During the week of 08/10/2026 to 08/17/2026, 183 vulnerability(ies) affecting WordPress were published in the Seckhmet database. Find below the details of these vulnerabilities and the week’s news.
Vulnerability Details
Critical 9.8
Component : Formidable Digital Signatures (Plugin)
CWE : CWE-23
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled filename in the item_meta[field_id][content] parameter alongside the delete_saved_image flag during the standard entry-creation POST flow on any form that accepts anonymous submissions.
Critical 9.8
Component : Wishlist Member (Plugin)
CWE : CWE-640
The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter while accepting the POST mergewith and POST wpm_id parameters without verifying that the mergewith user ID references a temporary or incomplete registrant that is bound to the current registration transaction. This makes it possible for unauthenticated attackers to take over any existing WordPress account — including administrator accounts — by supplying an arbitrary user’s numeric ID as the mergewith value, which causes wp_update_user() to overwrite the target account’s username (additionally written via a direct $wpdb UPDATE), password, email address, first name, and last name with attacker-controlled values, while WordPress password and email change notification emails are explicitly suppressed. When wpm_id references a non-existent membership level, no role key is added to the update payload, causing wp_update_user() to preserve the target user’s existing role — including administrator — making full privilege escalation a direct consequence of the takeover.
Critical 9.8
Component : QA Assistants – Driven by data (Plugin)
CWE : CWE-94
The QA Assistants – Driven by data plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.2.0.0. This makes it possible for unauthenticated attackers to execute code on the server.
Critical 9.8
Component : TrueBooker – Appointment Booking and Scheduler System (Plugin)
CWE : CWE-639
The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_update() AJAX handler being registered for unauthenticated users and accepting an arbitrary truebooker_wp_user_id value, which is passed directly to wp_update_user() without verifying authentication or ownership. This makes it possible for unauthenticated attackers to change any WordPress user account email address, including an administrator, by submitting the target user ID and an attacker-controlled email address. An attacker can then use the native WordPress password reset flow to receive the reset link at the attacker-controlled email address and take over the account.
Critical 9.8
Component : miniOrange OTP Login, Verification and SMS Notifications (Plugin)
CWE : CWE-266
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.5.1. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
Critical 9.8
Component : MStore API – Create Native Android & iOS Apps On The Cloud (Plugin)
CWE : CWE-266
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.20.0. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
Critical 9.8
Component : 6Storage Rentals (Plugin)
CWE : CWE-287
The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on wp_ajax_nopriv_six_storage_create_wp_user without any nonce, capability, credential, or ownership verification, while calling wp_set_current_user() and wp_set_auth_cookie() for any WordPress user resolved by the attacker-supplied email address. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by submitting that user’s email address.
Critical 9.8
Component : User Session Synchronizer (Plugin)
CWE : CWE-287
The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The `synchronize_session()` function, hooked on `init` and therefore executed on every request, performs no nonce, capability, or shared-secret validation against the attacker-supplied `ussync-key`, `ussync-token`, and `ussync-ref` parameters; when `ussync-key` references an unregistered slot, `get_option()` returns `false` for both the secret key and the domain list, causing the AES-256-CBC encryption key to degrade to the fully predictable `md5(”)` and the referer allowlist to collapse to an empty-string match, while the AES IV is unconditionally hard-coded as `md5(‘another-secret’)`. This makes it possible for unauthenticated attackers to supply a crafted request encrypting any known or guessable user email address in the `ussync-ref` parameter, causing the handler to call `wp_set_auth_cookie()` for the matched user and granting full authentication as that user — including administrators — with no prior knowledge of site secrets.
Critical 9.8
Component : User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor (Plugin)
CWE : CWE-704
The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an is_wp_error() check — when a registration is submitted with a 61–70 character username, WordPress core rejects it with a WP_Error object, but absint() coerces that object to the integer 1 before the error check can short-circuit execution, causing the plugin to bind and return a transient-backed autologin nonce tied to user ID 1. This makes it possible for unauthenticated attackers to log in as the site’s Administrator account (user ID 1), resulting in full administrative takeover of the site.
Critical 9.8
Component : WP BASE Booking of Appointments, Services and Events (Plugin)
CWE : CWE-94
The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.3.0. This makes it possible for unauthenticated attackers to execute code on the server.
Critical 9.8
Component : Pods – Custom Content Types and Fields (Plugin)
CWE : CWE-863
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON meta-box-loader compatibility path only writes failures to the PHP error log and returns false instead of terminating the request, rendering all guards ineffective. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator or overwrite the password of any user account, including the site owner’s, enabling complete site takeover, or perform another administrator action.
Critical 9.8
Component : Frontend Admin by DynamiApps (Plugin)
CWE : CWE-269
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can(‘edit_user’, $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string — a condition that can be induced by passing a crafted value such as `1one` through the unvalidated `item_id` parameter of the unauthenticated `wp_ajax_nopriv_frontend_admin/forms/change_form` AJAX endpoint. This makes it possible for attackers to escalate privileges to administrator by obtaining a server-signed `_acf_objects` payload carrying the non-numeric user ID, which WordPress subsequently coerces to integer 1 (the default administrator), allowing the attacker to overwrite that account’s password or email address. Exploitation by unauthenticated users requires a public-facing frontend user form to be configured; in all other cases a subscriber-level account is sufficient.
Critical 9.8
Component : Contact Form, Survey, Quiz & Popup Form Builder – ARForms (Plugin)
CWE : CWE-502
The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submissions. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
Critical 9.8
Component : ProSolution WP Client (Plugin)
CWE : CWE-434
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which overrides the allow-listed multipart filename before the file is saved, and a post-save extension check that fails to delete the already-written file. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce required to reach the upload handler is publicly exposed via wp_localize_script on any front-end page rendering the job portal shortcode, allowing unauthenticated visitors to obtain a valid nonce and bypass that gating check entirely.
Critical 9.1
Component : ProSolution WP Client (Plugin)
CWE : CWE-89
The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection.
Critical 9.1
Component : Link Library (Plugin)
CWE : CWE-22
The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Exploitation requires the administrator to have enabled the ‘Delete local file on link deletion’ plugin option (disabled by default) and to subsequently permanently delete the attacker-submitted link, which is a routine moderation action.
Critical 9.1
Component : RapiSafe – Secure Multi File Upload for Contact Form 7 (Plugin)
CWE : CWE-22
The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handleAjaxRemoveUpload function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The nonce required to invoke the removal handler is exposed in public-facing JavaScript as RSMFCF7Vars.nonce on every Contact Form 7 page rendering a RapiSafe upload field, making it obtainable by any unauthenticated visitor.
