Common Vulnerabilities and Exposures (CVE)

CVE-2026-77183

Oct 10, 2026 05:31:01 UTC

The FooSales – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.43.0. This is due to the plugin not properly validating a user's iden...

CVE-2026-91862

Oct 10, 2026 05:31:01 UTC

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-image-points' parameter in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. Th...

CVE-2026-94421

Oct 10, 2026 05:31:01 UTC

The Church Admin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 5.1.2 due to insufficient input sanitization and output escaping. This makes it possible for ...

CVE-2026-96667

Oct 10, 2026 05:31:00 UTC

The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 7.3 due to insufficient input sanitizatio...

CVE-2026-94375

Oct 10, 2026 05:31:00 UTC

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8 via the get_file_path. This makes it possible for unauthenticated attackers to ...

CVE-2026-103520

Oct 10, 2026 05:30:59 UTC

The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom text attribute (user-defined field name)' parameter in all versions up to, and including,...

CVE-2026-104763

Oct 10, 2026 05:30:59 UTC

The Post Export Import with Media plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.17.1 via the 'file_path' parameter parameter. This makes it possible for authenticated attackers, with admin...

CVE-2026-104725

Oct 10, 2026 05:30:59 UTC

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9 This is due to a missing ownership and capability check on the `user` parameter...

CVE-2026-14379

Oct 10, 2026 05:30:58 UTC

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_id' parameter in all versions up to, and including, 7.9.4 due t...

CVE-2026-16776

Oct 10, 2026 05:30:58 UTC

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.14.2 due to insufficient input sanitiza...

CVE-2026-83526

Oct 10, 2026 05:30:58 UTC

The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This is due to insufficient file type validation in check_mimetype(), which writes atta...

CVE-2026-104742

Oct 10, 2026 05:30:57 UTC

The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized ...

CVE-2026-104766

Oct 10, 2026 05:30:57 UTC

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.7.3. This is due to the `OsSettingsController::update()` han...

CVE-2026-104741

Oct 10, 2026 05:30:56 UTC

The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized ...

CVE-2026-78068

Oct 10, 2026 05:30:56 UTC

The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell Content in all versions up to, and including, 1.3.35 due to insufficient input sanitization and output escaping. This ma...