Common Vulnerabilities and Exposures (CVE)

CVE-2026-19858

Sep 6, 2026 10:41:50 UTC

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post an...

CVE-2026-19861

Sep 6, 2026 10:41:35 UTC

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inje...

CVE-2026-77826

Sep 6, 2026 10:41:21 UTC

The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose ...

CVE-2026-78149

Sep 6, 2026 10:41:07 UTC

The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenticated AJAX action, allowing unauthenticated users to read protected ...

CVE-2026-78150

Sep 6, 2026 10:40:51 UTC

The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges and above to copy any private or password protected post into a draf...

CVE-2026-78362

Sep 6, 2026 10:40:36 UTC

The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline W...

CVE-2026-81348

Sep 6, 2026 10:40:22 UTC

The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post content, comments and post URLs from a site th...

CVE-2026-81404

Sep 6, 2026 10:40:07 UTC

The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users w...

CVE-2026-81423

Sep 6, 2026 10:39:51 UTC

The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect visitors to an arbitrary external website, which can be leveraged f...

CVE-2026-81424

Sep 6, 2026 10:39:36 UTC

The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at l...

CVE-2026-82304

Sep 6, 2026 10:39:22 UTC

The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

CVE-2026-82846

Sep 6, 2026 10:39:07 UTC

The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting a...

CVE-2026-83543

Sep 6, 2026 10:38:51 UTC

The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the re...

CVE-2026-83544

Sep 6, 2026 10:38:36 UTC

The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that e...

CVE-2026-84021

Sep 6, 2026 10:38:22 UTC

The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a filter that can be evaded, allowing users with the Contributor role and above to inject arbitr...