Vulnerabilities
266 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-62105 | Unauthenticated PHP Object Injection in ThemeREX Addons WordPress Plugin CVE-2026-62105 is an unauthenticated PHP object injection flaw (CWE-502, deserialization of untrusted data) in the ThemeREX Addons plugin for WordPress, affecting all versions below 2.45.0. Because the vulnerable deserialization path is reachable over the network without authentication, privileges, or user interaction (CVSS 3.1 AV:N/AC:L/PR:N/UI:N), any remote attacker can send a crafted serialized PHP payload to trigger it. Successful object injection can leverage PHP object chains in WordPress for high-impact outcomes such as arbitrary code execution, database manipulation, or file operations (CVSS 3.1 C:H/I:H/A:H), potentially leading to full site compromise. WordPress sites running ThemeREX Addons prior to 2.45.0 are affected, including sites where the plugin was installed automatically as a companion to a ThemeREX commercial theme rather than chosen by the site owner. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time. Do: Update ThemeREX Addons to version 2.45.0 or later, checking the plugin list even on sites where it was installed automatically with a bundled ThemeREX theme. If immediate patching is not possible, apply WAF rules that restrict unauthenticated requests to the plugin's endpoints and review logs for unexpected admin users, modified files, or unusual serialized input. No public PoC or known exploitation is currently reported, but treat this critical (9.8) issue as a priority patch. | 9.8 | — |
| mass≈200,000+ sites (plugin is reported in the order of 200,000 active installs) | ||
| CVE-2026-62103 | Unauthenticated PHP Object Injection in Everest Forms WordPress Plugin (<= 3.6.0) CVE-2026-62103 is an unauthenticated PHP object injection vulnerability in the Everest Forms WordPress plugin, caused by deserialization of untrusted data (CWE-502). An attacker who can reach the affected code path without logging in can supply crafted serialized values, causing the plugin to instantiate arbitrary PHP objects. Depending on the object classes (gadget chains) present in a site's installed plugins, this can escalate to arbitrary file deletion, data modification, and potentially remote code execution, consistent with the assigned critical 9.8 CVSS score. All WordPress sites running Everest Forms version 3.6.0 or earlier are affected. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and there is no confirmed exploitation in the wild at this time. Do: Update Everest Forms to the latest available release (any version above 3.6.0) on all WordPress sites, prioritizing internet-facing sites given the unauthenticated, network-exploitable nature of the flaw. If patching must be delayed, deactivate the plugin as a stopgap and review web server and WordPress logs for suspicious unauthenticated requests or signs of object-injection abuse. | 9.8 | — |
| large≈100,000+ WordPress sites (plugin's public active-install count is roughly 100k, and all installs at or below 3.6.0 are vulnerable) | ||
| CVE-2026-62102 | Subscriber Privilege Escalation in Gato GraphQL WordPress Plugin CVE-2026-62102 is a privilege escalation flaw (CWE-266) in the Gato GraphQL plugin for WordPress that lets an authenticated user with Subscriber-level privileges elevate their account to higher privileges, most likely administrator. It is triggered over the web through the plugin's exposed GraphQL API, requiring only a low-privileged account (PR:L) and no user interaction, which is reflected in the 8.8 High CVSS 3.1 score. A successful attacker gains high-impact control over the site, consistent with administrator-level access to content, settings, and data. Any WordPress installation running Gato GraphQL version 19.2.3 or earlier is affected, with the greatest exposure on sites that permit subscriber registrations or have other subscriber-level accounts. As of this analysis there is no public proof-of-concept, the issue is not listed in CISA KEV, and no in-the-wild exploitation has been reported. Do: Update Gato GraphQL on every affected site to a release newer than 19.2.3, checking the plugin's changelog for the patched version. Until patched, consider deactivating the plugin if it is not required or restricting access to the GraphQL endpoint, and audit user accounts for unexpected administrator-level users (a sign of prior privilege escalation). Sites with registration closed and no subscriber-level accounts face reduced risk because exploitation requires an authenticated low-privileged user. | 8.8 | — |
| moderatelikely on the order of a few thousand active WordPress installs (10^3-10^4) | ||
