2026-08-28 CVE-2026-81767 Affects <= 2.5.2 Patched in 2.5.3 Full record on Wordfence ↗
  118. Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker < 11.2.4 - Authenticated (Contributor+) Insecure Direct Object Reference

    2026-08-28 CVE-2026-79615 Affects < 11.2.4 Patched in 11.2.4 Full record on Wordfence ↗
  119. AI Engine – The Chatbot, AI Framework & MCP for WordPress 3.4.0 - 3.7.1 - Missing Authorization to Unauthenticated Arbitrary AI Query Execution

    2026-08-28 CVE-2026-75798 Affects 3.4.0 - 3.7.1 Patched in 3.7.2 Full record on Wordfence ↗
  120. Slider Hero with Video Background, Animation < 9.1.3 - Unauthenticated Stored Cross-Site Scripting

    2026-08-28 CVE-2026-76789 Affects < 9.1.3 Patched in 9.1.3 Full record on Wordfence ↗
  121. Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates < 2.7.2 - Unauthenticated Server-Side Request Forgery

    2026-08-28 CVE-2026-17565 Affects < 2.7.2 Patched in 2.7.2 Full record on Wordfence ↗
  122. User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder < 5.2.6 - Authenticated (Custom Role+) Privilege Escalation

    2026-08-28 CVE-2026-79996 Affects < 5.2.6 Patched in 5.2.6 Full record on Wordfence ↗
  123. W WPMU DEV Dashboard Critical

    WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion

    2026-08-27 CVE-2026-76581 Affects <= 5.0.1 Patched in 5.0.2 Full record on Wordfence ↗
  124. A Avada (Fusion) Builder Medium

    Avada (Fusion) Builder <= 3.15.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'size' Shortcode Attribute

    2026-08-27 CVE-2026-16654 Affects <= 3.15.6 Patched in 3.16 Full record on Wordfence ↗
  125. Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters

    2026-08-27 CVE-2026-16759 Affects <= 4.0.5 Patched in 4.0.6 Full record on Wordfence ↗
  126. One User Avatar | User Profile Picture <= 2.5.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter

    2026-08-27 CVE-2026-18983 Affects <= 2.5.4 Patched in 2.5.5 Full record on Wordfence ↗
  127. LiteSpeed Cache <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via Comment Content

    2026-08-27 CVE-2026-18978 Affects <= 7.8.1 Patched in 7.9 Full record on Wordfence ↗
  128. LiteSpeed Cache <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes

    2026-08-27 CVE-2026-3129 Affects <= 7.7 Patched in 7.8 Full record on Wordfence ↗
  129. Forminator Forms <= 1.57.0.1 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field

    2026-08-27 CVE-2026-18324 Affects <= 1.57.0.1 Patched in 1.57.0.2 Full record on Wordfence ↗
  130. TranslatePress <= 3.3.3 - Unauthenticated Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser

    2026-08-27 CVE-2026-76053 Affects <= 3.3.3 Patched in 3.3.4 Full record on Wordfence ↗
  131. Optimole <= 4.2.10 - Unauthenticated Stored Cross-Site Scripting via 'a' (above_fold_images) Parameter

    2026-08-27 CVE-2026-77365 Affects <= 4.2.10 Patched in 4.2.11 Full record on Wordfence ↗
  132. Smart Slider 3 <= 3.5.1.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'slider' Block Attribute

    2026-08-27 CVE-2026-15798 Affects <= 3.5.1.38 Patched in 3.5.1.39 Full record on Wordfence ↗
  133. RestrictMate – Restrict Page, Post and any Content ( Content Restriction and Membership Plugin) < 1.3.0 - Unauthenticated Privilege Escalation

    2026-08-27 CVE-2026-13598 Affects < 1.3.0 Patched in 1.3.0 Full record on Wordfence ↗
  134. Frontend Admin by DynamiApps < 3.29.11 - Authenticated (Subscriber+) Membership Plan Deletion

    2026-08-27 CVE-2026-81346 Affects < 3.29.11 Patched in 3.29.11 Full record on Wordfence ↗
  135. Envira Gallery <= 1.12.4 - Authenticated (Author+) Stored Cross-Site Scripting via Gallery Description

