Common Vulnerabilities and Exposures (CVE)

CVE-2026-75966

Sep 9, 2026 03:28:49 UTC

The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'episode_contributor[..][..][comment]' Parameter in all versions up to, and including, 4.5.5 due to insufficient input sanitization and outp...

CVE-2026-11363

Sep 9, 2026 03:28:48 UTC

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes it possible for authe...

CVE-2026-19944

Sep 9, 2026 03:28:48 UTC

The WP Crowdfunding plugin for WordPress is vulnerable to generic SQL Injection via 'wpneo_reward' Post Meta in all versions up to, and including, 2.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient prep...

CVE-2026-19800

Sep 9, 2026 03:28:48 UTC

The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and including, 1.31.0 due to insufficient escaping on t...

CVE-2026-19797

Sep 9, 2026 03:28:47 UTC

The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_group_section' parameter in all versions up to, and including, 2.3.18 due to insufficient input sanitization and output escaping. This...

CVE-2026-77187

Sep 9, 2026 03:28:47 UTC

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes in all versions up to, and including, 3.8.3 due to insufficient input sanitization an...

CVE-2026-77186

Sep 9, 2026 03:28:47 UTC

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fallback' Shortcode Attribute in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output es...

CVE-2026-84293

Sep 9, 2026 03:28:46 UTC

The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output ...

CVE-2026-7804

Sep 9, 2026 03:28:46 UTC

The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpf_fid' parameter in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escapin...

CVE-2026-17553

Sep 9, 2026 03:28:45 UTC

The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.9.3. This is due to the ec_ajax_save_page_default_options() AJAX handler iterating over every $_POST key and passing it directly ...

CVE-2026-81644

Sep 9, 2026 03:25:36 UTC

DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availability.

CVE-2026-49312

Sep 9, 2026 03:23:35 UTC

Permission control vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVE-2026-49310

Sep 9, 2026 03:22:18 UTC

Permission control vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVE-2026-49314

Sep 9, 2026 03:19:50 UTC

OOB write vulnerability in the rendering and composition module. Impact: Successful exploitation of this vulnerability may affect availability.

CVE-2026-49311

Sep 9, 2026 03:16:45 UTC

Permission control vulnerability in the event notification module.Impact: Successful exploitation of this vulnerability may affect availability.