Plugin Pulse

Plugin vulnerabilities

Recently disclosed security vulnerabilities in WordPress plugins, newest first: what the issue is, which versions it hits, and the release that fixes it. The plugin directory itself never shows you any of this.

  1. W W3SC Elementor to Zoho CRM Medium

    W3SC Elementor to Zoho CRM <= 2.2.0 - Cross-Site Request Forgery to Settings Update

    2026-07-17 CVE-2026-9734 Affects <= 2.2.0 No patch available Full record on Wordfence ↗
  2. HubSpot All-In-One Marketing <= 11.3.62 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Localized Script

    2026-07-16 CVE-2026-9656 Affects <= 11.3.62 Patched in 11.3.64 Full record on Wordfence ↗
  3. WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter

    2026-07-16 CVE-2026-15094 Affects <= 2.3.2 Patched in 2.3.3 Full record on Wordfence ↗
  4. pCloud WP Backup <= 2.0.3 - Missing Authorization on the 'start_backup' AJAX Method to Authenticated (Subscriber+) Arbitrary File Read

    2026-07-16 CVE-2026-14503 Affects <= 2.0.3 Patched in 2.0.4 Full record on Wordfence ↗
  5. ChatHelp <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes

    2026-07-16 CVE-2026-15759 Affects <= 3.5.1 Patched in 3.5.2 Full record on Wordfence ↗
  6. LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints

    2026-07-16 CVE-2026-13765 Affects <= 4.4.1 Patched in 4.4.2 Full record on Wordfence ↗
  7. ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Company Location Creation via wp_ajax_erp-company-location AJAX Handler

    2026-07-16 CVE-2026-15349 Affects <= 1.17.6 Patched in 1.17.7 Full record on Wordfence ↗
  8. Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 - Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion

    2026-07-16 CVE-2026-13352 Affects <= 4.16.18 Patched in 4.16.19 Full record on Wordfence ↗
  9. N Ninja Forms - Excel Export Medium

    Ninja Forms - Excel Export <= 3.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'filter' Parameter

    2026-07-16 CVE-2026-15161 Affects <= 3.3.6 Patched in 3.3.7 Full record on Wordfence ↗
  10. Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameter

    2026-07-16 CVE-2026-15457 Affects <= 6.0.13 Patched in 6.0.14 Full record on Wordfence ↗
  11. Fense Proxy & VPN Blocker <= 3.0.1 - Missing Authorization to Unauthenticated Plugin Option/Transient Deletion via fense_bpvt_save_settings AJAX Action

    2026-07-16 CVE-2026-8616 Affects <= 3.0.1 Patched in 3.0.2 Full record on Wordfence ↗
  12. Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value

    2026-07-16 CVE-2026-15395 Affects <= 2.4.18 Patched in 2.4.19 Full record on Wordfence ↗
  13. N Ninja Forms - Excel Export Medium

    Ninja Forms - Excel Export <= 3.3.6 - Missing Authorization to Authenticated (Subscriber+) XLS Write via Path Traversal

    2026-07-16 CVE-2026-15160 Affects <= 3.3.6 Patched in 3.3.7 Full record on Wordfence ↗
  14. N Ninja Forms - Excel Export Medium

    Ninja Forms - Excel Export <= 3.3.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Data Disclosure via 'spreadsheet_export_form_id' Parameter

    2026-07-16 CVE-2026-15159 Affects <= 3.3.6 Patched in 3.3.7 Full record on Wordfence ↗
  15. W WooCommerce Placetopay Gateway Belice Medium

    WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via 'redirect-url'

    2026-07-16 CVE-2026-11324 Affects <= 3.2.2 No patch available Full record on Wordfence ↗
  16. W WooCommerce Placetopay Gateway Ecuador Medium

    WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via 'redirect-url'

    2026-07-16 CVE-2026-11324 Affects <= 3.2.2 No patch available Full record on Wordfence ↗
  17. W WooCommerce Placetopay Gateway Colombia Medium

    WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via 'redirect-url'

    2026-07-16 CVE-2026-11324 Affects <= 3.2.2 No patch available Full record on Wordfence ↗
  18. W WooCommerce Placetopay Gateway Uruguay Medium

    WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via 'redirect-url'

    2026-07-16 CVE-2026-11324 Affects <= 3.2.2 No patch available Full record on Wordfence ↗
  19. W WooCommerce Placetopay Gateway Medium

    WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via 'redirect-url'

    2026-07-16 CVE-2026-11324 Affects <= 3.2.2 No patch available Full record on Wordfence ↗
  20. W WooCommerce Placetopay Gateway Honduras Medium

    WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via 'redirect-url'

    2026-07-16 CVE-2026-11324 Affects <= 3.2.2 No patch available Full record on Wordfence ↗
  21. Smart Custom Fields <= 5.0.7 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title

    2026-07-16 CVE-2026-2594 Affects <= 5.0.7 Patched in 5.0.8 Full record on Wordfence ↗
  22. B Bricksforge Critical

    Bricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter

    2026-07-16 CVE-2026-14956 Affects <= 3.1.8.6 Patched in 3.1.8.7 Full record on Wordfence ↗
  23. Booking for Appointments and Events Calendar – Amelia <= 2.4.3 - Authenticated (Custom+) SQL Injection via Customer Import

    2026-07-16 CVE-2026-14782 Affects <= 2.4.3 Patched in 2.4.4 Full record on Wordfence ↗
  24. D Digits: WordPress Mobile Number Signup and Login High

    Digits: WordPress Mobile Number Signup and Login <= 9.1.0.5 - Authenticated (Subscriber+) Privilege Escalation via 'digits_reg_userrole' Parameter

    2026-07-15 CVE-2026-13741 Affects <= 9.1.0.5 Patched in 9.1.0.6 Full record on Wordfence ↗
  25. Loco Translate <= 2.8.5 - Cross-Site Request Forgery to Remote Code Execution via 'template' Parameter

    2026-07-15 CVE-2026-15005 Affects <= 2.8.5 Patched in 2.8.6 Full record on Wordfence ↗
  26. WPFunnels <= 3.12.8 - Authenticated (Funnel Manager+) Privilege Escalation via 'group_id' Path Parameter

    2026-07-15 CVE-2026-15103 Affects <= 3.12.8 Patched in 3.12.9 Full record on Wordfence ↗
  27. WP Bulk Delete <= 1.4.2 - Authenticated (Administrator+) SQL Injection via 'delete_user_roles' Parameter

    2026-07-15 CVE-2026-15727 Affects <= 1.4.2 Patched in 1.4.3 Full record on Wordfence ↗
  28. SysBasics Customize My Account for WooCommerce <= 4.4.14 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'row_type' Parameter

    2026-07-15 CVE-2026-15324 Affects <= 4.4.14 Patched in 4.5.0 Full record on Wordfence ↗
  29. wpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'location' Profile Field

    2026-07-15 CVE-2026-15021 Affects <= 3.1.1 Patched in 3.1.2 Full record on Wordfence ↗
  30. WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter

    2026-07-15 CVE-2026-15106 Affects <= 8.5.6 Patched in 8.5.7 Full record on Wordfence ↗
  31. WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function

    2026-07-15 CVE-2026-15610 Affects <= 8.5.6 Patched in 8.5.7 Full record on Wordfence ↗
  32. Tickera <= 3.6.0.0 - Authenticated (Staff+) SQL Injection via 's' Parameter

    2026-07-15 CVE-2026-13754 Affects <= 3.6.0.0 Patched in 3.6.0.1 Full record on Wordfence ↗
  33. Uncanny Automator <= 7.3.1.4 - Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field Token