    2026-08-27 CVE-2026-3423 Affects <= 1.12.4 Patched in 1.12.5 Full record on Wordfence ↗
  136. Defender Security – Malware Scanner, Login Security & Firewall < 6.2.0 - Authenticated (Administrator+) Remote Code Execution

    2026-08-27 CVE-2026-19225 Affects < 6.2.0 Patched in 6.2.0 Full record on Wordfence ↗
  137. W WP Rocket High

    WP Rocket <= 3.21.0.1 - Unauthenticated Stored Cross-Site Scripting via Picture Source Attributes in rocket_beacon Endpoint

    2026-08-27 CVE-2026-5934 Affects <= 3.21.0.1 Patched in 3.21.1 Full record on Wordfence ↗
  138. Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.276 - Authenticated (Author+) Remote Code Execution

    2026-08-27 CVE-2026-81757 Affects <= 1.0.276 Patched in 1.0.277 Full record on Wordfence ↗
  139. WP Job Portal – AI-Powered Recruitment System for Company or Job Board website <= 2.5.9 - Authenticated (Subscriber+) Insecure Direct Object Reference

    2026-08-27 CVE-2026-81299 Affects <= 2.5.9 Patched in 2.6.0 Full record on Wordfence ↗
  140. Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions < 8.5.5 - Unauthenticated Insecure Direct Object Reference

    2026-08-27 CVE-2026-80311 Affects < 8.5.5 Patched in 8.5.5 Full record on Wordfence ↗
  141. CMP – Coming Soon & Maintenance Plugin by NiteoThemes < 4.1.18 - Missing Authorization to Unauthenticated Settings Change

    2026-08-27 CVE-2026-13414 Affects < 4.1.18 Patched in 4.1.18 Full record on Wordfence ↗
  142. Smush – Image Optimization, Compression, Lazy Load, WebP & CDN < 4.3.2 - Authenticated (Administrator+) Remote Code Execution

    2026-08-27 CVE-2026-19223 Affects < 4.3.2 Patched in 4.3.2 Full record on Wordfence ↗
  143. Newsletters < 4.17 - Insufficient Authorization

    2026-08-27 CVE-2026-17520 Affects < 4.17 Patched in 4.17 Full record on Wordfence ↗
  144. MStore API – Create Native Android & iOS Apps On The Cloud < 4.21.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Completion

    2026-08-27 CVE-2026-18233 Affects < 4.21.1 Patched in 4.21.1 Full record on Wordfence ↗
  145. Finale Lite – Sales Countdown Timer & Discount for WooCommerce < 2.21.0 - Authenticated (Subscriber+) Information Exposure

    2026-08-27 CVE-2026-78138 Affects < 2.21.0 Patched in 2.21.0 Full record on Wordfence ↗
  146. Workeera – AI Job Board with Applicant Tracking System (ATS) < 1.0.6 - Authenticated (Subscriber+) Arbitrary File Upload

    2026-08-27 CVE-2026-77018 Affects < 1.0.6 Patched in 1.0.6 Full record on Wordfence ↗
  147. J JetEngine High

    JetEngine <= 3.8.14.2 - Unauthenticated Stored Cross-Site Scripting

    2026-08-27 CVE-2026-81760 Affects <= 3.8.14.2 Patched in 3.8.14.3 Full record on Wordfence ↗
  148. 爱采集数据采集和发布插件 <= 1.0.0 - Unauthenticated Arbitrary File Read

    2026-08-27 CVE-2026-77012 Affects <= 1.0.0 No patch available Full record on Wordfence ↗
  149. UpdraftPlus: WP Backup & Migration Plugin < 1.26.7 - Cross-Site Request Forgery

    2026-08-27 CVE-2026-76549 Affects < 1.26.7 Patched in 1.26.7 Full record on Wordfence ↗
  150. AI Engine – The Chatbot, AI Framework & MCP for WordPress 3.3.3 - 3.7.1 - Authenticated (Subscriber+) Arbitrary File Read

    2026-08-27 CVE-2026-75797 Affects 3.3.3 - 3.7.1 Patched in 3.7.2 Full record on Wordfence ↗
  151. Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.8.0 - Unauthenticated Captcha Bypass