Critical 9.1
Component : Solace Extra (Plugin)
CWE : CWE-862
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_action-import-zip and wp_ajax_nopriv_action-import-zip and only verifies the ‘ajax-nonce’ nonce, which is emitted on every admin page via wp_localize_script (unrestricted admin_enqueue_scripts hook) and is therefore accessible to any authenticated user including Subscribers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to wipe navigation menus, sidebar widgets (via update_option(‘sidebars_widgets’, array())), all theme mods (via remove_theme_mods()), and Elementor templates, as well as trigger arbitrary demo-content imports.
Critical 9.1
Component : ProSolution WP Client (Plugin)
CWE : CWE-22
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). An attacker must first call the proSol_fileUploadModalProcess handler to poison their own session with a path-traversal key, then call proSol_fileDeleteProcess with that key as the filename parameter; both steps require only the publicly exposed frontend nonce.
High 8.8
Component : Autopay (Plugin)
CWE : CWE-79
The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page.
High 8.8
Component : Frontend Admin by DynamiApps (Plugin)
CWE : CWE-862
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level and above permissions, to reset the password of any user on the site, including administrators, leading to full account takeover and complete site compromise. Exploitation requires the attacker to hold a valid encrypted Current-User token obtained by accessing any Edit User form they are legitimately authorized to submit, which they then use as a known-plaintext base for the CBC bit-flipping forgery.
High 8.8
Component : AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress (Plugin)
CWE : CWE-269
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.11.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the BCC field of the acy_notification_cms notification template, causing subsequent WordPress password-reset emails — including those targeting administrator accounts — to be silently copied to an attacker-controlled address, enabling account takeover via the captured reset link. Successful exploitation requires the site administrator to have enabled the “Send website emails with AcyMailing” option, which routes WordPress core notification emails through AcyMailing’s templating system.
High 8.8
Component : KiviCare – Clinic & Patient Management System (EHR) (Plugin)
CWE : CWE-89
The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic staff-level role to perform SQL injection.
High 8.8
Component : MaxUpload – Big File Uploads – Increase Maximum File Upload Size (Plugin)
CWE : CWE-434
The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.4.0 via the handle_upload function. This is due to a filename-validation mismatch in the handle_upload function where extension and MIME checks are applied to the uploaded chunk’s filename but not to the final assembled filename derived from the resumableFilename parameter. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.
High 8.8
Component : Propovoice: All-in-One Client Management System (Plugin)
CWE : CWE-269
The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8. This is due to the `create()` function’s REST endpoint failing to validate the user-supplied `role` parameter against an allowlist of permitted WordPress roles and omitting any `promote_users` capability check before passing the sanitized value directly to `WP_User::set_role()`. This makes it possible for authenticated attackers with `ndpv_manager`-level access and above to create a new WordPress user account with the `administrator` role assigned, achieving full vertical privilege escalation. The `ndpv_manager` capability is a sub-administrator CRM team role granted by Propovoice itself, meaning the attack surface extends beyond site administrators to any user the plugin has elevated to a manager position.
High 8.8
Component : Wholesale Market (Plugin)
CWE : CWE-269
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.2.2 via the ced_wholesale_request_send AJAX action. The ced_wholesale_request_send_callback() handler only verifies a nonce (which is exposed to any authenticated user through wp_localize_script on the frontend) and that the caller has a positive user ID, then calls WP_User::add_role() with the client-supplied role_required POST parameter without restricting the value to an allowlist of wholesale roles. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to Administrator when the site administrator has enabled the ‘Assigning requested role directly’ option.
High 8.8
Component : bLoyal: Loyalty & Promotions by bLoyal (Plugin)
CWE : CWE-269
The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.611.78. This is due to the AJAX actions `save_bloyal_configuration_data` and `save_bloyal_accesskeyverification_data` being registered without any capability or nonce checks, and the `bloyal_customer_auto_login` function unconditionally trusting the `Customer.ExternalId` value returned by whichever API URL is stored in the plugin’s options. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the plugin’s bLoyal Loyalty Engine API URL (`bloyal_custom_loyaltyengine_api_url`) and the `is_bloyal_custom_api_url` flag via the unprotected AJAX actions, then trigger the unauthenticated `/cart` REST route to cause `bloyal_customer_auto_login` to fetch customer data from an attacker-controlled endpoint and call `wp_set_auth_cookie()` with an attacker-supplied `Customer.ExternalId`, thereby authenticating as any WordPress user including the site Administrator.
High 8.8
Component : Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! (Plugin)
CWE : CWE-434
The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.7.1 via the fetch_remote_file function. This is due to a filename validation/destination mismatch in fetch_remote_file, where file type validation is performed against the attacker-controlled Content-Disposition filename rather than the URL-path-derived destination filename. This makes it possible for authenticated attackers, with contributor-level access and above, to execute code on the server. A GIF+PHP polyglot file passes wp_check_filetype_and_ext validation as image/gif via the Content-Disposition filename, while the actual destination path is written with a .php extension derived from the URL path, bypassing the unfiltered_upload capability gate entirely. The affected endpoints are reachable at this privilege level because Templately’s entire REST API — including the cloud import endpoints used in this attack (/templately/v1/clouds/upload and /templately/v1/insert) — is authorized only by a current_user_can(‘delete_posts’) check, with no administrator or manage_options capability requirement. The same permission gate also allows a contributor to overwrite the site’s global Templately cloud connection via the /templately/v1/login endpoint with global_signin set to true. A complete remediation should both correct fetch_remote_file to validate the file type against the actual destination filename rather than the Content-Disposition header (and avoid deriving the write path from the request URL), and restrict state-changing Templately REST routes to an appropriate administrator-level capability.
High 8.8
Component : Query Wrangler (Plugin)
CWE : CWE-434
The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the ‘options’ parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_form_ajax handler, combined with unsanitized attacker-controlled options fully replacing saved query options and being passed directly to call_user_func_array() guarded only by function_exists(). This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server. Exploitation requires only that at least one query row exists in the database, as the query_id is a small enumerable integer with no further access control.
High 8.8
Component : Podlove Podcast Publisher (Plugin)
CWE : CWE-502
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authenticated attackers, with contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). A viable POP chain exists within the plugin itself via Podlove\ImageCache\GenerationGuard, whose __destruct() method invokes wp_delete_file() with an attacker-controlled file path populated through unserialization.
