Wordfence Intelligence Weekly WordPress Vulnerability Report (April 13, 2026 to April 19, 2026)
Autor: Chloe Chamberland
⚠️ CVE-Referenzen:
CVE-2026-3596
CVE-2026-39540
CVE-2026-3649
CVE-2026-1541
CVE-2026-6372
CVE-2026-40724
CVE-2026-40725
CVE-2026-3464
CVE-2026-6080
CVE-2026-6203
CVE-2026-39594
CVE-2026-4666
CVE-2026-40735
CVE-2025-15635
CVE-2026-4005
CVE-2026-4091
CVE-2026-1782
CVE-2026-4388
CVE-2026-0718
CVE-2026-3642
CVE-2026-39494
CVE-2026-5718
CVE-2026-3369
CVE-2026-5502
CVE-2026-1559
CVE-2025-15441
CVE-2026-39512
CVE-2026-4109
CVE-2026-6048
CVE-2026-3299
CVE-2026-6439
CVE-2026-2840
CVE-2026-39593
CVE-2026-40784
CVE-2026-5234
CVE-2026-5231
CVE-2026-39598
CVE-2026-39468
CVE-2026-2986
CVE-2026-5710
CVE-2026-3878
CVE-2026-3155
CVE-2026-2505
CVE-2026-40733
CVE-2026-40720
CVE-2026-40727
CVE-2026-3830
CVE-2026-3330
CVE-2025-15565
CVE-2026-5717
CVE-2026-39527
CVE-2026-6293
CVE-2026-40786
CVE-2026-1572
CVE-2026-2834
CVE-2026-40726
CVE-2026-4479
CVE-2026-40739
CVE-2026-3489
CVE-2026-4059
CVE-2026-39531
CVE-2026-1838
CVE-2026-3876
CVE-2026-3875
CVE-2026-1607
CVE-2026-4812
CVE-2025-15470
CVE-2026-3659
CVE-2026-4352
CVE-2026-3595
CVE-2026-6441
CVE-2026-5797
CVE-2026-5427
CVE-2026-1620
CVE-2026-4853
CVE-2026-3581
CVE-2025-63029
CVE-2026-3885
CVE-2026-2582
CVE-2026-3017
CVE-2026-0894
CVE-2026-1852
CVE-2026-3995
CVE-2026-5694
CVE-2026-2262
CVE-2026-6370
CVE-2026-6451
CVE-2026-39513
CVE-2026-5162
CVE-2026-40731
CVE-2025-15636
CVE-2026-6518
CVE-2026-4817
CVE-2026-4365
CVE-2026-40738
CVE-2026-1314
CVE-2026-39597
CVE-2026-2434
CVE-2026-4011
CVE-2026-3773
CVE-2026-4801
CVE-2026-40736
CVE-2025-14868
CVE-2026-39548
CVE-2026-5070
CVE-2026-1509
CVE-2026-39463
CVE-2026-40741
CVE-2025-13364
CVE-2026-4002
CVE-2026-39579
CVE-2026-39491
CVE-2026-39511
CVE-2026-39474
CVE-2026-4032
CVE-2026-3488
CVE-2026-3551
CVE-2026-3998
CVE-2026-4659
CVE-2026-5617
CVE-2026-39530
CVE-2026-1555
CVE-2026-3599
CVE-2026-2396
CVE-2026-0868
CVE-2026-3355
CVE-2026-4160
CVE-2026-4949
CVE-2026-39507
CVE-2026-39532
CVE-2026-3461
CVE-2026-39525
CVE-2025-53444
CVE-2026-4880
CVE-2026-5050
CVE-2026-3643
CVE-2026-6227
CVE-2026-3614
Last week, there were 139 vulnerabilities disclosed in 116 WordPress Plugins and 10 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 84 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 33,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status
Number of Vulnerabilities
Patched
109
Unpatched
30
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating
Number of Vulnerabilities
Low Severity
1
Medium Severity
86
High Severity
46
Critical Severity
6
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE
Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
48
Missing Authorization
27
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
15
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
10
Deserialization of Untrusted Data
9
Cross-Site Request Forgery (CSRF)
7
Authorization Bypass Through User-Controlled Key
5
Unrestricted Upload of File with Dangerous Type
5
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
2
Improper Control of Generation of Code ('Code Injection')
2
Authentication Bypass Using an Alternate Path or Channel
1
Embedded Malicious Code
1
Exposure of Sensitive Information to an Unauthorized Actor
1
Improper Input Validation
1
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
1
Improper Privilege Management
1
Improper Verification of Cryptographic Signature
1
Incorrect Privilege Assignment
1
URL Redirection to Untrusted Site ('Open Redirect')
1
Researchers That Contributed to WordPress Security Last Week
Researcher Name
Number of Vulnerabilities
Nguyen Ba Khanh
9
Muhammad Yudha - DJ
9
Muhammad Nur Ibnu Hubab (Ibnu)
7
Athiwat Tiprasaharn (Jitlada)
6
Denver Jackson
5
Kai Aizen
4
daroo
4
Supakiad S. (m3ez)
3
Webbernaut
3
Chawabhon Netisingha (JNX03)
3
0xd4rk5id3
3
Itthidej Aramsri (Boeing777)
3
Martín Martín
3
zakaria
2
Gilang - DJ
2
Osvaldo Noe Gonzalez Del Rio (Os)
2
Drew Webber (mcdruid)
2
Naoya Takahashi (nakko)
2
Leonid Semenenko (lsemenenko)
2
Tharadol Suksamran (d3kc4rt_1)
2
Nabil Irawan
2
Fernando Mecozzi
2
Poli
2
João Pedro Soares de Alcântara
2
Chiao-Lin Yu (Steven Meow)
2
Dmitrii Ignatyev
2
Anthony Cihan (Hann1bl3L3ct3r)
1
Louis Deschanel (JeanJeanLeHaxor)
1
Pascal SUN
1
Jared Reyes
1
Pixel_DefaultBR
1
Jakub Herman
1
Prickly Cactus
1
Caspian
1
Ananda Dhakal
1
theviper17y
1
h0xilo
1
Bee
1
Teerachai Somprasong
1
Martino Spagnuolo
1
Sandeep V
1
luc
1
Vilaysone CHANTHAVONG (0xJ0cKkY)
1
hiariz
1
kai63001
1
lucsob
1
Muhammad Sharief
1
Sein Linn
1
Régis SENET
1
PRISM
1
Phat RiO
1
Nguyen Ngoc Duc (duc193)
1
Ivan Cese
1
Abu Hurayra (HurayraIIT)
1
Muhan Luo
1
Kévin Mosbahi (Mika)
1
Ali Osman ERBAS (0110m4n)
1
andrea bocchetti
1
Tin Pham aka TF1T
1
Ren Voza
1
shark3y
1
darkmode
1
Jack Pas (Dark.)
1
MAJidox
1
Victor Pasman
1
Steven Julian
1
BaroHaf
1
Legion Hunter
1
Pattama Tangpoonponwiwat (Kwan)
1
Mohammad Amin Hajian (mamadrce)
1
Jarno Vos (jarnovos)
1
Muhammad Sharief (Md Sharief)
1
ll
1
oolongeya
1
MD. TAREQ AHAMED JONY (itztrq)
1
Rafshanzani Suhada
1
momopon1415
1
Md. Moniruzzaman Prodhan (NomanProdhan)
1
Phat RiO
1
AXIS
1
chaeyp
1
Ronnachai Sretawat Na Ayutaya (Simonhaskelly)
1
Ronnachai Chaipha (rxnr)
1
zaim
1
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name
Software Slug
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery
interactive-3d-flipbook-powered-physics-engine
Academy LMS Pro
academy-pro