| CVE-2026-62089 | Missing Authorization in Master Addons for Elementor Allows Privilege Abuse CVE-2026-62089 is a missing authorization flaw (CWE-862) in the Pixar Labs 'Master Addons for Elementor' WordPress plugin, meaning one or more of its routines fail to verify a user's capabilities before executing privileged actions. Because the flaw requires low privileges (CVSS PR:L), an attacker needs an account on the target site — even a low-level role such as subscriber — and can then send a crafted network request to trigger the unprotected function. Successful abuse lets a minimally privileged user perform privileged operations, with the published CVSS score (7.1 high) weighting the impact toward integrity changes and potentially high availability impact rather than data disclosure. Any WordPress site running Master Addons for Elementor version 3.2.2 or earlier is affected. There is no evidence of exploitation so far: the flaw is not in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known. Do: Update Master Addons for Elementor to the latest patched release (any version newer than 3.2.2; check the WordPress.org plugin page or changelog for the current fixed version, as none is specified in the advisory). Until patched, review accounts with low-privilege roles and consider restricting unknown registered users, and verify logged-in-user activity for signs of unauthorized privileged actions. Admins of Elementor-based sites should confirm their installed plugin version in the WordPress dashboard. | 7.1 | — |
| large≈100,000 WordPress sites (plugin is listed with roughly 100,000+ active installations) | ||
| CVE-2026-62088 | Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data. Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data. This issue affects ElasticPress: from n/a through 5.3.4. NVD description · AI analysis pending | 5.3 | — |
| — | ||
| CVE-2026-27378 | Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions. Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions. NVD description · AI analysis pending | 5.3 | — |
| — | ||
| CVE-2026-87122 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-85984. Reason: This candidate is a reservation duplicate of CVE-2026-85984. Notes: All CVE users should reference CVE-2026-85984 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. NVD description · AI analysis pending | — | — |
| — | ||
| CVE-2026-15439 | The GamiPress plugin for WordPress is vulnerable to authenticated (Subscriber+) SQL Injection via the 'q' parameter of the wpForo integration AJAX selector (act The GamiPress plugin for WordPress is vulnerable to authenticated (Subscriber+) SQL Injection via the 'q' parameter of the wpForo integration AJAX selector (action gamipress_wpforo_get_posts) in versions up to, and including, 7.9.7. The value is passed only through $wpdb->esc_like() and interpolated directly into a single-quoted LIKE clause with no %s placeholder. Because esc_like() runs after WordPress core magic quotes, it doubles the injected backslash (\' -> \\'), which MySQL reads as one literal backslash followed by a live closing quote, allowing the attacker to break out of the string and inject boolean-based SQL. The wpForo plugin only needs to be active to register the callback; no wpForo vulnerability is used. Requires a Subscriber account, which can read the gamipress_admin nonce (exposed on every admin page, e.g. /wp-admin/profile.php). Note: the researcher's Simple:Press vectors (PoC 2 & 3) do not reproduce in current code, which uses $wpdb->prepare() with %s placeholders; only the wpForo selector is confirmed. NVD description · AI analysis pending | 6.5 | — |
| — | ||
| CVE-2024-12145 | The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 14.3.3 via the bp_notifications_acti The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 14.3.3 via the bp_notifications_action_bulk_manage due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete/mark as read/mark as unread notifications of other users. NVD description · AI analysis pending | 4.3 | — |
| — | ||
| CVE-2026-86813 | The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that are placed into notification email heade The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that are placed into notification email headers, allowing unauthenticated attackers to inject additional email headers, such as Bcc, into the emails the site sends when a submitted field value is configured to populate a header. NVD description · AI analysis pending | 4.8 | — |
| — | ||
| CVE-2026-86809 | The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment authority obtained from a different transaction. NVD description · AI analysis pending | 5.3 | — |
| — | ||
| CVE-2026-85116 | The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, in The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. NVD description · AI analysis pending | 6.5 | — |
| — | ||
| CVE-2026-82215 | The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment notifications it receives before a The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment notifications it receives before acting on them, allowing unauthenticated attackers who know the store's merchant identifier to mark arbitrary orders as paid, or to cancel or fail them. NVD description · AI analysis pending | 5.9 | — |