High 8.8
Component : Royal Addons for Elementor – Addons and Templates Kit for Elementor (Plugin)
CWE : CWE-918
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget’s ‘webhook_url’ setting. The widget’s render() method persists the attacker-controlled URL into the wpr_webhook_url_{widget_id} option on every render (including a Contributor previewing their own draft), and the wpr_form_builder_webhook AJAX handler — registered for both authenticated and unauthenticated callers — reads that option and dispatches the outbound request via the non-safe wp_remote_post(), with no host allowlist, no scheme restriction, and no private/loopback IP filter (the plugin’s existing wpr_is_blocked_remote_host / wpr_is_private_or_local_ip helpers are not called on this path). This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
High 8.8
Component : WordPress Core (Core)
CWE : CWE-434
WordPress Core is vulnerable to Remote Code Execution in multiple release branches, including versions 4.7.0 through 7.0.3. This is due to insufficient validation in the `WP_Image_Editor_Imagick::load()` image-processing path before passing uploaded files or streams to Imagick, which can interpret attacker-supplied image-like files as PostScript-family or compressed delegate formats based on magic bytes, format specifiers, or decompressed content rather than the WordPress-accepted extension. This makes it possible for authenticated attackers, with Author-level access and above, to upload a crafted file that is processed during attachment metadata generation and may trigger unsafe ImageMagick/Ghostscript behavior, resulting in remote code execution on sites using Imagick and Ghostscript. Unauthenticated exploitation is deployment-dependent and requires an additional public-upload plugin or theme path that sends attacker-supplied files through WordPress image metadata generation.
High 8.6
Component : ProSolution WP Client (Plugin)
CWE : CWE-89
The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the database and to delete the records the ProSolution WP Client WordPress plugin before 2.0.9 stores.
High 8.6
Component : WP Directory Kit (Plugin)
CWE : CWE-89
The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when a non-default search field type is configured.
High 8.6
Component : Paymob for WooCommerce (Plugin)
CWE : CWE-89
The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider’s HMAC signature. This allows unauthenticated attackers to perform SQL injection and read arbitrary data from the database — including user credentials and other secrets — through both in-band (reflected) and time-based blind extraction.
High 8.2
Component : Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce (Plugin)
CWE : CWE-284
The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordPress user accounts for arbitrary email addresses and inject order records.
High 8.1
Component : Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect (Plugin)
CWE : CWE-287
The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify’s /v1/me endpoint as proof of mailbox ownership — Generic::normalize_common() copies this value into the normalized profile without requiring an email_verified assertion, and User_Links::link_or_login_user() subsequently passes it directly to get_user_by(’email’, $email) and issues a persistent authentication cookie via wp_set_auth_cookie() without a provider-specific verified-email gate, a local mailbox challenge, or a logged-in approval step. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including Administrators, by supplying a known target email address through a controlled Spotify OAuth flow, gaining full administrative access to the site.
High 8.1
Component : GeoDirectory – WP Business Directory Plugin and Classified Listings Directory (Plugin)
CWE : CWE-22
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_revision function in all versions up to, and including, 2.8.169. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). By placing post_type=attachment exclusively in the query string to bypass the consistency check, an attacker can convert an auto-draft GeoDirectory listing into a WordPress attachment with attacker-controlled file paths injected into attachment metadata, which the delete_revision handler then dereferences and unlinks without any post-type or path validation.
High 8.1
Component : Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder (Plugin)
CWE : CWE-89
The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection.
High 8.1
Component : Events Manager – Calendar, Bookings, Tickets, and more! (Plugin)
CWE : CWE-89
The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to other people.
High 8.1
Component : WP Directory Kit (Plugin)
CWE : CWE-89
The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks an authorization check, allowing any authenticated user such as a Subscriber to perform SQL injection attacks.
High 8.1
Component : Biagiotti (Plugin)
CWE : CWE-98
The Biagiotti Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
High 8.1
Component : Foton Core (Plugin)
CWE : CWE-98
The Foton Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
High 8.1
Component : Booking Activities (Plugin)
CWE : CWE-502
The Booking Activities plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.18.4 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
High 8.1
Component : Headless SSO Plugin for WP (Plugin)
CWE : CWE-502
The Headless Single Sign On plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
High 8.1
Component : Barista (Theme)
CWE : CWE-98
The Barista theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.5.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
High 7.5
Component : InstaWP Connect – 1-click WP Staging & Migration (Plugin)
CWE : CWE-434
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.1.3.6 via the (top-level script) function. This is due to the plugin stores its encrypted options file as options-{migrate_key}.txt in wp-content/instawpbackups/ without deploying an index.php or .htaccess to prevent directory listing, exposing the 40-character migrate_key on Apache servers with directory indexing enabled, which allows an attacker to derive the AES-256-CBC passphrase via SHA256(migrate_key), decrypt the options file to recover the api_signature. This makes it possible for unauthenticated attackers to get the database access details and api_signature. Exploitation requires the target WordPress site to be hosted on Apache with directory listing enabled (Options +Indexes) for the wp-content/instawpbackups/ directory, and time limited because it can only be exploited during the migration period.
High 7.5
Component : Ezoic (Plugin)
CWE : CWE-862
The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated attackers to trigger a server-side export of the site’s database, including user password hashes and password reset tokens, as well as to persistently change some of its settings.
High 7.5
Component : Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent (Plugin)
CWE : CWE-89
The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
High 7.5
Component : Listdom: AI-powered Business Directory with Classifieds Ads Listings (Plugin)
CWE : CWE-89
The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
High 7.5
Component : Real Estate Manager Pro (Plugin)
CWE : CWE-269
The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 12.8.6. This is due to improper capability handling in the allow_attachment_actions() function, which can treat a target user ID as a media attachment ID during user capability checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit an administrator account and escalate their privileges to Administrator when the targeted user ID matches the ID of an existing media attachment.
High 7.5
Component : Object Sync for Salesforce (Plugin)
CWE : CWE-89
The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-sync-for-salesforce/push/ REST route. The route’s permission callback (can_process()) checks only the HTTP method for the push class — no capability or nonce — so it is reachable by unauthenticated users. The wordpress_object_type value is concatenated directly into a SQL query (post_type = “$object_type”, class-object-sync-sf-wordpress.php:328) and executed via $wpdb->get_results() with no $wpdb->prepare() (:578). Because REST body parameters are not magic-quoted, an attacker can break out of the quoted string and inject arbitrary SQL. This makes it possible for unauthenticated attackers to append additional SQL queries (time-based blind), enabling extraction of sensitive information such as password hashes from the database. Only a valid wordpress_id (e.g. 1) is required — no authentication or Salesforce connection.
High 7.5
Component : Web Directory Free (Plugin)
CWE : CWE-89
The Web Directory Free plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
High 7.5
Component : WP Directory Kit (Plugin)
CWE : CWE-89
The Directory Kit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
High 7.5
Component : WP Travel Engine – Tour Booking Plugin – Tour Operator Software (Plugin)
CWE : CWE-862
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view private booking billing details — including the victim customer’s first name, last name, email address, street address, city, and phone number — rendered as default values in checkout form fields by binding an arbitrary booking ID to the attacker’s session. The only access control on the endpoint is a frontend nonce that is publicly emitted to all visitors via the wteL10n global on trip pages, meaning it provides CSRF protection only and does not restrict unauthenticated access.
High 7.2
Component : Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce (Plugin)
CWE : CWE-22
The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files.