Accept Cryptocurrencies with Plisio
plisio-payment-gateway-for-woocommerce
Accessibility Suite by Ability, Inc
online-accessibility
Accessibly – WordPress Website Accessibility
otm-accessibly
AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress
acymailing
Advanced Custom Fields (ACF®)
advanced-custom-fields
Age Verification & Identity Verification by Token of Trust
token-of-trust
Avada (Fusion) Builder
fusion-builder
BackWPup – WordPress Backup & Restore Plugin
backwpup
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)
barcode-scanner-lite-pos-to-manage-products-inventory-and-orders
Basic Google Maps Placemarks
basic-google-maps-placemarks
bBlocks – Essential Gutenberg Blocks & Patterns Collection
b-blocks
Better Find and Replace – AI-Powered Suggestions
real-time-auto-find-and-replace
BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor
betterdocs
Booking Activities
booking-activities
Canto
canto
Career Section
career-section
Categories Images
categories-images
Client Portal Pro
leco-client-portal
CMP – Coming Soon & Maintenance Plugin by NiteoThemes
cmp-coming-soon-maintenance
Coachific Shortcode
coachific-shortcode
CodeColorer
codecolorer
Content Blocks (Custom Post Widget)
custom-post-widget
Contextual Related Posts
contextual-related-posts
Custom New User Notification
custom-new-user-notification
Customer Reviews for WooCommerce
customer-reviews-woocommerce
DirectoryPress – Business Directory And Classified Ad Listing
directorypress
Drag and Drop Multiple File Upload for Contact Form 7
drag-and-drop-multiple-file-upload-contact-form-7
e-shot
e-shot-form-builder
Easy Appointments
easy-appointments
Email Encoder – Protect Email Addresses and Phone Numbers
email-encoder-bundle
EMC – Easily Embed Calendly Scheduling
embed-calendly-scheduling
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)
wp-event-solution
Events Calendar for GeoDirectory
events-for-geodirectory
Flipbox Addon for Elementor
ultimate-flipbox-addon-for-elementor
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration
fluent-boards
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
form-maker
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
geodirectory
Germanized for WooCommerce
woocommerce-germanized
Groundhogg — CRM, Newsletters, and Marketing Automation
groundhogg
HAPPY – Helpdesk Support Ticket System
happy-helpdesk-support-ticket-system
Hostel
hostel
Inquiry form to posts or pages
inquiry-form-to-posts-or-pages
JetBackup – Backup, Restore & Migrate
backup
JetEngine
jet-engine
Jupiter X Core
jupiterx-core
Katalogportal-pdf-sync Widget
katalogportal-pdf-sync
Kubio AI Page Builder
kubio
LatePoint – Calendar Booking Plugin for Appointments and Events
latepoint
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
learnpress
List View Google Calendar
list-view-google-calendar
Livemesh Addons by Elementor
addons-for-elementor
Login as User – Switch User & WooCommerce Login as Customer
one-click-login-as-user
ManageWP Worker
worker
MasterStudy LMS WordPress Plugin – for Online Courses and Education
masterstudy-lms-learning-management-system
Meta Box
meta-box
MetForm Pro
metform-pro
Mini Ajax Cart for WooCommerce
mini-ajax-woo-cart
MyRewards
woorewards
Nexi XPay
cartasi-x-pay
OneSignal – Web Push Notifications
onesignal-free-web-push-notifications
OPEN-BRAIN
open-brain
Page Builder Gutenberg Blocks – CoBlocks
coblocks
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
wp-user-avatar
Payment Gateway for Redsys & WooCommerce Lite
woo-redsys-gateway-light
Petje.af
petje-af
Plugin: CMS für Motorrad Werkstätten
cms-fuer-motorrad-werkstaetten
Post Duplicator
post-duplicator
Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX
ultimate-post
Power Charts – Responsive Beautiful Charts & Graphs
wpgo-power-charts-lite
Prismatic
prismatic
Product Filter for WooCommerce by WBW
woo-product-filter
Product Pricing Table by WooBeWoo
woo-product-pricing-tables
Pz-LinkCard
pz-linkcard
Quick Interest Slider
quick-interest-slider
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker
quiz-master-next
Riaxe Product Customizer
riaxe-product-customizer
Royal Addons for Elementor – Addons and Templates Kit for Elementor
royal-elementor-addons
Royal Elementor Addons Pro
wpr-addons-pro
Shipment Tracker for Woocommerce
shipment-tracker-for-woocommerce
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
woolentor-addons
Smart Online Order for Clover
clover-online-orders
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts
post-carousel
Social Slider Feed
instagram-slider-widget
SpeakOut! Email Petitions
speakout
Surbma | Booking.com Shortcode
surbma-bookingcom-shortcode
Tutor LMS – eLearning and online course solution
tutor
Ultra Addons for WPForms
ultra-addons-for-wpforms
Unlimited Elements For Elementor
unlimited-elements-for-elementor
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
user-registration
User Registration Stripe
user-registration-stripe
UserPro - Community and User Profile WordPress Plugin
userpro
VI: Include Post By
vi-include-post-by
Video Gallery – YouTube Gallery & Responsive Video Playlist
youtube-showcase
VideoZen
videozen
Visa Acceptance Solutions
visa-acceptance-solutions
WCFM Marketplace – Multivendor Marketplace for WooCommerce
wc-multivendor-marketplace
WholeSale Products Dynamic Pricing Management WooCommerce
wholesale-products-dynamic-pricing-management-woocommerce
WM JqMath
wm-jqmath
WooCommerce Product Filters