| — | ||
| CVE-2026-82213 | The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not verify that the saved payment token being requested belongs to the current user, allowing unau The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not verify that the saved payment token being requested belongs to the current user, allowing unauthenticated attackers to retrieve other customers' stored card token references together with a valid authorisation signature. NVD description · AI analysis pending | 5.3 | — |
| — | ||
| CVE-2026-17037 | Unauthenticated Stored XSS in Kirki – Freeform Page Builder WordPress Plugin CVE-2026-17037 is a stored cross-site scripting (XSS, CWE-79) vulnerability in the Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress, caused by insufficient input sanitization and output escaping of the 'comment' parameter. An unauthenticated attacker can submit a crafted 'comment' value that the plugin stores and later outputs without proper escaping, so the injected web script executes in the browser of any user who loads the affected page. Successful exploitation lets the attacker run arbitrary JavaScript in victims' browsers — for example stealing session cookies or performing actions in the context of logged-in users, including administrators — and the CVSS 3.1 score of 7.2 (High) with a changed scope reflects that users beyond the vulnerable component are impacted. All versions of the plugin up to and including 6.2.0 are affected on any WordPress site where the plugin is active. As of this analysis there is no public proof-of-concept, no confirmed in-the-wild exploitation, and the issue is not in CISA's KEV; the CVE was assigned by Wordfence, the WordPress ecosystem CNA. Do: Update the plugin to a patched release newer than 6.2.0 as soon as one is available, since all versions through 6.2.0 are affected. Until then, deploy a WAF or virtual-patching rule that strips HTML/script tags and event-handler attributes from 'comment' parameters, and audit recently saved content and comments for injected script payloads. Sites that do not rely on the plugin's form/comment functionality can deactivate the plugin as an interim mitigation. | 7.2 | — |
| mass≈300,000 WordPress sites (Kirki has historically shown on the order of 300k active installs on WordPress.org) | ||
| CVE-2026-6642 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset field values when they are rendered in HTML attribute contexts in the mla_generate_bulk_edit_form_fieldsets() function and mla-bulk-edit-fieldsets.tpl template. While wp_kses() filtering is applied during preset export for users without unfiltered_html capability, this does not prevent attribute injection attacks since the malicious payload consists of quotes and HTML attributes rather than HTML tags. When preset values are retrieved and rendered, they are directly assigned to template variables without esc_attr() escaping and then inserted into input element value attributes via simple string replacement. This makes it possible for authenticated attackers, with Author-level access and above (upload_files capability), to inject arbitrary web scripts that execute when an administrator imports the poisoned preset and the targeted input field receives focus. NVD description · AI analysis pending | 6.4 | — |
| — | ||
| CVE-2026-6641 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3. The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35. This is due to insufficient input sanitization and output escaping on the mla_link_href parameter when mla_output is set to 'paginate_links', where the _paginate_links() function processes the value through mla_process_shortcode_parameter() and _replace_query_parameter() without proper URL escaping, then outputs it directly in href attributes without applying esc_url(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD description · AI analysis pending | 6.4 | — |
| — | ||
| CVE-2026-6640 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD description · AI analysis pending | 6.4 | — |
| — | ||
| CVE-2026-86815 | The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, backup-destination, and backup-execution The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, backup-destination, and backup-execution management, allowing users holding a BackWPup WordPress plugin before 5.7.5-defined, administrator-assigned limited role to create and run backup jobs and exfiltrate a full database backup to an attacker-controlled destination. NVD description · AI analysis pending | 5.5 | — |
| — | ||
| CVE-2026-86812 | The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks retu The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allowing unauthenticated users to disclose guest order information and to change the status of, or trash, any order. NVD description · AI analysis pending | 6.5 | — |