High 7.2
Component : Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder (Plugin)
CWE : CWE-79
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Notification Smartcode Values in all versions up to, and including, 6.2.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in the browser of an administrator (or any user with the Fluent Forms entry-viewing capability) when they view the form’s entry Submission Logs in the WordPress admin dashboard. Exploitation requires that a site administrator or Fluent Forms manager has configured an email notification whose subject or static (direct) Send To value references an attacker-influenced Smartcode such as an input_password field value, a cookie value, or submission.response.
High 7.2
Component : W3 Total Cache (Plugin)
CWE : CWE-79
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the Lazy Load Images feature of W3 Total Cache is enabled, as the unsafe re-emission occurs exclusively within the LazyLoad mutator’s img tag rewriting step.
High 7.2
Component : MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder (Plugin)
CWE : CWE-79
The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
High 7.2
Component : Welcart e-Commerce (Plugin)
CWE : CWE-79
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.11.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
High 7.2
Component : WP-Stats (Plugin)
CWE : CWE-79
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
High 7.2
Component : Smart Popup by Supsystic (Plugin)
CWE : CWE-79
The Smart Popup by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.11.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
High 7.2
Component : WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode (Plugin)
CWE : CWE-79
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘regionArray’ parameter in all versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that the site administrator has enabled the ‘Support Google Consent Mode (GCM)’ setting, which is disabled by default. Additionally, the AJAX handler performs no nonce or capability check, allowing any authenticated user including those with Subscriber-level access to overwrite the affected plugin setting.
High 7.2
Component : Online Booking & Scheduling Calendar for WordPress by vcita (Plugin)
CWE : CWE-79
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘business_id’ parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
High 7.2
Component : Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms (Plugin)
CWE : CWE-79
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘action’ parameter in all versions up to, and including, 5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The stored payload is written by any unauthenticated admin-ajax.php request whose action value matches an entry in the plugin’s explicit-actions list, which is auto-populated for common form builders at activation and requires no authentication gate to reach the save path.
High 7.2
Component : Maspik – Multi-Layer Spam Protection (Plugin)
CWE : CWE-79
The Maspik – Spam blacklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
High 7.2
Component : Online Scheduling and Appointment Booking System – Bookly (Plugin)
CWE : CWE-79
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action in all versions up to, and including, 27.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injection point is the bookly_speed_up_update_addons AJAX action, which is registered as wp_ajax_nopriv_* and therefore reachable without authentication; the payload is stored verbatim in the bookly_log.details column when a request is submitted without a valid signature, and executes when an administrator later views the Diagnostics → Logs page.
High 7.2
Component : Echo Knowledge Base – Documentation, FAQs, Chat & Smart Search (Plugin)
CWE : CWE-79
The Knowledge Base for Documentation, FAQs with AI Assistance plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 17.211.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
High 7.2
Component : Autopay (Plugin)
CWE : CWE-79
The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 via the ‘bm_woocommerce_css_editor_content’ POST parameter. This is due to the Css_Editor::handle_save() method being wired to the WordPress ‘init’ hook by Settings_Manager::init_once() with no capability check, no nonce verification, and no sanitization on the input — the raw $_POST value is written to the ‘woocommerce_bluemedia_settings’ option via update_option(), then later echoed directly inside a <style> block on the WooCommerce checkout page by Css_Frontend::print_to_wp_head() with no output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page (the checkout page).
High 7.2
Component : Blog Floating Button (Plugin)
CWE : CWE-79
The Blog Floating Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.20 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
High 7.2
Component : WCPOS – Point of Sale (POS) plugin for WooCommerce (Plugin)
CWE : CWE-94
The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the ‘thermal’ Template Engine in all versions up to, and including, 1.9.14 due to the Receipt_Renderer_Factory dispatching templates with the ‘thermal’ engine to the Legacy_Php_Renderer instead of a safe thermal-specific renderer. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to inject arbitrary PHP code into a template post that is subsequently written to a temporary file and executed via PHP’s include(), resulting in remote code execution on the server. This requires the attacker to have Shop Manager-level access or above, as the template save path enforces a wcpos_template_settings nonce and the manage_woocommerce_pos capability check.
High 7.2
Component : Mang Board WP (Plugin)
CWE : CWE-79
The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
High 7.2
Component : Business Directory Plugin – Easy Listing Directories for WordPress (Plugin)
CWE : CWE-79
The Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
High 7.2
Component : Visitor Traffic Real Time Statistics (Plugin)
CWE : CWE-79
The Visitors Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
High 7.2
Component : Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress (Plugin)
CWE : CWE-89
The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the ‘_gallery_order_{post_id}’ parameter array keys in all versions up to, and including, 4.7.9. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The `gllr_save_postdata()` function stores unsanitized array keys from `$_POST` directly into post meta, which are later used in SQL queries without prepared statements. This makes it possible for authenticated attackers, with Editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
High 7.2
Component : Infility Global (Plugin)
CWE : CWE-79
The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in all versions up to, and including, 2.15.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The /cf7_records viewer is accessible to any authenticated user including those with Subscriber-level access, meaning the injected payload executes for any logged-in user who visits the records page.
High 7.2
Component : ToneDen Shortcode (Plugin)
CWE : CWE-79
The Do Lasso plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 358 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Medium 6.8
Component : s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions (Plugin)
CWE : CWE-79
The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS).
Medium 6.8
Component : Embed Google Photos album (Plugin)
CWE : CWE-79
The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user, including administrators, who views the affected post.
Medium 6.6
Component : Car Rental Manager – Online Vehicle Booking System (Plugin)
CWE : CWE-502
The Car Rental Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.9 via deserialization of untrusted input. This makes it possible for authenticated attackers, with editor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Medium 6.6
Component : Turnkey bbPress by WeaverTheme (Plugin)
CWE : CWE-502
The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deserialization of untrusted input in the wvrbbp_set_to_serialized_values() function (reached through the wvrbbp_save_restore() settings-restore handler). The function reads the raw contents of an administrator-uploaded file and passes them directly to unserialize() without any validation. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin itself; however, if a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Medium 6.5
Component : duplicate-post-littlebizzy (Plugin)
CWE : CWE-639
The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Duplicate Post WordPress plugin before 1.5.5 access to permanently delete arbitrary posts on the site, including those belonging to other users.
Medium 6.5
Component : Ray Enterprise Translation (Plugin)
CWE : CWE-862
The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to overwrite the administrator-configured translation API token with an arbitrary value.
Medium 6.5
Component : LearnPress – WordPress LMS Plugin for Create and Sell Online Courses (Plugin)
CWE : CWE-200
The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-assistant requests against that course’s lesson content, allowing any authenticated user such as a subscriber to obtain material from paid courses they have not enrolled in.
Medium 6.5
Component : Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce (Plugin)
CWE : CWE-200
The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users with contributor-level access and above to read other customers’ personal data such as names and email addresses.