    2026-08-27 CVE-2026-81777 Affects <= 6.8.0 Patched in 6.8.1 Full record on Wordfence ↗
  152. Workeera – AI Job Board with Applicant Tracking System (ATS) < 1.0.6 - Authenticated (Subscriber+) Arbitrary File Read

    2026-08-27 CVE-2026-77017 Affects < 1.0.6 Patched in 1.0.6 Full record on Wordfence ↗
  153. Booking for Appointments and Events Calendar <= 2.2 - Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission

    2026-08-27 CVE-2026-6286 Affects <= 2.2 Patched in 2.2.1 Full record on Wordfence ↗
  154. E ElementsKit Pro Medium

    ElementsKit Pro <= 4.10.1 - Unauthenticated Stored Cross-Site Scripting via 's' Parameter

    2026-08-27 CVE-2026-4246 Affects <= 4.10.1 Patched in 4.10.2 Full record on Wordfence ↗
  155. Smush – Image Optimization, Compression, Lazy Load, WebP & CDN <= 4.2.0 - Unauthenticated Denial of Service

    2026-08-27 CVE-2026-81285 Affects <= 4.2.0 Patched in 4.3.0 Full record on Wordfence ↗
  156. Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist < 3.1.4 - Authenticated (Subscriber+) Insecure Direct Object Reference

    2026-08-27 CVE-2026-78139 Affects < 3.1.4 Patched in 3.1.4 Full record on Wordfence ↗
  157. Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar <= 5.5.0 - Missing Authorization

    2026-08-27 CVE-2026-81759 Affects <= 5.5.0 Patched in 5.6.0 Full record on Wordfence ↗
  158. M Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce Medium

    Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce <= 0.4.62 - Authenticated (Subscriber+) Insecure Direct Object Reference

    2026-08-27 CVE-2026-16568 Affects <= 0.4.62 Patched in 0.4.63 Full record on Wordfence ↗
  159. Advanced Custom Fields: Extended <= 0.9.2.6 - Missing Authorization

    2026-08-27 CVE-2026-81284 Affects <= 0.9.2.6 Patched in 0.9.2.7 Full record on Wordfence ↗
  160. wpForo Forum <= 2.4.17 - Unauthenticated SQL Injection via 'referer' Parameter

    2026-08-27 CVE-2026-5097 Affects <= 2.4.17 Patched in 3.0.0 Full record on Wordfence ↗
  161. MasterStudy LMS WordPress Plugin – for Online Courses and Education < 3.7.43 - Unauthenticated Open Redirect

    2026-08-27 CVE-2026-81342 Affects < 3.7.43 Patched in 3.7.43 Full record on Wordfence ↗
  162. H HEL Online Classroom: AI-powered Online Classrooms High

    HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Missing Authorization to Unauthenticated Settings Update

    2026-08-27 CVE-2026-77008 Affects <= 1.0.3 No patch available Full record on Wordfence ↗
  163. Everest Forms <= 3.4.4 - Unauthenticated Server-Side Request Forgery via Upload Field 'Previous Value'

    2026-08-27 CVE-2026-5096 Affects <= 3.4.4 Patched in 3.4.5 Full record on Wordfence ↗
  164. Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress <= 5.9.33 - Unauthenticated Stored Cross-Site Scripting

    2026-08-27 CVE-2026-81290 Affects <= 5.9.33 Patched in 5.9.34 Full record on Wordfence ↗
  165. A All-in-One WP Migration Unlimited Extension Medium

    All-in-One WP Migration Unlimited Extension <= 2.84 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'ai1wm_backups_path' Parameter

    2026-08-27 CVE-2026-6128 Affects <= 2.84 Patched in 2.85 Full record on Wordfence ↗
  166. Customer Reviews for WooCommerce <= 5.106.0 - Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form

    2026-08-27 CVE-2026-6176 Affects <= 5.106.0 Patched in 5.107.0 Full record on Wordfence ↗
  167. GiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

    2026-08-27 CVE-2026-5510 Affects <= 4.14.4 Patched in 4.14.5 Full record on Wordfence ↗
  168. MStore API – Create Native Android & iOS Apps On The Cloud < 4.21.1 - Missing Authorization