woocommerce-product-filters
WowShipping Pro
table-rate-shipping-pro
WP Circliful
wp-circliful
WP Customer Area
customer-area
WP Directory Kit
wpdirectorykit
WP Docs
wp-docs
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WP Photo Album Plus
wp-photo-album-plus
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
WP Statistics – Simple, privacy-friendly Google Analytics alternative
wp-statistics
WP YouTube Lyte
wp-youtube-lyte
wpForo Forum
wpforo
WpStream – Live Streaming, Video on Demand, Pay Per View
wpstream
WPZOOM Addons for Elementor – Starter Templates & Widgets
wpzoom-elementor-addons
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
youzify
WordPress Themes with Reported Vulnerabilities Last Week
Software Name
Software Slug
ChapterOne - Bookstore and Publisher WordPress Theme
chapterone
Eldon - Artist Portfolio WordPress Theme
eldon
Eleganzo
eleganzo
Laurits - Portfolio and Agency WordPress Theme
laurits
LuxeDrive - Limousine and Car Rental WordPress Theme
luxedrive
magone
magone
Reina - Spa and Wellness WordPress Theme
reina
ShiftUp - Car Repair & Auto Services WordPress Theme
shiftup
Vantage
vantage
WebStack
webstack
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Barcode Scanner (+Mobile App) <= 1.11.0 - Unauthenticated Privilege Escalation via Insecure Token Authentication
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-4880
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders]
Researcher
0xd4rk5id3
More Details >
Riaxe Product Customizer <= 2.1.2 - Missing Authorization to Unauthenticated Arbitrary Options Update to Privilege Escalation via 'install-imprint' AJAX Action
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-3596
Patch Status
Unpatched
Published
Apr 15, 2026
Affected Software
Riaxe Product Customizer [riaxe-product-customizer]
Researcher
Kai Aizen
More Details >
Visa Acceptance Solutions <= 2.1.0 - Unauthenticated Authentication Bypass via Billing Email
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-3461
Patch Status
Unpatched
Published
Apr 14, 2026
Affected Software
Visa Acceptance Solutions [visa-acceptance-solutions]
Researcher
0xd4rk5id3
More Details >
WebStack <= 1.2024 - Unauthenticated Arbitrary File Upload
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-1555
Patch Status
Unpatched
Published
Apr 14, 2026
Affected Software
WebStack [webstack]
Researcher
Chiao-Lin Yu (Steven Meow)
More Details >
WowShipping Pro 1.0.6 - Injected Backdoor
9.8
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Apr 17, 2026
Affected Software
WowShipping Pro [table-rate-shipping-pro]
Researcher(s): Unknown
More Details >
LearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletion
9.1
CVSS Rating
9.1 (Critical)
CVE-ID
CVE-2026-4365
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses [learnpress]
Researcher
Supakiad S. (m3ez)
More Details >
Academy LMS Pro < 3.5.2 - Authenticated (Custom+) Arbitrary File Upload
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-39598
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Academy LMS Pro [academy-pro]
Researcher
luc
More Details >
AcyMailing 9.11.0 - 10.8.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-3614
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress [acymailing]
Researcher
Ren Voza
More Details >
bBlocks – Essential Gutenberg Blocks & Patterns Collection <= 2.0.31 - Authenticated (Contributor+) Privilege Escalation
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-39579
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
bBlocks – Essential Gutenberg Blocks & Patterns Collection [b-blocks]
Researcher
Abu Hurayra (HurayraIIT)
More Details >
Career Section <= 1.6 - Cross-Site Request Forgery to Arbitrary File Deletion
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2025-14868
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
Career Section [career-section]
Researcher
Ivan Cese
More Details >
CMP – Coming Soon & Maintenance Plugin by NiteoThemes <= 4.1.16 - Missing Authorization to Authenticated (Administrator+) Arbitrary File Upload and Remote Code Execution
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-6518
Patch Status
Patched
Published
Apr 17, 2026
Affected Software
CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance]
Researcher
ll
More Details >
Livemesh Addons by Elementor <= 9.0 - Authenticated (Contributor+) Local File Inclusion via Widget Template Parameter
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-1620
Patch Status
Unpatched
Published
Apr 15, 2026
Affected Software
Livemesh Addons by Elementor [addons-for-elementor]
Researcher
Webbernaut
More Details >
Login as User <= 1.0.3 - Authenticated (Subscriber+) Privilege Escalation via 'oclaup_original_admin' Cookie
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-5617
Patch Status
Unpatched
Published
Apr 14, 2026
Affected Software
Login as User – Switch User & WooCommerce Login as Customer [one-click-login-as-user]
Researcher
BaroHaf
More Details >
WP Customer Area <= 8.3.4 - Authenticated (Subscriber+) Arbitrary File Read/Deletion via ajax_attach_file
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-3464
Patch Status
Patched
Published
Apr 17, 2026
Affected Software
WP Customer Area [customer-area]
Researcher
shark3y
More Details >
WpStream – Live Streaming, Video on Demand, Pay Per View < 4.11.2 - Authenticated (Subscriber+) Arbitrary File Upload
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-39527