Medium 6.5
Component : reviewer (Plugin)
CWE : CWE-89
The Reviewer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.14.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Medium 6.5
Component : Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder (Plugin)
CWE : CWE-89
The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the ‘data[queryCondition]’ parameter in all versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Medium 6.5
Component : Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe (Plugin)
CWE : CWE-89
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Second-Order SQL Injection via MultipleFiles Second-Order Payload via ‘cg_multiple_files_for_post’ -> ‘cgRealId’ in all versions up to, and including, 30.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Medium 6.5
Component : Groundhogg — CRM, Newsletters, and Marketing Automation (Plugin)
CWE : CWE-89
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the ‘tag_query’ parameter in all versions up to, and including, 4.5.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with vendor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires the attacker to trigger the vulnerable Legacy_Contact_Query code path by submitting an unknown filter type (e.g. filters[0][0][type]=force_fallback), which causes a FilterException that dispatches execution away from the modern query handler.
Medium 6.5
Component : KiviCare – Clinic & Patient Management System (EHR) (Plugin)
CWE : CWE-89
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the ‘searchTerm’ parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a KiviCare custom role with the ‘settings_view’ permission (e.g., Doctor or Receptionist), meaning standard WordPress subscribers cannot exploit this without a KiviCare-assigned role.
Medium 6.5
Component : WPML (Plugin)
CWE : CWE-89
The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL Injection via the ‘sorting’ parameter in all versions up to, and including, 4.9.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with translator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Medium 6.5
Component : Image Uploader for Welcart (Plugin)
CWE : CWE-89
The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the ‘post_title’ parameter in all versions up to, and including, 1.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Medium 6.5
Component : Booktics – Appointment Booking Calendar for Service Businesses (Plugin)
CWE : CWE-89
The Booktics plugin for WordPress is vulnerable to SQL Injection in versions up to 1.0.22 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Medium 6.5
Component : Simply Schedule Appointments (Plugin)
CWE : CWE-639
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.10 via the ssa_past_appointments due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to access appointment records belonging to arbitrary users and harvest the per-appointment ownership tokens (32-character hashes) embedded in the rendered HTML, which can then be used without any authentication to read or modify those appointments including full customer PII such as name, email, phone number, and private notes. The /wp-json/ssa/v1/render-shortcode REST endpoint is registered unconditionally on rest_api_init regardless of whether the Divi theme is installed, and its permission callback only requires current_user_can(‘edit_posts’), meaning any Contributor-level account is sufficient to trigger this entire exploit chain.
Medium 6.5
Component : WP Compress – Instant Performance & Speed Optimization (Plugin)
CWE : CWE-352
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.10.09. This is due to missing or incorrect nonce validation on the (top-level template code) function. This makes it possible for unauthenticated attackers to delete arbitrary WordPress options, including critical ones such as siteurl, home, active_plugins, template, and stylesheet, causing site outage or a full plugin and theme reset via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Medium 6.5
Component : CubeWP Framework (Plugin)
CWE : CWE-89
The CubeWP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.30 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Medium 6.5
Component : ToneDen Shortcode (Plugin)
CWE : CWE-89
The Do Lasso plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 358 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Medium 6.5
Component : Fullscreen Galleria (Plugin)
CWE : CWE-89
The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via ‘href’ Attribute in Post Content in all versions up to, and including, 1.6.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Medium 6.5
Component : The School Management – Education & Learning ERP (Plugin)
CWE : CWE-89
The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via ‘order[0][dir]’ Parameter in all versions up to, and including, 5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This vulnerability is replicated across seven or more AJAX handlers including wlsm-fetch-staff-classes, wlsm-fetch-notices, wlsm-fetch-subjects, wlsm-fetch-inquiries, wlsm-fetch-staff-employee, and wlsm-fetch-payments, and the missing nonce verification on several of these handlers also enables CSRF-chained exploitation.
Medium 6.5
Component : StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More (Plugin)
CWE : CWE-22
The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.1 via the parse_file_path function. This makes it possible for authenticated attackers, with vendor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Medium 6.5
Component : Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker (Plugin)
CWE : CWE-89
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via ‘randon_category’ Quiz Option in all versions up to, and including, 11.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Medium 6.4
Component : Kirki – Freeform Page Builder, Website Builder & Customizer (Plugin)
CWE : CWE-79
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_meta Shortcode in all versions up to, and including, 6.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Medium 6.4
Component : PPWP – Password Protect Pages (Plugin)
CWE : CWE-79
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s `ppwp` shortcode attributes in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Medium 6.4
Component : GiveWP – Donation Plugin and Fundraising Platform (Plugin)
CWE : CWE-79
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 4.16.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with donor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Medium 6.4
Component : WP Photo Album Plus (Plugin)
CWE : CWE-79
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 9.2.04.003 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Medium 6.4
Component : WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards (Plugin)
CWE : CWE-79
The WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.79 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Medium 6.4
Component : Featured Image from URL (FIFU) (Plugin)
CWE : CWE-79
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Medium 6.4
Component : Vehica Core (Plugin)
CWE : CWE-918
The Vehica Core plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.0.104. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.
Medium 6.4
Component : Beaver Builder Page Builder – Drag and Drop Website Builder (Plugin)
CWE : CWE-79
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Button Module ‘button’ (Button Code) Setting in all versions up to, and including, 2.10.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Beaver Builder grants editor access to any WordPress role holding the edit_posts capability by default, meaning Author-level users and above can exploit this vulnerability.
Medium 6.4
Component : Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker (Plugin)
CWE : CWE-79
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘question_title’ parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Medium 6.4
Component : Bold Page Builder (Plugin)
CWE : CWE-79
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘bt_bb_shortcode’ shortcode in all versions up to, and including, 5.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Medium 6.4
Component : Hydra Booking — Appointment Scheduling & Booking Calendar (Plugin)
CWE : CWE-79
The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘first_name’ parameter in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with host-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The tfhb_host role required to exploit this vulnerability can be self-assigned by any visitor via the plugin’s public Signup shortcode, making this effectively exploitable by unauthenticated users who complete the registration flow.
Medium 6.4
Component : Toocheke Companion (Plugin)
CWE : CWE-79
The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10 via the ‘series_bg_color’ post meta field. This is due to insufficient input sanitization in the toocheke_series_bg_color_save() function (which stores the raw $_POST value in post meta) and insufficient output escaping in the series admin column rendering (where the stored value is concatenated into a style attribute without esc_attr()). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user, such as an administrator, accesses the series list table in the admin dashboard.
Medium 6.4
Component : SureDash – Community, Courses & Member Dashboard (Plugin)
CWE : CWE-79
The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ‘draweropenverposition’ Block/Shortcode Attribute in all versions up to, and including, 1.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is stored inside the block-delimiter HTML comment’s JSON, which wp_kses_post does not neutralize on save, and is only interpolated into the rendered style attribute at display time without esc_attr() escaping, allowing a double-quote to break out of the attribute and introduce arbitrary HTML event handlers.
