ZeroHour

Vulnerabilities

1,181 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-89027
miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthent

miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification. Attackers can force the plugin to use Basic HTTP authentication regardless of configured JWT or API token settings, then exploit distinguishable error codes and the absence of rate limiting to perform unthrottled username enumeration and credential guessing attacks.

NVD description · AI analysis pending
6.9
  • WordPress
CVE-2026-89307
The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, en

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).

NVD description · AI analysis pending
5.1
  • WordPress
CVE-2026-87793
The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file, allowing an unauthenticated at

The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file, allowing an unauthenticated attacker to execute arbitrary JavaScript in a victim's browser via a crafted URL containing a malicious archive parameter.

NVD description · AI analysis pending
5.1
  • WordPress
CVE-2026-87792
Unauthenticated Authorization Bypass in Design Scuole Italia WordPress Theme

The Design Scuole Italia WordPress theme, a theme purpose-built for Italian school websites, contains multiple missing-authorization flaws (CWE-862) in its dsi_pdf_generator and dsi_csv_generator functions, resulting in sensitive-information exposure (CWE-200). An unauthenticated remote attacker can invoke these PDF/CSV export functions directly to retrieve restricted 'Circolare' (school circular/notice) content and data belonging to registered users without any credentials. Exploitation is further eased by an unauthenticated RSS feed at /circolare/feed/, which makes restricted circular content trivially harvestable in bulk. The issue is rated CVSS 4.0 8.7 (high) because it is network-exploitable with no privileges, no user interaction, and high confidentiality impact. No public proof of concept is known, the flaw is not in CISA's KEV catalog, and no exploitation in the wild has been reported.

Do: Update the Design Scuole Italia theme to the latest available release as soon as a patched version is published, and verify with the maintainers which version fixes the dsi_pdf_generator/dsi_csv_generator flaws. Until then, block or require authentication for requests hitting the PDF/CSV generator endpoints and the /circolare/feed/ RSS feed (e.g., via a security plugin or web-server rules), and review access logs for unauthenticated access to these paths. Also audit whether restricted Circolare content or registered-user data has already been exported, and consider rotating user data if leaks are confirmed.

8.7
  • Design Scuole Italia project (Regione del Veneto) Design Scuole Italia (WordPress theme)
moderate≈1,000–5,000 sites (likely low thousands of Italian school websites)
CVE-2026-87791
Unauthenticated Path Traversal File Read in WordPress Design Scuole Italia Theme

The Design Scuole Italia WordPress theme contains an unauthenticated path traversal flaw (CWE-22) in the reserved_file_check function of functions.php, rated 8.7 (high) under CVSS 4.0. A remote attacker with no credentials can send a crafted request with traversal sequences to a file-download endpoint handled by the theme, tricking it into serving files outside the intended directory. Successful exploitation discloses arbitrary files readable by the web server process, most critically wp-config.php, which contains database credentials, salts, and keys. Affected parties are WordPress sites — primarily Italian school websites — running an unpatched version of the theme; the advisory data does not specify an exact affected version range. No public proof of concept is known, the flaw is not in CISA's KEV catalog, and no exploitation has been observed.

Do: Update the Design Scuole Italia theme to the latest release from the official repository and confirm the reserved_file_check function in functions.php is patched. Inspect access logs for unauthenticated file-download requests containing dot-dot path traversal patterns or successful retrieval of sensitive files such as wp-config.php, /etc/passwd, or environment files. As defense-in-depth, block traversal sequences in download parameters via WAF rules, and rotate database credentials and authentication salts if any suspicious file access is found.

8.7
  • Design Scuole Italia project (Italian public sector / Team per la Trasformazione Design Scuole Italia (WordPress theme)
moderateLikely low thousands of sites (order of 1,000–10,000, probably at the lower end)
CVE-2026-90650
Unauthenticated Stored XSS via Stripe Webhook in MotoPress Hotel Booking (<=6.2.4)

The MotoPress Hotel Booking plugin for WordPress contains a stored cross-site scripting flaw in the premium Stripe gateway's webhook listener (webhook-listener.php), affecting all versions up to and including 6.2.4. Because the plugin only verifies the Stripe webhook signature when an optional signing secret is configured — and that secret is empty by default — an unauthenticated attacker can send a forged webhook event (e.g., a fake 'refund.created') that is accepted without cryptographic verification. The attacker-controlled event object 'id' is then written unescaped into the payment log and executes as arbitrary JavaScript when an administrator views the payment in the WordPress dashboard. Exploitation requires knowledge of a valid Stripe PaymentIntent ID for an existing payment, which limits the attacker pool to those with some visibility into a site's transactions. The vulnerable handler exists only in the premium Stripe integration, not the lite plugin, and no public PoC or in-the-wild exploitation is currently known.