Patch Status
Patched
Published
Apr 17, 2026
Affected Software
WpStream – Live Streaming, Video on Demand, Pay Per View [wpstream]
Researcher
Muhammad Sharief (Md Sharief)
More Details >
ChapterOne <= 1.7 - Unauthenticated Local File Inclusion
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40731
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
ChapterOne - Bookstore and Publisher WordPress Theme [chapterone]
Researcher
João Pedro Soares de Alcântara
More Details >
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.6 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-5718
Patch Status
Patched
Published
Apr 17, 2026
Affected Software
Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7]
Researcher
Leonid Semenenko (lsemenenko)
More Details >
Eldon - Artist Portfolio WordPress Theme <= 1.4.1 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40738
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Eldon - Artist Portfolio WordPress Theme [eldon]
Researcher
Denver Jackson
More Details >
Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.4 - Authenticated (Sales Representative+) Arbitrary File Deletion
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40727
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Groundhogg — CRM, Newsletters, and Marketing Automation [groundhogg]
Researcher
daroo
More Details >
Laurits <= 1.5.1 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40736
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Laurits - Portfolio and Agency WordPress Theme [laurits]
Researcher
Denver Jackson
More Details >
LuxeDrive - Limousine and Car Rental WordPress Theme <= 1.4 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40739
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
LuxeDrive - Limousine and Car Rental WordPress Theme [luxedrive]
Researcher
Denver Jackson
More Details >
Meta Box <= 5.11.1 - Authenticated (Contributor+) Arbitrary File Deletion
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-39468
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
Meta Box [meta-box]
Researcher
Nguyen Ba Khanh
More Details >
Reina <= 2.1 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40735
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Reina - Spa and Wellness WordPress Theme [reina]
Researcher
Denver Jackson
More Details >
ShiftUp <= 1.3 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40733
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
ShiftUp - Car Repair & Auto Services WordPress Theme [shiftup]
Researcher
Denver Jackson
More Details >
WooCommerce Product Filters < 2.0.6 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40725
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
WooCommerce Product Filters [woocommerce-product-filters]
Researcher
Phat RiO
More Details >
DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.26 - Unauthenticated SQL Injection via 'packages'
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-3489
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
DirectoryPress – Business Directory And Classified Ad Listing [directorypress]
Researcher
Leonid Semenenko (lsemenenko)
More Details >
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.6 - Unauthenticated Limited Arbitrary File Read via mfile Field
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-5710
Patch Status
Patched
Published
Apr 17, 2026
Affected Software
Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7]
Researcher
Osvaldo Noe Gonzalez Del Rio (Os)
More Details >
Easy Appointments <= 3.12.21 - Unauthenticated Sensitive Information Exposure via REST API
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-2262
Patch Status
Patched
Published
Apr 17, 2026
Affected Software
Easy Appointments [easy-appointments]
Researcher
MD. TAREQ AHAMED JONY (itztrq)
More Details >
Events Calendar for GeoDirectory <= 2.3.25 - Authenticated (Contributor+) PHP Object Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-39532
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Events Calendar for GeoDirectory [events-for-geodirectory]
Researcher
daroo
More Details >
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder < 1.15.38 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2025-15441
Patch Status
Patched
Published
Apr 14, 2026
Affected Software
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker]
Researcher
hiariz
More Details >
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.152 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-39512
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory [geodirectory]
Researcher
Tin Pham aka TF1T
More Details >
JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via '_cct_search' Parameter
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-4352
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
JetEngine [jet-engine]
Researcher
h0xilo
More Details >
Payment Gateway for Redsys & WooCommerce Lite <= 7.0.0 - Improper Verification of Cryptographic Signature to Unauthenticated Payment Status Manipulation
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-5050
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
Payment Gateway for Redsys & WooCommerce Lite [woo-redsys-gateway-light]
Researcher
Nguyen Ngoc Duc (duc193)
More Details >
Post Duplicator <= 3.0.10 - Authenticated (Contributor+) PHP Object Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-39474
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