| — | ||
| CVE-2026-86782 | The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing users with the Contributor role and abov The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing users with the Contributor role and above to publish, rename, and overwrite the content of posts and pages they do not own, including other users' private drafts. NVD description · AI analysis pending | 5.5 | — |
| — | ||
| CVE-2026-86781 | The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file downl The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowing any authenticated user, including Subscribers, to download the site's TLS private key, certificates, and diagnostic logs. NVD description · AI analysis pending | 5.3 | — |
| — | ||
| CVE-2026-86780 | The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow us The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected post, including higher-privileged users such as Editors and Administrators. NVD description · AI analysis pending | 6.8 | — |
| — | ||
| CVE-2026-86779 | The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-objec The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above to permanently delete any chart on the site, including charts created by other users such as administrators. NVD description · AI analysis pending | 2.7 | — |
| — | ||
| CVE-2026-85678 | The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it inside a script tag on the front end, al The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it inside a script tag on the front end, allowing users with contributor level access and above to store arbitrary JavaScript that will execute in the browser of anyone who views the post, including the editor or administrator who reviews it. NVD description · AI analysis pending | 6.8 | — |
| — | ||
| CVE-2026-85677 | Unauthenticated Stored XSS in Gutenverse News WordPress Plugin The Gutenverse News WordPress plugin before 3.3.3 adds extra HTML elements to WordPress's global sanitization allowlist (KSES) without scoping them to its own intended context, so the relaxed list applies to every sanitization path on the site, including comments submitted by unauthenticated visitors. An attacker can therefore post a comment containing JavaScript-bearing HTML that passes WordPress's sanitization and is stored on the site. The injected script executes in the browser of any administrator who reviews the pending comment in the moderation queue, potentially allowing session hijacking and unauthorized admin actions, and also executes for any visitor who views the post after the comment is approved. Any WordPress site running the vulnerable plugin with unauthenticated comments enabled is affected. No public proof-of-concept, listing in CISA KEV, or confirmed in-the-wild exploitation is known at this time. Do: Update Gutenverse News to version 3.3.3 or later as soon as possible. Until patched, consider disabling unauthenticated comments or disabling the plugin, and review the comment queue plus existing approved comments for HTML containing script or event-handler attributes; because admins who reviewed comments may already have been targeted, check for suspicious admin activity and rotate credentials if anything looks unusual. | 8.8 | — |
| moderatelikely on the order of tens of thousands of WordPress sites (exact active-install count not provided in the data) | ||
| CVE-2026-83546 | The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contribut The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed. NVD description · AI analysis pending | 6.8 | — |
| — | ||
| CVE-2026-83545 | The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with con The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes when the content is viewed. NVD description · AI analysis pending | 6.8 | — |
| — | ||
| CVE-2026-82305 | The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated user The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site. NVD description · AI analysis pending | 5.3 | — |
| — | ||
| CVE-2026-74925 | Vendor-to-Admin Privilege Escalation in MultiVendorX WordPress Plugin (before 5.0.16) The MultiVendorX WordPress plugin prior to 5.0.16 does not restrict which users can modify the plugin's role and capability settings, an improper privilege management flaw (CWE-269). A user holding the plugin's vendor role can reach those unprotected settings and grant the vendor role administrator-level capabilities. The next time that vendor acts with their role, they effectively hold administrator rights and can take over the site, including full read/write control and content or configuration changes. Any WordPress site running a MultiVendorX version before 5.0.16 is affected, especially multi-vendor marketplaces where several untrusted parties hold vendor accounts. There is no public proof-of-concept, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation is known. Do: Update MultiVendorX to version 5.0.16 or later. If immediate upgrade is not possible, restrict and review who holds the vendor role and audit vendor accounts and role definitions for unexpectedly granted administrator-level capabilities, checking for any unauthorized admin users or capability changes. | 7.2 | — |