Do: Update MotoPress Hotel Booking to a version newer than 6.2.4 as soon as a patched release is available. Immediately configure the Stripe webhook signing secret in the plugin settings — this forces cryptographic verification of incoming webhooks and blocks forged events even on unpatched installs. Review payment log entries and admin-facing payment pages for unexpected or injected script content, and check Stripe dashboard webhook delivery logs for events that do not correspond to legitimate Stripe-originated transactions.

7.2
  • MotoPress Hotel Booking plugin for WordPress (premium Stripe gateway integration, webhook-listener.php) All versions up to and including 6.2.4 (lite/free plugin directory not affected — handler only present in the premium Stripe gateway)
moderate≈ low thousands of premium-licensed sites running the Stripe gateway (lite plugin reports roughly 10k active installs; vulnerable code is paid-version only)
CVE-2026-15609
The Bridge - Creative Multipurpose WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute in all

The Bridge - Creative Multipurpose WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute in all versions up to, and including, 30.8.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NVD description · AI analysis pending
6.4
  • WordPress
CVE-2026-14805
Authenticated Privilege Escalation in Consulting WordPress Theme (≤6.7.16)

The Consulting theme for WordPress, in versions up to and including 6.7.16, chains two flaws that let any authenticated user with subscriber-level access or above escalate to full administrator privileges. The unprotected masterstudy_ms_stm_set_discard_transient AJAX endpoint in admin/admin-notices/classes/STMHandler.php allows an attacker to set arbitrary transients without capability checks or nonce validation, so they can set stm_developer_access_token to a known value (1). Because the developer-access login mechanism in admin/classes/stm-theme-support.php trusts that transient for authentication when running in legacy string mode, visiting a specially crafted URL then logs the attacker in as any existing user, including administrators. Any site running the theme at or below 6.7.16 where an attacker can obtain even a low-privileged account (e.g., via open registration) is affected. No public PoC exists and no exploitation in the wild has been reported, though the attack is straightforward to reproduce for anyone with the technical details.

Do: Update to the latest Consulting theme release (any version newer than 6.7.16) as soon as the vendor ships a fix; until then, disable open user registration and audit existing low-privileged accounts. Check for unexpected stm_developer_access_token transient values and any newly created or modified administrator accounts, and consider a WAF rule blocking the masterstudy_ms_stm_set_discard_transient AJAX action and the developer-access login URL.

8.8
  • StylemixThemes Consulting theme for WordPress up to and including 6.7.16
moderateestimated tens of thousands of sites (roughly 10k-50k active installations)
CVE-2026-89141
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to access and retrieve the transcribed contents of private audio attachments belonging to other users, including Administrators, via a supplied attachment ID. This vulnerability requires the Public API module to be enabled in the plugin settings; when disabled, the REST route is absent and the endpoint returns HTTP 404.

NVD description · AI analysis pending
6.5
  • WordPress
CVE-2026-75983
Privilege Escalation via map_meta_cap in Eventin WordPress Plugin (≤4.1.23)

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to privilege escalation in all versions up to and including 4.1.23. Its PermissionManager::manage_permissions() function, hooked to WordPress core's map_meta_cap filter, unconditionally returns the always-true 'exist' primitive for every capability check whenever the evaluated user ID is 1, without scoping this to plugin-specific capabilities. An authenticated attacker who controls the site's user ID 1 account — even one demoted to Subscriber, a common administrator-account hardening practice — can therefore pass every capability check, including manage_options, edit_plugins, edit_themes, promote_users, and update_core, gaining administrator-equivalent power, full site takeover, and remote code execution via the plugin and theme editors. On default installations where user ID 1 retains the administrator role, no incremental privilege gain occurs, which explains the High attack-complexity CVSS 3.1 score of 7.5. No public proof of concept is known and the flaw is not listed in CISA's KEV catalog, so exploitation is currently considered none known.