Medium 6.4
Component : Loco Translate (Plugin)
CWE : CWE-79
The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with translator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Medium 6.4
Component : Video Gallery – YouTube Gallery, Playlist & Video Grid (Plugin)
CWE : CWE-79
The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.4 via the ’emd_mb_meta’ shortcode. This is due to insufficient input sanitization and output escaping on attachment titles referenced by the shortcode’s image field: EMD_MB_Helper::image_info() returns the attachment’s raw post_title, and EMD_MB_Helper::shortcode() interpolates it into title=”%s” HTML attributes via sprintf() without esc_attr(). This makes it possible for authenticated attackers, with author-level access and above (upload_files capability required to create the attachment, edit_posts/publish_posts to embed the shortcode), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Medium 6.4
Component : AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress (Plugin)
CWE : CWE-79
The AcyMailing SMTP Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 10.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Medium 6.4
Component : Serious Slider (Plugin)
CWE : CWE-79
The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ‘theme’ Shortcode Attribute in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Medium 6.4
Component : Smash Balloon Social Post Feed – Simple Social Feeds for WordPress (Plugin)
CWE : CWE-79
The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ‘id’ Shortcode Attribute in all versions up to, and including, 4.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Medium 6.4
Component : Snippet Shortcodes (Plugin)
CWE : CWE-79
The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Medium 6.1
Component : Jet Plugin (Plugin)
CWE : CWE-79
The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict who can upload them, allowing unauthenticated attackers to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting).
Medium 6.1
Component : WP Photo Album Plus (Plugin)
CWE : CWE-79, CWE-287
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into an inline script block, which could allow unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone who is tricked into opening a crafted link to a page displaying one of its galleries.
Medium 6.1
Component : MultiParcels Shipping For WooCommerce (Plugin)
CWE : CWE-79
The MultiParcels Shipping For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.30.36 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Medium 6.1
Component : Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution (Plugin)
CWE : CWE-79
The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘soundFile’ parameter in all versions up to, and including, 5.4.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the attacker to control a domain whose origin string is a leading prefix of the target site’s backend URL (e.g. https://example.co against https://example.com), and the victim must be an authenticated WordPress administrator who visits the attacker-controlled page while the File Manager admin screen is open.
Medium 6.1
Component : Samex – Clean, Minimal Shop WooCommerce WordPress Theme (Theme)
CWE : CWE-79
The Samex – Clean, Minimal Shop WooCommerce WordPress theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Medium 5.9
Component : WP Directory Kit (Plugin)
CWE : CWE-89
The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Medium 5.8
Component : Term Pages (Plugin)
CWE : CWE-89
The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
Medium 5.4
Component : Customer Reviews for WooCommerce (Plugin)
CWE : CWE-862
The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin before 5.116.0 options, and disclose store configuration.
Medium 5.4
Component : Saitama Addon Pack (Plugin)
CWE : CWE-79
The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before outputting them, allowing users with contributor-level access and above to inject stored Cross-Site Scripting payloads that execute in the browser of a higher-privileged user who reviews the content.
Medium 5.4
Component : Patterns Kit (Plugin)
CWE : CWE-79
The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts it into the page, allowing users with a role as low as Contributor to store a payload that executes in the browser of a user who views the content and clicks the affected element.
Medium 5.4
Component : Welcart e-Commerce (Plugin)
CWE : CWE-79
The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it on the product pages, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any visitor viewing the product page.
Medium 5.4
Component : Royal Addons for Elementor – Addons and Templates Kit for Elementor (Plugin)
CWE : CWE-79
The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag before outputting it, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
Medium 5.4
Component : ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution (Plugin)
CWE : CWE-352
The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.
Medium 5.4
Component : Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress (Plugin)
CWE : CWE-94
The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.19. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes. The partial mitigation introduced via strip_shortcodes() on [profile-first-name] and [profile-last-name] can be bypassed through the [profile-display-name format=”first_last_names”] render path, the [profile-bio] render path (which re-fetches the raw description meta), and the double-bracket escape sequence [[tag]], all of which allow attacker-controlled shortcode text to reach the outer do_shortcode() call.
Medium 5.3
Component : Salon Booking System – Appointment Booking for Salons, Barbershops & Spas (Plugin)
CWE : CWE-862
The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.
Medium 5.3
Component : User Access Manager (Plugin)
CWE : CWE-862
The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups.
Medium 5.3
Component : Prevent Direct Access – Protect WordPress Files (Plugin)
CWE : CWE-285
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without escaping wildcard characters via `$wpdb->esc_like()`. This makes it possible for unauthenticated attackers to bypass the private token requirement by supplying SQL wildcard characters (such as `%`) as the token value, matching any record in the plugin’s file table and downloading any protected file.
Medium 5.3
Component : User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder (Plugin)
CWE : CWE-862
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.2.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Medium 5.3
Component : InstaWP Connect – 1-click WP Staging & Migration (Plugin)
CWE : CWE-862
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 0.1.3.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Medium 5.3
Component : Contact Form 7 – PayPal & Stripe Add-on (Plugin)
CWE : CWE-862
The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.5.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Medium 5.3
Component : Revolut Gateway for WooCommerce (Plugin)
CWE : CWE-862
The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 4.22.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Medium 5.3
Component : GiveWP – Donation Plugin and Fundraising Platform (Plugin)
CWE : CWE-862
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 4.16.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Medium 5.3
Component : Pinpoint Booking System – Version 2 (Plugin)
CWE : CWE-20
The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to, and including, 2.9.9.6.8. This is due to the `dopbsp_woocommerce_add_to_cart` AJAX action being registered via `wp_ajax_nopriv_*` with no authentication, no nonce verification, and no server-side recalculation of pricing — the `update` handler reads `price_total` directly from the attacker-controlled `cart_data` POST parameter and persists it to the database via `$wpdb->insert()` without validating it against the calendar’s configured pricing. The `woocommerce_before_calculate_totals` callback subsequently reads the stored attacker-supplied value back from the database and passes it directly to `$product->set_price()` without recomputing from calendar settings. This makes it possible for unauthenticated attackers to override the WooCommerce checkout price of any bookable product tied to a booking calendar to an arbitrary value, effectively enabling the purchase of any such product at a self-chosen price.
Medium 5.3
Component : Booking calendar, Appointment Booking System (Plugin)
CWE : CWE-862
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary reservations as paid or completed, cancel legitimate payments, auto-approve reservations, and trigger transactional booking emails by writing attacker-supplied payment status and transaction data directly into the payments table. The auto-approval of reservations is only triggered when the ‘enable_psuccess_approval’ site option is enabled, but payment status manipulation and email dispatch are exploitable regardless of that setting.