Post Duplicator [post-duplicator]
Researcher
Nguyen Ba Khanh
More Details >
Product Filter for WooCommerce by WBW < 3.1.3 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-3830
Patch Status
Patched
Published
Apr 14, 2026
Affected Software
Product Filter for WooCommerce by WBW [woo-product-filter]
Researcher
Drew Webber (mcdruid)
More Details >
Product Filter for WooCommerce by WBW <= 3.1.2 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-39494
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
Product Filter for WooCommerce by WBW [woo-product-filter]
Researcher
daroo
More Details >
Riaxe Product Customizer <= 2.1.2 - Unauthenticated SQL Injection via 'options' Parameter Keys in product_data
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-3599
Patch Status
Unpatched
Published
Apr 15, 2026
Affected Software
Riaxe Product Customizer [riaxe-product-customizer]
Researcher
Kai Aizen
More Details >
SpeakOut! Email Petitions <= 4.6.5 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-39530
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
SpeakOut! Email Petitions [speakout]
Researcher
Nguyen Ba Khanh
More Details >
Unlimited Elements For Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File Read via Path Traversal in Repeater JSON/CSV URL with Path Traversal
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-4659
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Unlimited Elements For Elementor [unlimited-elements-for-elementor]
Researcher
Dmitrii Ignatyev
More Details >
WP Directory Kit <= 1.5.0 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-39531
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
WP Directory Kit [wpdirectorykit]
Researcher
Martín Martín
More Details >
WP Photo Album Plus <= 9.1.08.001 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-39511
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
WP Photo Album Plus [wp-photo-album-plus]
Researcher
Martín Martín
More Details >
Accessibly <= 3.0.3 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via Widget Source Injection via REST API
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-3643
Patch Status
Unpatched
Published
Apr 14, 2026
Affected Software
Accessibly – WordPress Website Accessibility [otm-accessibly]
Researchers
chaeypRonnachai Sretawat Na Ayutaya (Simonhaskelly)Ronnachai Chaipha (rxnr)
More Details >
Age Verification & Identity Verification by Token of Trust <= 3.32.3 - Unauthenticated Stored Cross-Site Scripting via 'description' Parameter
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-2834
Patch Status
Patched
Published
Apr 14, 2026
Affected Software
Age Verification & Identity Verification by Token of Trust [token-of-trust]
Researcher
Teerachai Somprasong
More Details >
BackWPup <= 5.6.6 - Authenticated (Administrator+) Local File Inclusion via 'block_name' Parameter
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-6227
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
BackWPup – WordPress Backup & Restore Plugin [backwpup]
Researcher
Pixel_DefaultBR
More Details >
Form Maker by 10Web <= 1.15.40 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Text Box
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-4388
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker]
Researcher
Naoya Takahashi (nakko)
More Details >
ManageWP Worker <= 4.9.31 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-39463
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
ManageWP Worker [worker]
Researcher
Steven Julian
More Details >
Prismatic <= 3.7.3 - Unauthenticated Stored Cross-Site Scripting via 'prismatic_encoded' Pseudo-Shortcode
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-3876
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
Prismatic [prismatic]
Researcher
Athiwat Tiprasaharn (Jitlada)
More Details >
Quick Interest Slider <= 3.1.5 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-5694
Patch Status
Unpatched
Published
Apr 14, 2026
Affected Software
Quick Interest Slider [quick-interest-slider]
Researcher
Chawabhon Netisingha (JNX03)
More Details >
Royal Elementor Addons Pro < 1.7.1041 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-40720
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Royal Elementor Addons Pro [wpr-addons-pro]
Researcher
Drew Webber (mcdruid)
More Details >
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authenticated (Administrator+) PHP Object Injection
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-3017
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts [post-carousel]
Researcher
Vilaysone CHANTHAVONG (0xJ0cKkY)
More Details >
Social Slider Feed <= 2.3.2 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-39507
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Social Slider Feed [instagram-slider-widget]
Researcher
Nguyen Ba Khanh
More Details >
WP Statistics <= 14.16.4 - Unauthenticated Stored Cross-Site Scripting via 'utm_source' Parameter
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-5231
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics]
Researcher
daroo
More Details >
Accessibility Suite by Ability, Inc <= 4.20 - Authenticated (Subscriber+) SQL Injection via 'scan_id' Parameter
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-3773
Patch Status
Unpatched
Published
Apr 15, 2026
Affected Software
Accessibility Suite by Ability, Inc [online-accessibility]
Researcher
Victor Pasman
