Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26391
Total
1955
Critical
7971
High
8223
Medium
CVE ID Severity Score Description Published
CVE-2026-9014 MEDIUM 5.3 The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_stats() function in versions … May 27, 2026
CVE-2026-8994 HIGH 8.1 The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.3.3. The `ajaxLoginWithNear()` function — registered … May 27, 2026
CVE-2026-8943 MEDIUM 4.3 The GoStats for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to … May 27, 2026
CVE-2026-8941 MEDIUM 4.3 The CDN Linker lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.1. This is due to missing … May 27, 2026
CVE-2026-8939 MEDIUM 4.3 The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2. This is due to missing … May 27, 2026
CVE-2026-8938 MEDIUM 4.3 The auto making JSON-LD plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.3. This is due to … May 27, 2026
CVE-2026-8911 MEDIUM 6.1 The WP AutoBuzz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing … May 27, 2026
CVE-2026-8903 MEDIUM 4.3 The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is … May 27, 2026
CVE-2026-8899 MEDIUM 6.4 The Auto Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'thumbnails' shortcode in all versions up to, and including, 1.0. This … May 27, 2026
CVE-2026-8898 MEDIUM 6.4 The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'org-events' shortcode in versions up to, and including, 3.0. This … May 27, 2026
CVE-2026-8897 MEDIUM 6.4 The Shortcode Buddy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 0.1.9.5 due to … May 27, 2026
CVE-2026-8894 MEDIUM 6.4 The iWR Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `iwrtooltip` shortcode in versions up to, and including, 1.0. This … May 27, 2026
CVE-2026-8891 MEDIUM 6.4 The BitForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bitform' shortcode in versions up to, and including, 1.1.0. This is … May 27, 2026
CVE-2026-8887 MEDIUM 6.4 The Listen Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'listen' shortcode in versions up to, and including, 1.0. This is … May 27, 2026
CVE-2026-8886 MEDIUM 6.4 The hk_shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title-plane' shortcode in versions up to, and including, 1.0. This is due … May 27, 2026
CVE-2026-8884 MEDIUM 6.4 The Instant-Quote.co Quotation Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.3.4 due … May 27, 2026
CVE-2026-8877 MEDIUM 6.4 The Responsive Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rem_video' shortcode in versions up to, and including, 0.1. This … May 27, 2026
CVE-2026-8875 MEDIUM 6.4 The Easy Prism Syntax Highlighter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'code' (and 'c') shortcode in versions up to, … May 27, 2026
CVE-2026-8873 MEDIUM 6.4 The Content Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 2.4.1 due to … May 27, 2026
CVE-2026-8872 MEDIUM 6.4 The Animate Your Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animation-set' shortcode in versions up to, and including, 1.0.0. … May 27, 2026
CVE-2026-8871 MEDIUM 6.4 The Formidable Kinetic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'kinetic_link' shortcode in versions up to, and including, 1.1.01. This is … May 27, 2026
CVE-2026-8870 MEDIUM 6.4 The Team Master – A Modern WordPress Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up … May 27, 2026
CVE-2026-8869 MEDIUM 6.4 The Mutual Funds Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute in versions up to, and including, 1.2.1. … May 27, 2026
CVE-2026-8868 MEDIUM 6.4 The Single Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'single-mailchimp' shortcode in all versions up to, and including, 1.4. This … May 27, 2026
CVE-2026-8867 MEDIUM 6.4 The Post Category Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'postcategorygallery' shortcode in versions up to, and including, 1.0.0. … May 27, 2026