Medium 5.3
Component : Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder (Plugin)
CWE : CWE-89
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via ‘{username}’ Placeholder in Dynamic-Choice Field WHERE Clause in all versions up to, and including, 1.15.44 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This requires that a form is configured with a DB-backed dynamic choice field whose WHERE template references the {username} placeholder, and the attacker must first set their own display_name to a SQL payload via the standard WordPress profile edit screen before triggering the fm_reload_input AJAX endpoint.
Medium 5.3
Component : WPMobile.App (Plugin)
CWE : CWE-862
The WPMobile.App plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 11.77. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Medium 5.3
Component : WebHosting4U Secure Card Gateway for ePay Paycenter (Piraeus Bank) (Plugin)
CWE : CWE-862
The Secure Card Gateway for ePay Paycenter (Piraeus Bank) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.0.32. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Medium 5.3
Component : Hydra Booking — Appointment Scheduling & Booking Calendar (Plugin)
CWE : CWE-862
The Hydra Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Medium 5.3
Component : ToneDen Shortcode (Plugin)
CWE : CWE-639
The Do Lasso plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 358 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Medium 5.3
Component : Forminator Forms – Contact Form, Payment Form & Custom Form Builder (Plugin)
CWE : CWE-639
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.55.0.2 via the ‘draft’ parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to enumerate sequential integer entry IDs via the ‘draft’ parameter and read other users’ saved draft form data, including names, email addresses, phone numbers, addresses, and free-form message content. This is only exploitable on forms that have the ‘Save and Continue’ feature enabled.
Medium 5.3
Component : Product Table & List Builder For WooCommerce (Plugin)
CWE : CWE-74
The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and including, 5.6.0 via the ‘laptop_scroll_offset’ shortcode attribute exposed through the unauthenticated wcpt_ajax() AJAX handler. The handler is registered for wp_ajax_nopriv_wcpt_ajax, JSON-decodes attacker-supplied attributes, only allowlists key names (not values), applies a preg_replace that strips only [ ] < >, and passes the value through do_shortcode into wcpt_style__sticky_sidebar(), where it is interpolated verbatim into inline CSS (‘top: {$top}px;’ and ‘max-height: calc(100vh – {$top}px);’) with no numeric casting or CSS escaping. This makes it possible for unauthenticated attackers to inject arbitrary CSS declarations and rules on pages rendering a product table with sticky sidebar enabled, which can be leveraged for data exfiltration (via attribute-selector + background-image URLs), UI redressing, and phishing that bypasses CSPs permitting inline styles.
Medium 4.9
Component : affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display (Plugin)
CWE : CWE-89
The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 3.8.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Medium 4.9
Component : Mailchimp for WooCommerce (Plugin)
CWE : CWE-89
The Mailchimp for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to 6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Medium 4.9
Component : Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms (Plugin)
CWE : CWE-89
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via the ‘key’ parameter in all versions up to, and including, 5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Medium 4.9
Component : Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms (Plugin)
CWE : CWE-89
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via Pattern JSON Keys/Values in all versions up to, and including, 5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Medium 4.9
Component : Slider Hero with Video Background, Animation (Plugin)
CWE : CWE-89
The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7 via the qcld_sliderhero_duplicate() function. Slide data (description, title, btn, btn2, image_link, custom, etc.) is stored safely via $wpdb->update() with %s placeholders in the qchero_save_image AJAX handler, but when an administrator triggers the ‘heroduplicateslider’ task, qcld_sliderhero_duplicate() re-reads every slide column and concatenates the raw values directly into an INSERT VALUES tuple that is then executed with $wpdb->query() — with no $wpdb->prepare(), esc_sql(), or _real_escape_string in between. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Medium 4.9
Component : WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors (Plugin)
CWE : CWE-89
The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to generic SQL Injection via the ‘status’ parameter in all versions up to, and including, 2.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The sanitize_text_field callback strips HTML but leaves SQL metacharacters intact, and wp_magic_quotes slash protection does not apply because WP_REST_Server::serve_request() calls wp_unslash() on GET parameters before the sanitize callback executes.
Medium 4.9
Component : Kirki – Freeform Page Builder, Website Builder & Customizer (Plugin)
CWE : CWE-22
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1.1 via the ‘data’ parameter parameter. This makes it possible for authenticated attackers, with editor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The intended strpos()-based guard against leaving the uploads directory is bypassed by crafting a URL that includes the uploads base path as a substring while embedding directory traversal sequences, such as /wp-content/uploads/../../wp-config.php.
Medium 4.9
Component : NEX-Forms – Ultimate Forms Plugin for WordPress (Plugin)
CWE : CWE-89
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the ‘additional_params’ parameter in all versions up to, and including, 9.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with admin-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order vulnerability; the payload is stored via the submission_report2 AJAX handler (which lacks a nonce check and relies solely on a capability that can be configured down to subscriber-level) and triggered when a CSV export is generated.
Medium 4.9
Component : User Login History (Plugin)
CWE : CWE-89
The User Login History plugin for WordPress is vulnerable to SQL Injection via the ‘blog_id’ parameter in all versions up to, and including, 2.1.7. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is only exploitable on multisite installations.
Medium 4.8
Component : Advanced Excerpt (Plugin)
CWE : CWE-79
The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it on the front end of the site, which could allow administrators (including those without the unfiltered_html capability, such as on multisite) to perform Stored Cross-Site Scripting attacks that execute in the context of any visitor viewing affected pages.
Medium 4.4
Component : Admin Custom Login (Plugin)
CWE : CWE-79
The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Medium 4.4
Component : Gravity Booster – Styles & Layouts for Gravity Forms (Plugin)
CWE : CWE-79
The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Medium 4.3
Component : Library Management System (Plugin)
CWE : CWE-89
The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing users with a role as low as Subscriber to perform SQL injection and extract arbitrary data from the database, including user password hashes.
Medium 4.3
Component : Ray Enterprise Translation (Plugin)
CWE : CWE-862
The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to add or delete the site’s configured languages.
Medium 4.3
Component : Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce (Plugin)
CWE : CWE-639
The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing users with contributor-level access and above to read other customers’ order data including personal information by iterating order identifiers.
Medium 4.3
Component : KiviCare – Clinic & Patient Management System (EHR) (Plugin)
CWE : CWE-639
The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, allowing authenticated patient-level users to read other patients’ bills, invoices and appointment details.
Medium 4.3
Component : WP Crowdfunding (Plugin)
CWE : CWE-284
The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX actions, allowing any authenticated users such as Subscribers to create crowdfunding campaign posts despite not being granted that permission.