    2026-07-15 CVE-2026-15008 Affects <= 7.3.1.4 Patched in 7.4.0 Full record on Wordfence ↗
  34. WP TripAdvisor Review Slider <= 14.6 - Authenticated (Administrator+) SQL Injection via 'filtersource' Parameter

    2026-07-15 CVE-2026-15651 Affects <= 14.6 Patched in 14.7 Full record on Wordfence ↗
  35. WP Delicious <= 1.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'steps' Block Attribute

    2026-07-15 CVE-2026-15099 Affects <= 1.10.2 Patched in 1.10.3 Full record on Wordfence ↗
  36. Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array

    2026-07-15 CVE-2026-15022 Affects <= 4.0.0 Patched in 4.0.1 Full record on Wordfence ↗
  37. Tickera <= 3.6.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute

    2026-07-15 CVE-2026-13755 Affects <= 3.6.0.0 Patched in 3.6.0.1 Full record on Wordfence ↗
  38. The Cache Purger <= 2.3.20 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Log Deletion via 'the_log_purge' Parameter

    2026-07-15 CVE-2026-15350 Affects <= 2.3.20 Patched in 2.3.21 Full record on Wordfence ↗
  39. Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameter

    2026-07-15 CVE-2026-13767 Affects <= 11.2.0 Patched in 11.2.1 Full record on Wordfence ↗
  40. B Breakdance High

    Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting via Webhook Action Details

    2026-07-15 CVE-2026-7543 Affects <= 2.7.1 Patched in 2.7.2 Full record on Wordfence ↗
  41. SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'sort_field' Parameter

    2026-07-15 CVE-2026-15458 Affects <= 7.3.1 Patched in 7.3.2 Full record on Wordfence ↗
  42. SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter

    2026-07-15 CVE-2026-15445 Affects <= 7.3.1 Patched in 7.3.2 Full record on Wordfence ↗
  43. RPB Chessboard <= 8.1.2 - Unauthenticated Stored Cross-Site Scripting via Comment Content

    2026-07-15 CVE-2026-13042 Affects <= 8.1.2 Patched in 8.1.3 Full record on Wordfence ↗
  44. Product Feed Manager For WooCommerce <= 7.6.1 - Reflected Cross-Site Scripting via 's' Search Parameter

    2026-07-15 CVE-2026-15306 Affects <= 7.6.1 Patched in 7.6.2 Full record on Wordfence ↗
  45. MxChat <= 3.2.10 - Authenticated (Admin+) Stored Cross-Site Scripting via 'intro_message' Setting

    2026-07-15 CVE-2026-13005 Affects <= 3.2.10 Patched in 3.2.11 Full record on Wordfence ↗
  46. MultiVendorX <= 5.0.9 - Authenticated (Store Owner+) SQL Injection via 'order_by' Parameter

    2026-07-15 CVE-2026-12941 Affects <= 5.0.9 Patched in 5.0.10 Full record on Wordfence ↗
  47. Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Block Attribute

    2026-07-15 CVE-2026-15652 Affects <= 3.1.6 Patched in 3.1.7 Full record on Wordfence ↗
  48. Catch Themes Demo Import <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Single Plugin Installation via 'activate_plugin' Parameter

    2026-07-15 CVE-2026-15336 Affects <= 3.3 Patched in 3.4 Full record on Wordfence ↗
  49. List category posts <= 0.95.0 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via 'post_status' Shortcode Attribute

    2026-07-15 CVE-2026-12434 Affects <= 0.95.0 Patched in 0.96.0 Full record on Wordfence ↗
  50. Landing Page Builder <= 1.5.3.6 - Cross-Site Request Forgery to ulpb_admin_data AJAX Action

    2026-07-15 CVE-2026-12409 Affects <= 1.5.3.6 Patched in 1.5.3.7 Full record on Wordfence ↗

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Severity is the CVSS rating from the feed. "Affects" is the vulnerable version range; running a version in that range without the patched release means the hole is live on your site.