Common Vulnerabilities and Exposures (CVE)

CVE-2026-97340

Oct 10, 2026 07:41:48 UTC

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Stored Cross-Site Scripting via the user profile 'Author Page' social link contact-method fields (author_facebook, author_twitter, author_linkedin,...

CVE-2026-102291

Oct 10, 2026 07:41:47 UTC

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.3.1 This is due to the plugin substituting a user's `display_name` i...

CVE-2026-104759

Oct 10, 2026 07:41:47 UTC

The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Authentication Bypass via OIDC Nonce Replay in all versions up to, and including, 44.1 This is due to `Id_Token_Service_Deprecate...

CVE-2026-102774

Oct 10, 2026 07:41:46 UTC

The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Image 'alt' Attribute in Community Post Content in all versions up to, and including, 1.12.1 due to insuffi...

CVE-2026-104728

Oct 10, 2026 07:41:46 UTC

The AutomatorWP – No-Code Workflow Automation, Integration & Webhooks Plugin, now with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifyi...

CVE-2026-96653

Oct 10, 2026 07:41:46 UTC

The WP Directory Kit plugin for WordPress is vulnerable to time-based SQL Injection via 'display_name' Profile Field (Second-Order) in all versions up to, and including, 1.5.9 due to insufficient escaping on the user supplied parameter and ...

CVE-2026-100178

Oct 10, 2026 07:41:45 UTC

The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'adverts_location' parameter in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping...

CVE-2026-96765

Oct 10, 2026 07:41:45 UTC

The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id_token' parameter in all versions up to, and including, 44.1 due to insufficient input san...

CVE-2026-97396

Oct 10, 2026 07:41:45 UTC

The Email Marketing for WordPress and WooCommerce – Retainful plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 1.0.10 due to insufficient input sanitization and...

CVE-2026-104803

Oct 10, 2026 07:41:44 UTC

The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via the `uuid` and `code` parameters of the social-login callback handler registered on the `init` hook. The vulnerabi...

CVE-2026-101921

Oct 10, 2026 07:41:44 UTC

The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'attacker-chosen key referenced by the smart tag (e.g. "x")' p...

CVE-2026-101920

Oct 10, 2026 07:41:43 UTC

The Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'comment (href attribute inside comment content)' parameter in all versions...

CVE-2026-96662

Oct 10, 2026 07:41:43 UTC

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to generic SQL Injection via 'booking[service_id]' Parameter in all versions up to, and including, 5.7.2 due to insufficient...

CVE-2026-100147

Oct 10, 2026 07:41:43 UTC

The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shipping_first_name' parameter in all versions up to, and including, 3.16.0.5 due to insufficient input sanit...

CVE-2026-96563

Oct 10, 2026 07:41:42 UTC

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'stm_f_s' parameter in all versions up to, and including, 1.4.123 due to insufficient input sanitization and ...