| moderateTens of thousands of sites (plugin reports roughly 30,000 active installs on WordPress.org) | ||
| CVE-2026-14565 +1 in the same advisory: …14566 | The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated user such as a subscriber to store JavaScript that executes in the browser of visitors viewing the affected product. NVD description · AI analysis pending | 5.4 group max | — |
| — | ||
| CVE-2026-14563 | Unauthenticated Authentication Bypass in WordPress advanced-customized-prompts Plugin The advanced-customized-prompts WordPress plugin through version 1.0.1 fails to verify the password before issuing an authenticated session for a supplied email address via an unauthenticated action, an improper authentication flaw (CWE-287). An unauthenticated remote attacker can trigger this by submitting any registered user's email address to the affected endpoint and receive a valid logged-in session without ever knowing the password, or can create arbitrary new accounts. This grants full control of the impersonated account, including administrator accounts, potentially leading to complete site takeover. Any WordPress site running the plugin at version 1.0.1 or earlier is affected. No public proof-of-concept or in-the-wild exploitation is currently known, and the issue is not listed in CISA KEV. Do: Deactivate or remove the advanced-customized-prompts plugin until a patched release newer than 1.0.1 is published, then update to the latest fixed version. Audit WordPress user accounts and authentication logs for unexpected admin sessions or newly created accounts, and rotate credentials for privileged users as a precaution. | 9.8 | — |
| — | ||
| CVE-2026-14562 | The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, allowing unauthenticated attackers to disclose other customers' order and attachment data. NVD description · AI analysis pending | 5.3 | — |
| — | ||
| CVE-2026-14560 | Unauthenticated PHP File Upload RCE in teddy-bear-customize-addon WordPress Plugin CVE-2026-14560 is an unauthenticated arbitrary file upload flaw in the teddy-bear-customize-addon WordPress plugin (all versions through 1.0.5) that leads to remote code execution, classified as CWE-94 code injection. The plugin fails to validate uploads server-side, trusting the client-supplied content type and preserving the attacker's original filename, so an unauthenticated attacker can upload a file such as a PHP web shell directly to the server. When the uploaded PHP file is requested over the web, the attacker executes arbitrary code with the privileges of the web server, enabling full site compromise and potential lateral movement on shared hosting. Any WordPress installation running the plugin through 1.0.5 is affected; exposure is limited to sites using this niche customization addon. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time, but the trivially exploitable network vector (CVSS 10.0) makes opportunistic scanning likely. Do: Update the teddy-bear-customize-addon plugin to the latest available version as soon as a patched release is published (all versions through 1.0.5 are vulnerable); if no fix is available yet, deactivate or remove the plugin. Audit the uploads directory for unexpected .php files and review access logs for unauthenticated POST requests to the upload endpoint to detect any compromise. As a stopgap, block direct execution of PHP files in the uploads directory or apply WAF rules requiring server-side validation of upload types. | 10.0 | — |
| nichelikely well under 10,000 sites; no published active-install count available | ||
| CVE-2026-14559 | Authentication Bypass in teddy-bear-customize-addon WordPress Plugin CVE-2026-14559 is a critical authentication flaw (CWE-287) in the teddy-bear-customize-addon WordPress plugin, which authenticates users without verifying their password. An unauthenticated attacker who knows or guesses a registered user's email address can authenticate as that user through the plugin's login flow with no password required. Because the impersonated accounts include administrators, an attacker gains full control of the WordPress site, including the ability to install plugins or themes, edit files, and create new admin users for persistence. Any WordPress site running the plugin at version 1.0.5 or earlier is affected; the flaw requires no privileges or user interaction and is trivially exploitable over the network (CVSS 3.1: 9.8). No public proof-of-concept is known, the issue is not in CISA's KEV, and no in-the-wild exploitation has been documented as of this analysis. Do: Deactivate or remove the teddy-bear-customize-addon plugin until a patched release beyond 1.0.5 is available, then update immediately, as no fixed version is documented in the data. Review authentication logs for administrator sign-ins without corresponding password activity, and rotate or reset credentials for privileged accounts if any suspicious logins are found. As an interim mitigation, a WAF rule or enforced password check on the plugin's login path can block the bypass. | 9.8 | — |