More Details >
Client Portal (Pro) <= 5.6.2 - Authenticated (CP Client+) Arbitrary File Download
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-40724
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Client Portal Pro [leco-client-portal]
Researcher
Jarno Vos (jarnovos)
More Details >
Eleganzo <= 1.2 - Authenticated (Subscriber+) Arbitrary Directory Deletion
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2025-15470
Patch Status
Patched
Published
Apr 14, 2026
Affected Software
Eleganzo [eleganzo]
Researcher
Phat RiO
More Details >
Germanized for WooCommerce <= 3.20.5 - Unauthenticated Arbitrary Shortcode Execution
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-2582
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
Germanized for WooCommerce [woocommerce-germanized]
Researcher
Chiao-Lin Yu (Steven Meow)
More Details >
MasterStudy LMS <= 3.7.25 - Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' Parameters
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-4817
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system]
Researcher
Naoya Takahashi (nakko)
More Details >
Tutor LMS <= 3.9.8 - Authenticated (Admin+) SQL Injection via 'date' Parameter
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-6080
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Tutor LMS – eLearning and online course solution [tutor]
Researcher
PRISM
More Details >
WCFM Marketplace – Multivendor Marketplace for WooCommerce <= 3.7.1 - Authenticated (Store vendor+) SQL Injection
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2025-63029
Patch Status
Unpatched
Published
Apr 15, 2026
Affected Software
WCFM Marketplace – Multivendor Marketplace for WooCommerce [wc-multivendor-marketplace]
Researcher
Martino Spagnuolo
More Details >
WP Statistics <= 14.16.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure and Privacy Audit Manipulation
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-3488
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics]
Researcher
Jack Pas (Dark.)
More Details >
wpForo Forum <= 2.4.16 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Forum Post Modification via 'guestposting' Parameter
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-4666
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
wpForo Forum [wpforo]
Researcher
Jared Reyes
More Details >
BetterDocs <= 4.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-3875
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor [betterdocs]
Researcher
Muhammad Yudha - DJ
More Details >
Coachific Shortcode <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'userhash' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-4005
Patch Status
Unpatched
Published
Apr 14, 2026
Affected Software
Coachific Shortcode [coachific-shortcode]
Researcher
zakaria
More Details >
Content Blocks (Custom Post Widget) <= 3.3.9 - Authenticated (Author+) Stored Cross-Site Scripting via content_block Shortcode
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-0894
Patch Status
Patched
Published
Apr 17, 2026
Affected Software
Content Blocks (Custom Post Widget) [custom-post-widget]
Researcher
Muhammad Yudha - DJ
More Details >
Contextual Related Posts <= 4.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'other_attributes'
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-2986
Patch Status
Patched
Published
Apr 17, 2026
Affected Software
Contextual Related Posts [contextual-related-posts]
Researchers
Athiwat Tiprasaharn (Jitlada)Itthidej Aramsri (Boeing777)
More Details >
Email Encoder – Protect Email Addresses and Phone Numbers <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via eeb_mailto Shortcode
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-2840
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
Email Encoder – Protect Email Addresses and Phone Numbers [email-encoder-bundle]
Researcher
Athiwat Tiprasaharn (Jitlada)
More Details >
EMC Scheduling Manager <= 4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via calendly Shortcode
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-0868
Patch Status
Patched
Published
Apr 18, 2026
Affected Software
EMC – Easily Embed Calendly Scheduling [embed-calendly-scheduling]
Researcher
Muhammad Yudha - DJ
More Details >
Flipbox Addon for Elementor <= 2.1.1 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Attributes
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-6048
Patch Status
Patched
Published
Apr 17, 2026
Affected Software
Flipbox Addon for Elementor [ultimate-flipbox-addon-for-elementor]
Researchers
Athiwat Tiprasaharn (Jitlada)Itthidej Aramsri (Boeing777)
More Details >
Jupiter X Core <= 4.14.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-39491
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
Jupiter X Core [jupiterx-core]
Researcher
Nguyen Ba Khanh
More Details >
Livemesh Addons by Elementor <= 9.0 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via Plugin Settings
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-1572
Patch Status
Unpatched
Published
Apr 15, 2026
Affected Software
Livemesh Addons by Elementor [addons-for-elementor]
Researcher
Muhammad Yudha - DJ
More Details >
Mini Ajax Cart for WooCommerce <= 1.3.4 - Authenticated (Author+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-6370
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
Mini Ajax Cart for WooCommerce [mini-ajax-woo-cart]
Researcher
Ali Osman ERBAS (0110m4n)