Do: Update Eventin to a version newer than 4.1.23 (the latest release) as soon as possible. If you use the 'demote user ID 1' hardening pattern, audit that account for signs of compromise and enforce a strong password plus two-factor authentication until patched. As a defense-in-depth measure against the plugin/theme editor RCE path, define DISALLOW_FILE_EDIT in wp-config.php.

7.5
  • Themewinter Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce (WordPress plugin) All versions up to and including 4.1.23
moderateTens of thousands of WordPress sites (≈10,000–30,000 active installs), with only the small subset that deliberately demoted user ID 1 practically exploitable
CVE-2026-18063
The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter in all versions up to, and including, 2.8

The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NVD description · AI analysis pending
6.4
  • WordPress
CVE-2026-15402
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shed

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter in all versions up to, and including, 4.1.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NVD description · AI analysis pending
6.4
  • WordPress
CVE-2026-18232
The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public A

The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved listings belonging to other users.

NVD description · AI analysis pending
5.3
  • WordPress
CVE-2026-16593
The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticat

The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access to the page builder (Editor and above) to perform SQL injection attacks that execute when the affected page is rendered.

NVD description · AI analysis pending
6.8
  • WordPress
CVE-2026-16592
The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role as l

The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role as low as Contributor to disclose non-public listing content, including password-protected and hidden fields, belonging to other users.

NVD description · AI analysis pending
2.7
  • WordPress
CVE-2026-15758
The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the 'id' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including the full metadata payload of password-protected flipbooks — including title, outline, props, and the serialized data blob containing the underlying PDF file's direct URL — bypassing WordPress post-password confidentiality. Flipbook post IDs can be pre-enumerated via the also-unauthenticated fb3d_send_posts AJAX action, requiring no prior knowledge to target specific flipbooks.

NVD description · AI analysis pending
5.3
  • WordPress
CVE-2026-85657
The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up to, and including, 4.15.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user clicks on a link.

NVD description · AI analysis pending
5.4
  • WordPress
CVE-2026-85575
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable t

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shopengine_product_title_header_size’ parameter in all versions up to, and including, 4.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NVD description · AI analysis pending
6.4
  • WordPress, E-commerce
CVE-2026-89023
Missing Authorization in ThemeAtelier Domain For Sale WordPress Plugin REST API

The ThemeAtelier Domain For Sale plugin for WordPress before version 3.5.2 contains a missing authorization flaw (CWE-862) in its REST API endpoints, allowing unauthenticated attackers to reach protected resources without any credentials. The bug is triggered simply by sending crafted requests to the plugin's REST routes, which fail to verify user permissions. An attacker can retrieve stored offer records, delete arbitrary offers by numeric identifier, and pull dashboard statistics, exposing bidder contact information, offer details, private messages, verification tokens, and business data. Sites running any version prior to 3.5.2 with the plugin active are affected. No public proof-of-concept is known and the flaw does not appear in CISA's Known Exploited Vulnerabilities catalog, so there is no evidence of in-the-wild exploitation at this time.

Do: Update Domain For Sale to version 3.5.2 or later immediately. Until patched, block unauthenticated access to the plugin's REST API namespace at the WAF or reverse proxy, and verify that REST permission callbacks are enforced. Afterward, audit offer records for unauthorized deletions or tampering, rotate any exposed verification tokens, and notify affected bidders if contact details or messages were disclosed.

8.8
  • ThemeAtelier Domain For Sale (WordPress plugin) before 3.5.2
nichelikely low thousands of sites at most (order of magnitude: ~1,000s)
CVE-2026-82519
Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers

Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a crafted POST request without the two-factor-authentication field to skip nonce verification and trigger delete_two_fa_meta(), which resets the grace period anchor timestamp on every login cycle, causing mandatory 2FA enforcement to be deferred indefinitely.

NVD description · AI analysis pending
2.3
  • WordPress
CVE-2026-87087
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER.

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

NVD description · AI analysis pending
  • WordPress
CVE-2026-89050
The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an

The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a paid ad placement without payment.