Medium 4.3
Component : WP Photo Album Plus (Plugin)
CWE : CWE-639
The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload into the album they target when it processes a front-end upload, allowing any authenticated user, such as a Subscriber, to upload files into albums owned by other users or by the administrator. Exploitation requires the WP Photo Album Plus WordPress plugin before 9.2.09.002’s front-end user upload feature to be enabled, which is not the default.
Medium 4.3
Component : ProSolution WP Client (Plugin)
CWE : CWE-862
The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX actions, and the nonce they rely on is published on its public frontend, allowing any authenticated user, such as a subscriber, to trigger an administrative data synchronisation and to clear the ProSolution WP Client WordPress plugin before 2.0.9’s activity records.
Medium 4.3
Component : Astro Booking Engine (Plugin)
CWE : CWE-352
The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion functionality. This makes it possible for unauthenticated attackers to delete all plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Medium 4.3
Component : Solace Extra (Plugin)
CWE : CWE-862
The Solace Extra plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.6.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
Medium 4.3
Component : Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin (Plugin)
CWE : CWE-862
The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.23.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
Medium 4.3
Component : AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress (Plugin)
CWE : CWE-862
The AcyMailing SMTP Newsletter plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 10.11.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
Medium 4.3
Component : PPWP – Password Protect Pages (Plugin)
CWE : CWE-639
The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.20 via the ppw_free_set_password AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to update the password on any password protected post and subsequently access the content.
Medium 4.3
Component : Service Finder Bookings (Plugin)
CWE : CWE-862
The Service Finder Booking plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
Medium 4.3
Component : Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce (Plugin)
CWE : CWE-200
The Event SOlution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.1.18. This makes it possible for authenticated attackers, with customer-level access and above, to extract sensitive user or configuration data.
Medium 4.3
Component : ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization (Plugin)
CWE : CWE-862
The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.11.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify configuration options of third-party plugins including ShortPixel Image Optimizer, Autoptimize, WP Rocket, Imagify, and LiteSpeed Cache, as well as the plugin’s own API key and account binding. Exploitation requires the respective third-party plugins to be installed, as the impact against those plugins’ settings is only reachable when those plugins are present.
Medium 4.3
Component : Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI (Plugin)
CWE : CWE-862
The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with delegated form management access and above, to activate arbitrary already-installed WordPress plugins — including previously deactivated or vulnerable plugins — without holding the core activate_plugins capability. Exploitation requires the target user to hold a delegated Everest Forms capability (manage_everest_forms, everest_forms_create_forms, or everest_forms_view_forms), which the plugin’s own roles and permissions tool allows administrators to assign to non-administrator roles such as Author; the nonces required to exploit the AJAX handlers are emitted on EVF admin pages accessible to any such delegated user.
Medium 4.3
Component : Kubio AI Page Builder (Plugin)
CWE : CWE-862
The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to overwrite front-page configuration options (show_on_front, page_on_front, and page_for_posts), rewrite primary navigation menu items, replace template parts, and overwrite the Kubio global-data post. Although a nonce check via check_ajax_referer() is present, the nonce is unconditionally emitted into window.kubioUtilsData for every user who can load the block editor, making it harvestable by any Contributor and therefore an ineffective authorization barrier.
Medium 4.3
Component : Online Scheduling and Appointment Booking System – Bookly (Plugin)
CWE : CWE-639
The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment, action=bookly_mobile_staff_cabinet) in frontend/modules/mobile_staff_cabinet/api/handlers/Handler1_0.php. This is due to the handler loading an Appointment by the attacker-supplied params[id] without verifying that the appointment’s staff_id matches the authenticated staff member, whereas sibling operations (deleteAppointment, saveAppointment, appointments list) correctly scope to $this->staff->getId() when $this->role === ROLE_STAFF. This makes it possible for authenticated attackers, with staff-level mobile cabinet access (any valid access_key token bound to a Staff entity), to read appointment details — including the internal note and the full customer_appointments collection (customer full_name, email, phone, notes, custom_fields, extras, payment_total, payment_type, payment_status) — belonging to other staff members by enumerating sequential appointment IDs.
Medium 4.3
Component : Tourfic Toolkit (Plugin)
CWE : CWE-862
The Travelfic Toolkit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.5.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
Medium 4.3
Component : Kirki – Freeform Page Builder, Website Builder & Customizer (Plugin)
CWE : CWE-862
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.1.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to read arbitrary user metadata and sensitive user record fields — including email address, assigned roles, registration date, and any user_meta values — belonging to any WordPress user including administrators, by supplying a target user ID with a user-type context to the frontend collection endpoint.
Vulnerabilities by CWE
| CWE | Count |
|---|---|
| CWE-79 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) |
52 |
| CWE-89 Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) |
39 |
| CWE-862 Missing Authorization |
28 |
| CWE-639 Authorization Bypass Through User-Controlled Key |
10 |
| CWE-22 Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) |
7 |
| CWE-269 Improper Privilege Management |
6 |
| CWE-502 Deserialization of Untrusted Data |
6 |
| CWE-434 Unrestricted Upload of File with Dangerous Type |
6 |
| CWE-94 Improper Control of Generation of Code (‘Code Injection’) |
4 |
| CWE-287 Improper Authentication |
4 |
| CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) |
3 |
| CWE-200 Exposure of Sensitive Information to an Unauthorized Actor |
3 |
| CWE-352 Cross-Site Request Forgery (CSRF) |
3 |
| CWE-266 Incorrect Privilege Assignment |
2 |
| CWE-918 Server-Side Request Forgery (SSRF) |
2 |
| CWE-284 Improper Access Control |
2 |
| CWE-23 Relative Path Traversal |
1 |
| CWE-640 Weak Password Recovery Mechanism for Forgotten Password |
1 |
| CWE-704 | 1 |
| CWE-863 Incorrect Authorization |
1 |
| CWE-285 Improper Authorization |
1 |
| CWE-20 Improper Input Validation |
1 |
| CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (‘Injection’) |
1 |
Weekly News
Source : WordPress
The official WordPress Browser Extension is now available for Google Chrome and Chromium-based browsers in the Chrome Web Store and for Safari on macOS in the Mac App Store. This new open source extension lets logged-in site users easily hide the admin bar while keeping its most helpful shortcuts in the browser toolbar, provides quick […]
Source : SecurityWeek
WordPress 7.0.4 fixes a high-severity remote code execution vulnerability (CVE-2026-65640) that allows authenticated users with Author-level permissions or higher to execute arbitrary code by uploading malicious PostScript files on affected Imagick/Ghostscript installations.
Source : WordPress
WordPress 7.0.4 is now available WordPress 7.0.4 is now available which features a security fix. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.4 by downloading it from WordPress.org, or visiting your site’s Dashboard → Updates and clicking Update Now. Sites that support […]
Source : The Hacker News
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads.
"Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.
Source : BleepingComputer
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts. […]
Find more statistics on WordPress vulnerabilities at https://seckhmet.com/en/stats.php