More Details >
Page Builder Gutenberg Blocks <= 3.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via External iCal Feed Data
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-4801
Patch Status
Patched
Published
Apr 17, 2026
Affected Software
Page Builder Gutenberg Blocks – CoBlocks [coblocks]
Researcher
Fernando Mecozzi
More Details >
Power Charts <= 0.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-4011
Patch Status
Unpatched
Published
Apr 14, 2026
Affected Software
Power Charts – Responsive Beautiful Charts & Graphs [wpgo-power-charts-lite]
Researcher
Muhammad Yudha - DJ
More Details >
Pz-LinkCard <= 2.5.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-2434
Patch Status
Unpatched
Published
Apr 17, 2026
Affected Software
Pz-LinkCard [pz-linkcard]
Researcher
Muhammad Yudha - DJ
More Details >
Royal Addons for Elementor <= 1.7.1056 - Authenticated (Contributor+) Stored Cross-Site Scripting via Instagram Feed Widget
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-5162
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons]
Researcher
Caspian
More Details >
Shipment Tracker for Woocommerce <= 1.5.3.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-39540
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Shipment Tracker for Woocommerce [shipment-tracker-for-woocommerce]
Researcher
Nguyen Ba Khanh
More Details >
ShopLentor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-4059
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin [woolentor-addons]
Researcher
zaim
More Details >
Surbma | Booking.com <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-1607
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
Surbma | Booking.com Shortcode [surbma-bookingcom-shortcode]
Researcher
zakaria
More Details >
Vantage <= 1.20.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Block Text Content
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-5070
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
Vantage [vantage]
Researcher
Osvaldo Noe Gonzalez Del Rio (Os)
More Details >
VI: Include Post By <= 0.4.200706 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_container' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-5717
Patch Status
Unpatched
Published
Apr 14, 2026
Affected Software
VI: Include Post By [vi-include-post-by]
Researcher
MAJidox
More Details >
Video Gallery – YouTube Gallery & Responsive Video Playlist <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2025-15636
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
Video Gallery – YouTube Gallery & Responsive Video Playlist [youtube-showcase]
Researcher
Muhammad Yudha - DJ
More Details >
WM JqMath <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-3998
Patch Status
Unpatched
Published
Apr 14, 2026
Affected Software
WM JqMath [wm-jqmath]
Researcher
Gilang - DJ
More Details >
WP Circliful <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-3659
Patch Status
Unpatched
Published
Apr 14, 2026
Affected Software
WP Circliful [wp-circliful]
Researcher
Gilang - DJ
More Details >
WP Docs <= 2.2.9 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wpdocs_options[icon_size]'
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-3878
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
WP Docs [wp-docs]
Researcher
Nabil Irawan
More Details >
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'put_wpgm' Shortcode
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2025-13364
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin]
Researcher
Muhammad Yudha - DJ
More Details >
WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_box Shortcode
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-3885
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate]
Researcher
Dmitrii Ignatyev
More Details >
WP YouTube Lyte <= 1.7.29 - Authenticated (Contributor+) Stored Cross-Site Scripting via lyte Shortcode
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-3299
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
WP YouTube Lyte [wp-youtube-lyte]
Researcher
Muhammad Yudha - DJ
More Details >
Youzify <= 1.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'checkin_place_id' Parameter
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-1559
Patch Status
Patched
Published
Apr 17, 2026
Affected Software
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress [youzify]
Researcher
Tharadol Suksamran (d3kc4rt_1)
More Details >
CodeColorer <= 0.10.1 - Unauthenticated Stored Cross-Site Scripting via 'class' attribute in 'cc' Comment Shortcode
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-4032
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
CodeColorer [codecolorer]
Researcher
Chawabhon Netisingha (JNX03)
More Details >
Customer Reviews for WooCommerce <= 5.101.0 - Reflected Cross-Site Scripting via 'crsearch'
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-3355
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
Customer Reviews for WooCommerce [customer-reviews-woocommerce]
Researchers
Athiwat Tiprasaharn (Jitlada)Itthidej Aramsri (Boeing777)
More Details >
Hostel <= 1.1.6 - Reflected Cross-Site Scripting via 'shortcode_id' Parameter
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-1838
Patch Status
Patched
Published
Apr 17, 2026
Affected Software
Hostel [hostel]
Researcher
Bee
More Details >
MagOne <= 9.0 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-39548