NVD description · AI analysis pending
4.3
  • WordPress
CVE-2026-88802
Unauthenticated Post Deletion in MDJM Event Management & Mobile Events Manager Plugins

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager plugin through 1.4.8.3 fail to check a capability, a nonce, or the type of record when processing a playlist-entry removal request, so the code permanently deletes whatever post ID the request identifies. Any unauthenticated attacker who can reach the affected site can send a crafted request to destroy arbitrary posts, pages, and media attachments, bypassing the WordPress trash so the content is unrecoverable without backups. The result is high-impact integrity loss (CVSS 3.1: 7.5, network vector, no privileges or user interaction required) but no confidentiality impact. Sites running these niche event/DJ-management plugins are affected. No public proof of concept or in-the-wild exploitation is known, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.

Do: Update MDJM Event Management to version 1.7.8.5 or later and Mobile Events Manager to a version newer than 1.4.8.3, or deactivate the plugin entirely if no fixed release is available for your version line. If patching must be delayed, use a WAF or firewall rule to block unauthenticated requests to the plugin's playlist-entry-removal AJAX/action endpoint. Because deletion bypasses the trash, verify working backups and audit the site for unexplained missing posts, pages, or media attachments.

7.5
  • MDJM Event Management (WordPress plugin) before 1.7.8.5
  • Mobile Events Manager (WordPress plugin) through 1.4.8.3 (<= 1.4.8.3)
nichelikely on the order of a few thousand sites or fewer (low thousands at most)
CVE-2026-88793
Unauthenticated Stored XSS in YouTube Embed WordPress Plugin 10.0–10.3

The YouTube Embed WordPress plugin versions 10.0 to 10.3 performs no authorisation check on one of its AJAX actions, with its only safeguard being a nonce that is printed on every front-end page, so any unauthenticated visitor can retrieve the nonce and invoke the action. Because the plugin also fails to escape stored data before rendering it, an attacker can persist arbitrary web scripts that execute in the browser of any user viewing the affected content, including administrators, enabling session hijacking and full site takeover. Any WordPress site running the plugin in the 10.0–10.3 range is affected. There is no known public PoC and the flaw is not listed in CISA's KEV, so exploitation is currently none known.

Do: Update to version 10.4 or later (or the latest release) immediately. Inspect the plugin's stored options and rendered embed content for injected scripts and log out/rotate admin sessions if tampering is found. If updating is not possible, deactivate and remove the plugin and review server logs for unauthenticated AJAX requests to the affected action.

8.8
  • YouTube Embed plugin (WordPress) YouTube Embed 10.0 to 10.3
moderate≈3,000–5,000 sites (plugin reports a few thousand active installs on WordPress.org)
CVE-2026-85129
Unauthenticated Stored XSS and Settings Wipe in Hoo Companion WordPress Plugin 1.0.2

The Hoo Companion WordPress plugin, version 1.0.2, performs no authorisation, validation, or sanitisation on one of its import features, which writes submitted data directly into the active theme's settings. An unauthenticated attacker can send a crafted request to this endpoint to inject arbitrary JavaScript that executes in the browsers of any site visitor, including administrators, enabling session hijacking and full site takeover. The same malicious request overwrites and destroys the site's existing theme settings, breaking the site's appearance and configuration. Any WordPress site running the plugin alongside its companion theme is affected. There is no known public proof of concept and no evidence of in-the-wild exploitation at this time.

Do: Remove or deactivate the Hoo Companion plugin until a patched version newer than 1.0.2 is available, and check the plugin's repository for security advisories. Inspect the active theme's settings for unexpected or foreign scripts and restore them from a known-good backup, since exploitation wipes legitimate settings. Review administrator accounts and sessions for compromise, and use a WAF rule to block unauthenticated requests to the plugin's import endpoint if it must remain enabled.

8.8
  • Hoo Companion (WordPress plugin vendor) Hoo Companion WordPress plugin 1.0.2 and prior
CVE-2026-81648
Unauthenticated Arbitrary File Deletion in CryptoPayment Gateway WordPress Plugin

The CryptoPayment Gateway WordPress plugin versions 1.2.1 and 1.2.2 fails to enforce an authorization (capability) check on one of its AJAX endpoints, which means any unauthenticated visitor can invoke what should be administrative-only operations. An attacker triggers the flaw simply by sending a crafted request to the unprotected AJAX action — no valid session, nonce, or credentials are required. Successful abuse lets the attacker delete arbitrary files on the server (potentially destroying the site or enabling a WordPress reinstallation takeover by wiping wp-config.php), overwrite the payment gateway configuration, and retrieve stored wallet credentials in cleartext, which could lead to direct theft of cryptocurrency funds. Sites running the plugin at versions 1.2.1–1.2.2 are affected regardless of configuration. There is no known public PoC and no evidence of in-the-wild exploitation to date, though the CVSS 10.0 rating and trivial preconditions make patching urgent.

