Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26391
Total
1955
Critical
7971
High
8223
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-8866 | MEDIUM | 6.4 | The jQuery googleslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'googleslides' shortcode in all versions up to, and including, 1.3. This … | May 27, 2026 |
| CVE-2026-8847 | MEDIUM | 6.4 | The Dideo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dideo' shortcode in version 1.0. This is due to insufficient input … | May 27, 2026 |
| CVE-2026-8846 | MEDIUM | 6.4 | The Tuxquote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'TUXQUOTE' shortcode in versions up to, and including, 1.3. This is due … | May 27, 2026 |
| CVE-2026-8845 | MEDIUM | 6.4 | The Islamic Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'islamicDB-roqya' shortcode in versions up to, and including, 1.0. This is … | May 27, 2026 |
| CVE-2026-8844 | MEDIUM | 6.4 | The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspcheck' shortcode in versions up to, and including, 0.0.3. This is … | May 27, 2026 |
| CVE-2026-8842 | MEDIUM | 6.4 | The Google+ Link Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gplusnamelink' shortcode in versions up to, and including, 1.0. This … | May 27, 2026 |
| CVE-2026-8837 | MEDIUM | 6.4 | The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adid' Shortcode Attribute in all versions up … | May 27, 2026 |
| CVE-2026-8787 | HIGH | 8.8 | The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.1.1. This is due … | May 27, 2026 |
| CVE-2026-8760 | CRITICAL | 9.8 | The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an … | May 27, 2026 |
| CVE-2026-8708 | MEDIUM | 4.3 | The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing … | May 27, 2026 |
| CVE-2026-8707 | MEDIUM | 6.1 | The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versions up to, and including, 1.2.4 due … | May 27, 2026 |
| CVE-2026-8703 | MEDIUM | 6.4 | The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.0.0 due to … | May 27, 2026 |
| CVE-2026-8702 | MEDIUM | 6.4 | The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the 'div' attribute of the 'gbitoprint' shortcode. This … | May 27, 2026 |
| CVE-2026-8701 | MEDIUM | 6.4 | The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the `title-ticker-slide`, `title-ticker-fade`, and `title-ticker-typing` shortcodes. This … | May 27, 2026 |
| CVE-2026-8698 | MEDIUM | 6.4 | The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0. This is due to insufficient output escaping in the … | May 27, 2026 |
| CVE-2026-8048 | MEDIUM | 6.4 | The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' shortcode attribute in the 'my-email' shortcode in all versions … | May 27, 2026 |
| CVE-2026-8040 | MEDIUM | 6.4 | The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute in the 'faq' shortcode in all versions up … | May 27, 2026 |
| CVE-2026-7614 | MEDIUM | 4.3 | The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to … | May 27, 2026 |
| CVE-2026-6268 | HIGH | 7.1 | The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_notify_dismiss_action AJAX handler before outputting it back in the … | May 27, 2026 |
| CVE-2026-9236 | MEDIUM | 4.3 | The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in … | May 27, 2026 |
| CVE-2026-8450 | CRITICAL | 9.1 | HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets … | May 27, 2026 |
| CVE-2026-6287 | MEDIUM | 5.4 | The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blockUniqId' block attribute in multiple … | May 27, 2026 |
| CVE-2026-49000 | HIGH | 7.0 | An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to … | May 27, 2026 |
| CVE-2025-14481 | MEDIUM | 4.3 | The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all versions up to, and including, 26.5. This is due to … | May 27, 2026 |
| CVE-2026-9022 | MEDIUM | 6.4 | The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in all versions up to, and including, 1.7.1 … | May 27, 2026 |