6.4 CVE-2026-15798
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slider' Block...

2026-08-28T20:17:22.460

6.4 CVE-2026-16654
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'size'...

2026-08-28T20:17:22.610

6.5 CVE-2026-16759
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote...

2026-08-28T16:17:07.720

7.2 CVE-2026-18324
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress...

2026-08-28T16:17:07.870

7.2 CVE-2026-18978
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content...

2026-08-28T20:17:23.680

7.5 CVE-2026-18983
The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting...

2026-08-28T20:17:23.810

6.4 CVE-2026-3129
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>`...

2026-08-29T00:16:37.263

7.2 CVE-2026-76053
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is...

2026-08-28T20:19:54.480

7.2 CVE-2026-77365
The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization...

2026-08-28T16:18:26.437

6.4 CVE-2026-82081
wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during...

2026-08-28T16:18:31.363

9.8 CVE-2026-82082
NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote...

2026-08-28T18:46:13.563

CVE-2026-82089
The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because...

2026-08-28T20:20:14.710

CVE-2026-82090
Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the...

2026-08-28T20:20:14.833

6.8 CVE-2026-12513
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do...

2026-08-28T18:43:25.883

5.3 CVE-2026-12514
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do...

2026-08-28T18:40:31.630

7.2 CVE-2026-14558
The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions...

2026-08-28T18:40:31.630

5.3 CVE-2026-14567
The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search...

2026-08-28T18:40:31.630

7.5 CVE-2026-19084
The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating...

2026-08-28T18:43:25.883

8.1 CVE-2026-19423
The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when...

2026-08-28T18:43:25.883

9 CVE-2026-40541
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability...

2026-08-28T16:17:57.600

6.1 CVE-2026-4246
The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 's' parameter...

2026-08-28T20:17:39.897