Do: Update the CryptoPayment Gateway plugin immediately to the latest version (anything after 1.2.2, per the advisory's fixed-range). Treat all wallet credentials and API keys handled by the plugin as compromised: rotate wallets/seed phrases, review the gateway configuration for unauthorized changes, and verify site files for unexpected deletions or modifications (including restoring from backup if wp-config.php was targeted). Until patched, block unauthenticated AJAX requests to the plugin's endpoints via WAF rules or disable the plugin.

10.0
  • CryptoPayment Gateway (WordPress plugin) 1.2.1 – 1.2.2
nicheunknown
CVE-2026-74933
Unauthenticated Config Overwrite and Stored XSS in GenieWords WordPress Plugin

The GenieWords WordPress plugin, versions 1.5.27 through 1.5.34, lacks authorization (capability and nonce) checks on several of its REST API and AJAX actions, which allows unauthenticated attackers to invoke those endpoints and overwrite the plugin's configuration. Because the plugin also decodes stored values before printing them, an attacker can inject arbitrary web scripts through the writable settings, resulting in persistent JavaScript that executes on every front-end page of the site. Successful exploitation (which requires a victim to load an affected page, per the UI:R in the CVSS vector) can lead to session theft, administrative action hijacking, and site-wide content manipulation, reflected in the high 8.8 CVSS score. Any site running GenieWords 1.5.27–1.5.34 with the plugin active is affected. No public proof-of-concept is known and the flaw is not on the CISA KEV list, so no active exploitation has been confirmed.

Do: Update GenieWords to a version newer than 1.5.34 as soon as a patched release is available; if none exists yet, deactivate and remove the plugin. Until remediated, block or restrict unauthenticated access to the plugin's REST API (e.g., /wp-/geniewords/) and admin-ajax.php actions via a WAF rule. Review the plugin's stored configuration for unexpected changes or injected script payloads, and check site pages and logs for signs of malicious JavaScript or unauthorized settings modifications.

8.8
  • GenieWords (WordPress plugin) 1.5.27 – 1.5.34
CVE-2026-89080
Unauthenticated 2FA Reset Bypass in Really Simple Security WordPress Plugin

The Really Simple Security WordPress plugin before version 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor authentication enrolment, undermining the plugin's own second factor. An attacker who already knows a victim's password can trigger this reset, bypass email 2FA, and log in to obtain that user's session — up to administrator, enabling full site takeover. Any WordPress site running a version below 9.8.1, particularly those relying on the plugin's email-based two-factor authentication, is affected. The flaw carries a high CVSS 3.1 score of 7.5 and is classified as an authentication vulnerability (CWE-287). No public proof of concept exists, the issue is not on CISA's Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported.

Do: Upgrade Really Simple Security to version 9.8.1 or later immediately. Check user accounts for unexpected 2FA enrolment resets and review login/session logs for the vulnerable period, rotating credentials and invalidating sessions for administrator accounts if anything looks off. Because the attack requires prior knowledge of the password, enforce strong unique passwords and consider app-based (TOTP) second factors where available.

7.5
  • Really Simple Plugins Really Simple Security (WordPress plugin) before 9.8.1
mass≈4,000,000+ WordPress sites (plugin reports 4M+ active installs), of which only sites with email 2FA enabled are practically exploitable
CVE-2026-88995
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allow

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.

NVD description · AI analysis pending
5.3
  • WordPress
CVE-2026-88912
The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and i

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, allowing users with a subscriber-level account or above to make another user's private activity public or hide it.

NVD description · AI analysis pending
4.2
  • WordPress
CVE-2026-88764
The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level conf

The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-priced membership while being granted a higher, more privileged membership level.

NVD description · AI analysis pending
5.4
  • WordPress
CVE-2026-86407
The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account n

The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account named in the request, nor that any registration or purchase has taken place, allowing unauthenticated users to retrieve another user's email address, profile fields, role and membership order details. Exploitation requires the site owner to have added a user smart tag to that page's configurable message, which the shipped default does not contain.