    2026-08-27 CVE-2026-18234 Affects < 4.21.1 Patched in 4.21.1 Full record on Wordfence ↗
  169. MasterStudy LMS WordPress Plugin – for Online Courses and Education < 3.7.40 - Unauthenticated Payment Bypass

    2026-08-27 CVE-2026-81026 Affects < 3.7.40 Patched in 3.7.40 Full record on Wordfence ↗
  170. Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar <= 5.5.0 - Missing Authorization

    2026-08-27 CVE-2026-81761 Affects <= 5.5.0 Patched in 5.6.0 Full record on Wordfence ↗
  171. Forminator Forms – Contact Form, Payment Form & Custom Form Builder < 1.57.0.5 - Authenticated (Administrator+) Remote Code Execution

    2026-08-27 CVE-2026-19221 Affects < 1.57.0.5 Patched in 1.57.0.5 Full record on Wordfence ↗
  172. F Formidable Charts High

    Formidable Charts <= 2.0.1 - Unauthenticated Arbitrary File Read via 'frm_graph' Parameter

    2026-08-26 CVE-2026-15990 Affects <= 2.0.1 Patched in 2.0.2 Full record on Wordfence ↗
  173. Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker < 4.0.7 - Authenticated (Subscriber+) Insecure Direct Object Reference

    2026-08-26 CVE-2026-74929 Affects < 4.0.7 Patched in 4.0.7 Full record on Wordfence ↗
  174. Shared Files Pro < 1.7.70 & Shared Files Free < 1.7.67 - Unauthenticated Limited File Upload

    2026-08-26 CVE-2026-12514 Affects < 1.7.67 Patched in 1.7.67 Full record on Wordfence ↗
  175. S Shared Files Pro Medium

    Shared Files Pro < 1.7.70 & Shared Files Free < 1.7.67 - Unauthenticated Limited File Upload

    2026-08-26 CVE-2026-12514 Affects < 1.7.70 Patched in 1.7.70 Full record on Wordfence ↗
  176. Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce < 4.1.22 - Unauthenticated Information Exposure

    2026-08-26 CVE-2026-13172 Affects < 4.1.22 Patched in 4.1.22 Full record on Wordfence ↗
  177. Kirki – Freeform Page Builder, Website Builder & Customizer < 6.0.14 - Missing Authorization

    2026-08-26 CVE-2026-77754 Affects < 6.0.14 Patched in 6.0.14 Full record on Wordfence ↗
  178. Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker 2.2.0 - 4.0.6 - Authenticated (Subscriber+) Insecure Direct Object Reference

    2026-08-26 CVE-2026-74930 Affects 2.2.0 - 4.0.6 Patched in 4.0.7 Full record on Wordfence ↗
  179. S Suggestion Engine for WooCommerce Medium

    Suggestion Engine for WooCommerce <= 2.0.11 - Authenticated (Contributor+) SQL Injection

    2026-08-26 CVE-2026-81277 Affects <= 2.0.11 Patched in 2.0.12 Full record on Wordfence ↗
  180. Booking for Appointments and Events Calendar – Amelia < 2.4.7 - Missing Authorization

    2026-08-26 CVE-2026-14216 Affects < 2.4.7 Patched in 2.4.7 Full record on Wordfence ↗
  181. F Fluent Boards Pro High

    Fluent Boards Pro <= 2.0.11 - Authenticated (Editor+) Arbitrary File Upload

    2026-08-26 CVE-2026-78274 Affects <= 2.0.11 Patched in 2.0.12 Full record on Wordfence ↗
  182. F Fluent Boards Pro Medium

    Fluent Boards Pro <= 2.0.11 - Authenticated (Editor+) Arbitrary File Deletion

    2026-08-26 CVE-2026-78275 Affects <= 2.0.11 Patched in 2.0.12 Full record on Wordfence ↗
  183. RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login < 6.0.9.4 - Authenticated (Administrator+) SQL Injection

    2026-08-26 CVE-2026-77790 Affects < 6.0.9.4 Patched in 6.0.9.4 Full record on Wordfence ↗
  184. F Fluent Player Pro Low