| nichelikely well under 1,000 sites (no published active-install count; obscure, early-stage addon plugin) | ||
| CVE-2025-15695 | The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup f The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site. NVD description · AI analysis pending | 3.5 | — |
| — | ||
| CVE-2026-8778 | Unauthenticated Arbitrary File Upload in MIPL Grouped Checkout Fields for WooCommerce The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields plugin for WordPress is affected by an unrestricted file-upload flaw (CWE-434): the mipl_wc_upload_file function performs no file-type validation in all versions up to and including 1.2.1. An unauthenticated, remote attacker can trigger the flaw by submitting a crafted upload request over the network, with no authentication or user interaction required (CVSS 9.8, vector AV:N/AC:L/PR:N/UI:N). By uploading arbitrary files — for example a PHP script — to a web-executable location, the attacker may achieve remote code execution and compromise the site, matching the high confidentiality, integrity, and availability impact reflected in the critical 9.8 score. Any WordPress site, typically a WooCommerce store, running the plugin at version 1.2.1 or older is affected. As of the available data there is no public proof-of-concept, the issue is not listed in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported. Do: Update the plugin to the first available release newer than 1.2.1 once a patched version is published (no fixed version number is stated in the available data), or deactivate the plugin until a fix ships. As an interim mitigation, deny PHP execution in the upload destination used by the plugin (typically under wp-content/uploads) via web-server rules so uploaded files cannot run. Because the flaw is exploitable by unauthenticated users on internet-facing stores, check the uploads directory for unexpected PHP or other unfamiliar files and review web-server logs for unauthenticated POST requests to the plugin's upload endpoint. | 9.8 | — |
| — | ||
| CVE-2026-84960 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Query String in all versions up to, and including, The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Query String in all versions up to, and including, 3.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Successful exploitation requires the victim to first visit the attacker-crafted URL and then click the Terms of Service link rendered on the resulting registration page. NVD description · AI analysis pending | 6.1 | — |
| — | ||
| CVE-2026-81825 | Unauthenticated Stored XSS in Simple Ajax Chat WordPress Plugin The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress, in all versions up to and including 20260811, is vulnerable to stored cross-site scripting (CWE-79) because chat message input is insufficiently sanitized and output is insufficiently escaped. The nonce that should gate message submission is publicly visible on the chat page, so it provides no real barrier, allowing fully unauthenticated attackers to submit messages containing arbitrary web scripts. These malicious messages are stored persistently and execute in the browser of every visitor who loads the affected page, potentially enabling session hijacking, credential theft, or content/redirect manipulation against admins and regular users alike. Any WordPress site running an affected version of the plugin is exposed, and the high-severity scope-changed CVSS score (7.2) reflects that impact on users beyond the vulnerable component. As of disclosure there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation is known. Do: Update Simple Ajax Chat to the latest patched release (any version newer than 20260811) via the WordPress plugin admin as soon as one is available. Until patched, consider temporarily deactivating the plugin or limiting chat posting to trusted users, and review stored chat messages for injected HTML/JavaScript. If an attacker-controlled message was rendered while an admin was logged in, check sessions and rotate credentials as a precaution. | 7.2 | — |
| largetens of thousands of sites (roughly 10,000–20,000 active installs) | ||