NVD description · AI analysis pending
3.7
  • WordPress
CVE-2026-86406
Payment Bypass Privilege Escalation in User Registration & Membership Plugin < 5.2.8

The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase and does not validate the payment method or the plan submitted with it, so any authenticated user — even a low-privileged subscriber — can claim a paid membership plan without paying. When a site owner has mapped a paid plan to a privileged WordPress role, this becomes privilege escalation, potentially granting full administrator access. The flaw (CWE-269, CVSS 3.1: 7.5 high) is triggered simply by submitting a crafted membership purchase request while logged in as any registered user. Affected sites are WordPress installations running the plugin below 5.2.8, particularly those that map purchasable plans to privileged roles. No public PoC is known, the CVE is not on the CISA KEV list, and there is no evidence of exploitation in the wild.

Do: Update to User Registration & Membership 5.2.8 or later immediately. Review your membership-plan-to-role mappings and remove any that assign privileged roles (especially administrator) to purchasable plans. Audit users, role assignments, and payment records for accounts that received paid plans or role changes without a corresponding successful payment.

7.5
  • User Registration & Membership (WordPress plugin) < 5.2.8
CVE-2026-80072
The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthe

The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which can be abused for phishing.

NVD description · AI analysis pending
4.7
  • WordPress
CVE-2026-80071
Author-to-Admin Privilege Escalation in User Registration & Membership Plugin < 5.2.8

The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan, nor does it validate the plan a user attaches to their own account — a privilege-management flaw (CWE-269). An authenticated attacker with Author-level access or above can create or attach a membership plan that grants an arbitrary role, escalating their own account to Administrator. Successful exploitation effectively yields full site takeover, since an administrator can install plugins, modify all content, and access all site data. All sites running a version before 5.2.8 are affected, with multi-user sites where non-administrators hold authoring roles at greatest risk. No public proof of concept exists, the CVE is not in CISA's KEV catalog, and no exploitation in the wild has been reported.

Do: Update to User Registration & Membership 5.2.8 or later as soon as possible. Audit your user list for unexplained Administrator accounts or role changes, and review any membership plans created or edited by non-administrator users. Until patched, restrict plan-authoring and publishing capabilities to trusted users and monitor audit logs for suspicious role assignments.

7.2
  • WPEverest User Registration & Membership (WordPress plugin) All versions before 5.2.8
moderateOn the order of tens of thousands of sites (≈10,000–100,000)
CVE-2026-77773
The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its publ

The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its public AJAX actions, allowing unauthenticated users to read the submitted entries of any form created with a supported third-party form Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8.

NVD description · AI analysis pending
5.3
  • WordPress
CVE-2026-15451
Authenticated Privilege Escalation in MemberPress Corporate Accounts WordPress Plugin

The MemberPress Corporate Accounts plugin for WordPress contains a mass assignment flaw in its 'add_sub_account_user' function, which passes the raw 'userdata' array to 'wp_insert_user' without stripping dangerous keys such as 'role' or 'ID'. An authenticated attacker with subscriber-level access who holds a corporate account can exploit this over the network to create new administrator accounts or hijack existing administrator accounts by overwriting their email addresses. Successful exploitation grants full site takeover, since the CVSS vector scores high impact to confidentiality, integrity, and availability. Any WordPress site running the plugin at version 1.5.39 or earlier is affected, though 1.5.39 only partially patched the issue. No public proof-of-concept or in-the-wild exploitation is currently known, and the flaw is not listed in CISA's KEV catalog.

Do: Update the Corporate Accounts plugin to the latest available release, verifying with MemberPress that the version you install fully remediates the flaw beyond the partial fix in 1.5.39. Audit the site for unexpected administrator accounts and recently changed admin email addresses, and review corporate account holders for suspicious activity. Until fully patched, consider temporarily deactivating the Corporate Accounts add-on or restricting corporate account creation.

8.8
  • MemberPress Corporate Accounts plugin for WordPress all versions up to and including 1.5.39 (1.5.39 contains only a partial patch)
largelikely tens of thousands of sites (premium MemberPress add-on; MemberPress claims 600,000+ total installs, with Corporate Accounts among its widely deployed…
CVE-2026-10148
The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up

The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually' parameter in the render() methods of classes. This makes it possible for authenticated attackers, with Contributor-level access and above who can use Elementor, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 2.4.8.

