6.4 CVE-2026-15798
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slider' Block...
6.4 CVE-2026-16654
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'size'...
6.5 CVE-2026-16759
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote...
7.2 CVE-2026-18324
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress...
7.2 CVE-2026-18978
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content...
7.5 CVE-2026-18983
The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
6.4 CVE-2026-3129
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>`...
7.2 CVE-2026-76053
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is...
7.2 CVE-2026-77365
The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization...
6.4 CVE-2026-82081
wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during...
9.8 CVE-2026-82082
NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote...
CVE-2026-82089
The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because...
CVE-2026-82090
Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the...
6.8 CVE-2026-12513
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do...
5.3 CVE-2026-12514
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do...
7.2 CVE-2026-14558
The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions...
5.3 CVE-2026-14567
The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search...
7.5 CVE-2026-19084
The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating...
8.1 CVE-2026-19423
The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when...
9 CVE-2026-40541
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability...
6.1 CVE-2026-4246
The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 's' parameter...