| CVE-2026-81754 | Unauthenticated Stored XSS via User-Agent in Vigilant WordPress Security Plugin CVE-2026-81754 is a stored cross-site scripting (XSS) flaw in the Vigilant – 100% Free Security Suite plugin for WordPress, present in all versions up to and including 2.10.2, caused by insufficient input sanitization and output escaping of the HTTP User-Agent header. An unauthenticated attacker triggers it by sending a login attempt with a crafted User-Agent header; when the login fails, the injected web script is passively stored on the site with no further action required from the attacker. The stored script then executes in the browser of any user who views an injected page, letting the attacker run arbitrary web script content in the context of the site (CVSS 3.1: 7.2 High, scope-changed, low confidentiality/integrity impact). Any WordPress site running Vigilant 2.10.2 or earlier is affected, with the greatest risk on sites whose login form is reachable by anonymous internet visitors. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time. Do: Update the Vigilant plugin to the latest patched release (any version newer than 2.10.2) as soon as it is available and verify the installed version afterward. As interim mitigation, restrict or rate-limit access to the login endpoint, consider filtering failed login attempts with unusual User-Agent strings, and review stored content/pages for unexpectedly injected scripts. Prioritize sites where wp-login.php is exposed to the public internet, since any anonymous visitor can plant a payload via a failed login. | 7.2 | — |
| nichelikely on the order of thousands of active WordPress sites (low-confidence estimate) | ||
| CVE-2026-7438 | The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_it The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NVD description · AI analysis pending | 6.4 | — |
| — | ||
| CVE-2026-78172 | The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query Parameter Name in all versions up to, an The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query Parameter Name in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. NVD description · AI analysis pending | 6.1 | — |
| — | ||
| CVE-2026-77150 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The show_preview AJAX action is registered for unauthenticated users and is gated only by a nonce, which an unauthenticated attacker can retrieve by loading any publicly accessible page that emits it. NVD description · AI analysis pending | 6.1 | — |
| — | ||
| CVE-2026-19991 | Authenticated Arbitrary File Deletion in UsersWP WordPress Plugin (≤ 1.2.70) UsersWP, a WordPress user-profile and registration plugin, is vulnerable to arbitrary file deletion in all versions up to and including 1.2.70 via its upload_file_remove() AJAX handler. Because the account 'file' field value is taken directly from $_POST when no real upload occurs, and the only validation (validate_file()) merely rejects a literal '../', an attacker can store a crafted URL containing embedded '.. ' tokens that collapse into '../../' traversal sequences when uwp_get_file_relative_url() later performs a str_replace() of the uploads base URL — after the final validation — with the transformed path appended to the uploads directory and passed to wp_delete_file() with no canonical containment check. Any authenticated attacker with Subscriber-level access or higher can thereby delete arbitrary files on the server, including wp-config.php, which can break or take down the site (CVSS 3.1: 8.1 High, with high integrity and availability impact). All WordPress sites running UsersWP version 1.2.70 or earlier are affected, most directly where the UsersWP account form includes a file field. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known as of this analysis. Do: Update UsersWP to the first patched release after 1.2.70 as soon as it is available (the data does not specify a fixed version number). Until patched, restrict Subscriber registrations or limit which users can submit the UsersWP account file field, and consider WAF rules blocking crafted file URLs containing '.. ' sequences. Check for signs of exploitation such as unexpectedly missing files on the server, especially wp-config.php. | 8.1 | — |
| moderate≈10,000 sites (UsersWP's WordPress.org active-install listing is on the order of 10k; fewer if the account form lacks a 'file' field) | ||
| CVE-2026-19985 | The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.28.1 via the 's', 'pos The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.28.1 via the 's', 'post_types', and 'orderby' request parameters. This is due to insufficient input sanitization and output escaping in the relevanssi_debug_array() function in lib/debug.php, which dumps user-supplied query variables through print_r() inside a block without HTML escaping. The debug path is enabled by supplying the relevanssi_debug=on request parameter when the administrator has previously enabled the 'Debugging mode' setting; the gate itself is a configuration check with no capability, nonce, or logged-in check (the vendor explicitly suppresses nonce verification on that line). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link. NVD description · AI analysis pending | 6.1 | — |