NVD description · AI analysis pending
6.4
  • WordPress
CVE-2026-85200
Unauthenticated Local File Inclusion in GEO my WP WordPress plugin

The GEO my WP geolocation/mapping plugin for WordPress is vulnerable to an unauthenticated local file inclusion (CWE-98) in the gmw_posts_locator_ajax_info_window_loader function, affecting all versions up to and including 4.5.5.3. An unauthenticated attacker can send a crafted request to this function that causes the server to include and execute arbitrary .php files present on the host. This can be used to bypass access controls or obtain sensitive data, and becomes full remote code execution if the attacker can upload .php files that are then included, or in environments where PEAR is installed with register_argc_argv enabled. Any WordPress site running the plugin at version 4.5.5.3 or older is affected. As of now the flaw is not listed in CISA KEV and no public proof-of-concept is known.

Do: Update GEO my WP to the latest release available, i.e., any version newer than 4.5.5.3, as soon as possible. Until patched, use a WAF/firewall rule to block unauthenticated requests to the affected AJAX action and prevent upload of .php files to the server, and check server configurations (PEAR present with register_argc_argv enabled) where the flaw can escalate to full remote code execution. Review logs for anomalous calls to the info-window loader and for unexpected PHP file uploads.

7.5
  • GEO my WP WordPress plugin all versions up to and including 4.5.5.3
largetens of thousands of sites (plugin has roughly 30,000 active installs on WordPress.org)
CVE-2026-85198
The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path in all version

The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path in all versions up to, and including, 4.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is only exploitable when the [mpg_spintax] shortcode is rendered in site-wide content such as a footer or template part, as the vulnerable code path is only reached when the shortcode is active on the requested page.

NVD description · AI analysis pending
6.5
  • WordPress
CVE-2026-78175
PHP Object Injection to RCE in Tutor LMS WordPress Plugin (≤ 4.0.7)

Tutor LMS, a WordPress eLearning plugin, suffers from a PHP object injection flaw (CWE-502) in the `tutor_save_withdraw_account` AJAX handler, which accepts attacker-controlled `withdraw_method_field` values with no capability check beyond a nonce and stores them via `update_user_meta()` in a way that corrupts serialized string lengths. An authenticated user with subscriber-level privileges (or an unauthenticated attacker, if open user registration is enabled) who holds a valid nonce can therefore make `unserialize()` over-read into attacker-controlled bytes and inject an arbitrary serialized object. By chaining the plugin's bundled PayPal Composer autoloader with the `GuzzleHttp\Cookie\FileCookieJar` gadget, the attacker achieves remote code execution, writing attacker-controlled content to an attacker-specified filename on the server. All sites running Tutor LMS up to and including version 4.0.7 with the monetization feature enabled are affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.

Do: Update Tutor LMS to a release newer than 4.0.7 as soon as a patched version is published (no fixed version number is confirmed in the available data). As interim mitigation, disable the plugin's monetization/withdraw feature, restrict or close open user registration, and review `update_user_meta()`-stored withdraw account data for tampered serialized values. Sites that enabled monetization and registration should also audit for unexpected files written by web-server users during the exposure window.

8.8
  • Themeum Tutor LMS – eLearning and online course solution plugin for WordPress All versions up to and including 4.0.7
large≈100,000+ WordPress installs of Tutor LMS (plugin-directory active-install level), of which a smaller subset
CVE-2026-78006
+1 in the same advisory: …78159
Unauthenticated RCE in The Events Calendar WordPress Plugin

The Events Calendar WordPress plugin is vulnerable to unauthenticated remote code execution (CWE-502, unsafe deserialization) in all versions up to and including 6.17.4 via the is_safe_widget_instance function, whose protection can be bypassed because PHP fires magic methods during pre-parse while enable_rendering_widget_copied() forges a valid wp_hash integrity attribute before unserialize() is reached. The flaw is reachable without authentication or approval because the plugin's V2 single-event template runs do_blocks() over buffered comment HTML, and WordPress returns a moderation-hash URL that lets an unauthenticated commenter immediately view their own still-pending comment, delivering attacker-injected block markup to the vulnerable code path before moderation occurs. Successful exploitation gives an unauthenticated attacker arbitrary code execution on the web server with full confidentiality, integrity, and availability impact. Any site running a vulnerable version is affected, but only when comments are enabled and visible on events. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation has been confirmed.