    FluentPlayer Pro <= 1.3.2 - Missing Authorization

    2026-08-26 CVE-2026-81272 Affects <= 1.3.2 Patched in 1.4.0 Full record on Wordfence ↗
  185. Kali Forms — Contact Form & Drag-and-Drop Builder <= 2.4.23 - Missing Authorization

    2026-08-26 CVE-2026-81276 Affects <= 2.4.23 Patched in 2.4.24 Full record on Wordfence ↗
  186. Ditty – Responsive News Tickers, Sliders, and Lists <= 3.1.67 - Missing Authorization

    2026-08-26 CVE-2026-81274 Affects <= 3.1.67 Patched in 3.1.69 Full record on Wordfence ↗
  187. F Fluent Booking Pro Medium

    FluentBooking Pro <= 2.2.4 - Cross-Site Request Forgery

    2026-08-26 CVE-2026-81273 Affects <= 2.2.4 Patched in 2.2.5 Full record on Wordfence ↗
  188. GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.176 - Cross-Site Request Forgery

    2026-08-26 CVE-2026-81271 Affects <= 2.8.176 Patched in 2.8.177 Full record on Wordfence ↗
  189. SureFeedback Client Site <= 1.2.12 - Authenticated (Subscriber+) Information Exposure

    2026-08-26 CVE-2026-80433 Affects <= 1.2.12 Patched in 1.2.13 Full record on Wordfence ↗
  190. Simple Newsletter Plugin – Noptin < 4.3.3 - Missing Authorization

    2026-08-26 CVE-2026-78146 Affects < 4.3.3 Patched in 4.3.3 Full record on Wordfence ↗
  191. S SmilePass Selfie Login Critical

    SmilePass Selfie Login <= 1.0.2 - Authentication Bypass to Administrator

    2026-08-26 CVE-2026-77002 Affects <= 1.0.2 No patch available Full record on Wordfence ↗
  192. Push Notification for Post and BuddyPress <= 3.20 - Missing Authorization

    2026-08-26 CVE-2026-81279 Affects <= 3.20 Patched in 3.21 Full record on Wordfence ↗
  193. WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System < 3.0.18 - Missing Authorization

    2026-08-26 CVE-2026-14550 Affects < 3.0.18 Patched in 3.0.18 Full record on Wordfence ↗
  194. F Fluent Boards Pro Medium

    Fluent Boards Pro <= 2.0.11 - Authenticated (Subscriber+) Stored Cross-Site Scripting

    2026-08-26 CVE-2026-78273 Affects <= 2.0.11 Patched in 2.0.12 Full record on Wordfence ↗
  195. WCFM Marketplace – Multivendor Marketplace for WooCommerce < 3.8.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Refund Request

    2026-08-26 CVE-2026-77701 Affects < 3.8.2 Patched in 3.8.2 Full record on Wordfence ↗
  196. F Fluent Boards Pro Medium

    Fluent Boards Pro <= 2.0.11 - Authenticated (Editor+) PHP Object Injection

    2026-08-26 CVE-2026-78276 Affects <= 2.0.11 Patched in 2.0.12 Full record on Wordfence ↗
  197. Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1066 - Missing Authorization

    2026-08-26 CVE-2026-13406 Affects < 1.7.1066 Patched in 1.7.1066 Full record on Wordfence ↗
  198. Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1066 - Authenticated (Contributor+) Stored Cross-Site Scripting

    2026-08-26 CVE-2026-19226 Affects < 1.7.1066 Patched in 1.7.1066 Full record on Wordfence ↗
  199. Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App 4.0.0-beta.1 - Missing Authorization to Authenticated (Subscriber+) Settings Change

    2026-08-26 CVE-2026-81278 Affects 4.0.0-beta.1 Patched in 4.0.1 Full record on Wordfence ↗
  200. C Classified Listing - Mobile Number Verification High

    Classified Listing - Mobile Number Verification <= 1.6.0 - Unauthenticated Authentication Bypass via Firebase OTP Login

    2026-08-25 CVE-2026-15985 Affects <= 1.6.0 Patched in 1.7.0 Full record on Wordfence ↗

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Severity is the CVSS rating from the feed. "Affects" is the vulnerable version range; running a version in that range without the patched release means the hole is live on your site.