| — | ||
| CVE-2026-18964 | The Floating Chat Widget: The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. WordPress's server-side HTML encoding of the 's' search parameter in the <title> element is bypassed because the browser DOM API decodes HTML entities when jQuery's .text() method reads document.title, returning literal special characters that are then embedded unescaped into the constructed HTML attribute value. NVD description · AI analysis pending | 6.1 | — |
| — | ||
| CVE-2026-18579 | Unauthenticated Stored XSS in WP Photo Album Plus WordPress Plugin WP Photo Album Plus, a WordPress photo gallery plugin, is vulnerable to stored cross-site scripting in all versions up to and including 9.2.08.003 because it fails to sufficiently sanitize and escape the attacker-controlled HTTP X-Forwarded-For header. An unauthenticated attacker sends a request to the wp_ajax_nopriv_wppa endpoint invoking the getshortcodedrenderedfenodelay action with a crafted X-Forwarded-For value; a deliberately failed nonce check acts as the log-write trigger rather than an access barrier, causing the plugin's wppa_log() routine to write the malicious header value to its log on disk. The injected script then executes whenever a user, such as an administrator viewing pages that render the plugin's stored log output, accesses an injected page, letting the attacker run arbitrary web script in that user's browser session. Any WordPress site running WP Photo Album Plus version 9.2.08.003 or earlier is affected, with practical exposure concentrated on sites where the plugin's logged data is rendered to privileged users. As of this analysis the flaw is not in the CISA KEV catalog, no public proof-of-concept is known, and no confirmed in-the-wild exploitation has been reported. Do: Update WP Photo Album Plus to the latest release beyond version 9.2.08.003 as soon as practical. As interim mitigation, filter or normalize unusual X-Forwarded-For values at the proxy or WAF layer and consider restricting unauthenticated admin-ajax.php requests targeting the plugin's wppa action. After upgrading, review and clear the plugin's log entries for injected HTML/script tags delivered via X-Forwarded-For and check recent admin sessions for signs of compromise. | 7.2 | — |
| moderateapprox. 10,000-20,000 active plugin installs (order of magnitude 10^4); likely fewer sites actually exploitable | ||
| CVE-2026-18562 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via SEO-friendly permalink filter The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via SEO-friendly permalink filter URL segments in versions up to, and including, 1.4.3. This is due to insufficient input sanitization and output escaping in the wp_load_js() function, which reads filter values from the URL path via the url_request extension's parse_url_query() and embeds them into an inline JavaScript string using json_encode() without escaping single quotes. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link. NVD description · AI analysis pending | 6.1 | — |
| — | ||
| CVE-2026-18561 | Unauthenticated SQL Injection in Unlimited Elements For Elementor ≤2.0.16 Unlimited Elements For Elementor, a popular WordPress widget library plugin, contains an unauthenticated SQL injection flaw in the 'addontype' parameter reaching getWhereString(). Because normalizeAjaxInputData() strips WordPress's magic-quotes protection and the parameter is insufficiently escaped, an attacker supplying it as an array can have element zero used verbatim as the SQL comparison operator and concatenated into the WHERE clause, allowing additional SQL queries to be appended to existing ones. A remote, unauthenticated attacker can leverage this to extract sensitive information from the site's database (confidentiality impact only; no alteration or disruption is scored). Any WordPress site running the plugin in versions up to and including 2.0.16 is affected, and the flaw is reachable without credentials or user interaction. There is currently no evidence of in-the-wild exploitation, no public proof-of-concept, and the issue is not on the CISA KEV list. Do: Update Unlimited Elements For Elementor to the latest patched release (anything newer than 2.0.16) as soon as possible; verify the installed version in the WordPress plugins dashboard. Until patched, restrict or monitor unauthenticated AJAX/REST access to the plugin's endpoints, and after patching check site logs for unusual 'addontype' array parameters and audit the WordPress database for unauthorized changes or exposed sensitive data. | 7.5 | — |
| largelikely on the order of 100,000+ sites (the plugin has roughly 1 million active installs; a substantial share runs the vulnerable 2.x line up to 2.0.16) |