Do: Update The Events Calendar to the latest available release (any version newer than 6.17.4) as soon as possible. Until patched, disable comments on events or prevent them from being publicly visible, since exploitation requires comments to be enabled and viewable on event pages. Review logs for pending comments submitted to events and unexpected widget/serialized data, and treat comment moderation queues on event posts with suspicion.

9.8<1% PoC ×2
  • StellarWP (The Events Calendar) The Events Calendar WordPress plugin All versions up to and including 6.17.4
mass≈200,000+ sites (plugin reports 200,000+ active installs on WordPress.org), with the exploitable subset smaller because comments must be enabled and visible on…
CVE-2026-77161
The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and includin

The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and including, 5.1.24 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires the plugin's sync feature to be enabled (options['enabled']) and get_option('egoi_mapping') to be truthy, both of which reflect ordinary configured states for the plugin's core contact mapping functionality.

NVD description · AI analysis pending
6.5
  • WordPress
CVE-2026-17585
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter. This makes it possible for unauthenticated attackers to extract arbitrary postmeta values from all published posts via character-by-character substring matching across the entire wp_postmeta table. The required nonce is emitted publicly via wp_localize_script on any frontend page that loads a Royal Elementor widget, meaning no authenticated session or prior action is needed to obtain it.

NVD description · AI analysis pending
5.3
  • WordPress
CVE-2026-16482
Unauthenticated Blind SQL Injection in rtMedia WordPress Plugin

The rtMedia for WordPress, BuddyPress and bbPress plugin is vulnerable to time-based blind SQL injection through the 'compare' parameter in all versions up to and including 4.7.11, caused by insufficient escaping and lack of prepared statements. Any unauthenticated attacker can trigger it by sending a crafted request to a public page that embeds an rtMedia shortcode (such as [rtmedia_gallery]) with the rtmedia_shortcode GET parameter set, since RTMediaQuery::query() merges $_REQUEST into the query while validating only top-level keys. Successful exploitation lets the attacker append additional SQL queries and extract sensitive information from the site's WordPress database, including potentially user credentials. Any WordPress site running the plugin with a rtMedia shortcode on a publicly reachable page is affected. As of now there is no known public proof-of-concept, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation has been confirmed.

Do: Update the rtMedia plugin to the newest release (any version newer than 4.7.11). Until patched, remove rtMedia shortcodes from public pages or use a WAF rule to block requests where the rtmedia_shortcode GET parameter is present along with nested 'compare' values. Review web server and WAF logs for requests containing the rtmedia_shortcode parameter, and check the database for signs of unexpected queries or data exfiltration.

7.5
  • rtCamp (rtMedia) rtMedia for WordPress, BuddyPress and bbPress (WordPress plugin) All versions up to and including 4.7.11
large≈100,000+ sites (plugin reports roughly 100k active installs on WordPress.org; the exploitable subset are sites with rtMedia shortcodes on public pages)
CVE-2026-11355
The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX

The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX handlers (including dtlms_save_poc_settings, dtlms_save_skin_settings, and dtlms_save_options_settings) in versions up to, and including, 1.1. These handlers are registered on the wp_ajax_nopriv_* hook and contain no capability check, no nonce verification, and pass user-supplied data directly to update_option(). This makes it possible for unauthenticated attackers to overwrite arbitrary plugin option values stored in the wp_options table, including Point-of-Contact email configuration and skin/branding settings, which can be used to alter the appearance and behavior of the LMS for all site visitors.

NVD description · AI analysis pending
5.3
  • WordPress
CVE-2026-87919
The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the u

The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerce products by previewing a post that contains the shortcode.

NVD description · AI analysis pending
4.9
  • WordPress, E-commerce
CVE-2026-87918
The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI provid

The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls, and consume the associated cost, using the site's own configured API keys.

NVD description · AI analysis pending
5.3
  • WordPress
CVE-2026-87916
The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthentica

The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every chat visitor by requesting a wide date range.

NVD description · AI analysis pending
5.3
  • WordPress