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
magone [magone]
Researcher
João Pedro Soares de Alcântara
More Details >
OPEN-BRAIN <= 0.5.0 - Cross-Site Request Forgery
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-4091
Patch Status
Unpatched
Published
Apr 14, 2026
Affected Software
OPEN-BRAIN [open-brain]
Researcher
Muhammad Nur Ibnu Hubab (Ibnu)
More Details >
Product Pricing Table by WooBeWoo <= 1.1.0 - Cross-Site Request Forgery to Stored XSS and Pricing Table Deletion
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-1852
Patch Status
Patched
Published
Apr 14, 2026
Affected Software
Product Pricing Table by WooBeWoo [woo-product-pricing-tables]
Researcher
Muhammad Nur Ibnu Hubab (Ibnu)
More Details >
User Registration & Membership <= 5.1.4 - Unauthenticated Open Redirect via 'redirect_to_on_logout' Parameter
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-6203
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder [user-registration]
Researchers
Anthony Cihan (Hann1bl3L3ct3r)Louis Deschanel (JeanJeanLeHaxor)Pascal SUN
More Details >
WPZOOM Addons for Elementor – Starter Templates & Widgets <= 1.3.4 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-39597
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
WPZOOM Addons for Elementor – Starter Templates & Widgets [wpzoom-elementor-addons]
Researcher
Nguyen Ba Khanh
More Details >
Avada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Limited Arbitrary WordPress Action Execution
5.4
CVSS Rating
5.4 (Medium)
CVE-ID
CVE-2026-1509
Patch Status
Patched
Published
Apr 14, 2026
Affected Software
Avada (Fusion) Builder [fusion-builder]
Researcher
Webbernaut
More Details >
Better Find and Replace – AI-Powered Suggestions <= 1.7.9 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Title
5.4
CVSS Rating
5.4 (Medium)
CVE-ID
CVE-2026-3369
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
Better Find and Replace – AI-Powered Suggestions [real-time-auto-find-and-replace]
Researcher
kai63001
More Details >
Categories Images <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'z_taxonomy_image' Shortcode
5.4
CVSS Rating
5.4 (Medium)
CVE-ID
CVE-2026-2505
Patch Status
Patched
Published
Apr 17, 2026
Affected Software
Categories Images [categories-images]
Researchers
Athiwat Tiprasaharn (Jitlada)Tharadol Suksamran (d3kc4rt_1)
More Details >
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.17 - Missing Authorization to Unauthenticated Private/Draft Flipbook Data Exposure
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-1314
Patch Status
Patched
Published
Apr 14, 2026
Affected Software
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine]
Researcher
Kai Aizen
More Details >
Accept Cryptocurrencies with Plisio <= 2.0.6 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-6372
Patch Status
Unpatched
Published
Apr 15, 2026
Affected Software
Accept Cryptocurrencies with Plisio [plisio-payment-gateway-for-woocommerce]
Researcher
AXIS
More Details >
Advanced Custom Fields (ACF®) <= 6.7.0 - Unauthenticated Missing Authorization to Arbitrary Post/Page Disclosure via AJAX Field Query Parameters
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-4812
Patch Status
Patched
Published
Apr 14, 2026
Affected Software
Advanced Custom Fields (ACF®) [advanced-custom-fields]
Researcher
Fernando Mecozzi
More Details >
Basic Google Maps Placemarks <= 1.10.7 - Missing Authorization to Unauthenticated Default Map Coordinate Update
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-3581
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
Basic Google Maps Placemarks [basic-google-maps-placemarks]
Researcher
Chawabhon Netisingha (JNX03)
More Details >
Booking Activities <= 1.16.48.1 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-39525
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
Booking Activities [booking-activities]
Researcher
Nguyen Ba Khanh
More Details >
e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Form Settings Modification via AJAX
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-3642
Patch Status
Unpatched
Published
Apr 14, 2026
Affected Software
e-shot [e-shot-form-builder]
Researcher
Poli
More Details >
Easy Appointments <= 3.12.21 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-39513
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
Easy Appointments [easy-appointments]
Researcher
Martín Martín
More Details >
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-4160
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform]
Researcher
Prickly Cactus
More Details >
HAPPY – Helpdesk Support Ticket System <= 1.0.10 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-39593
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
HAPPY – Helpdesk Support Ticket System [happy-helpdesk-support-ticket-system]
Researcher
Nabil Irawan
More Details >
Katalogportal-pdf-sync Widget <= 1.0.0 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure via 'katalogportal_shortcodePrinter' AJAX Action
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-3649
Patch Status
Unpatched
Published
Apr 14, 2026
Affected Software
Katalogportal-pdf-sync Widget [katalogportal-pdf-sync]
Researcher
Poli
More Details >
Kubio AI Page Builder <= 2.7.2 - Missing Authorization to Authenticated (Contributor+) Limited File Upload via Kubio Block Attributes
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-5427
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Kubio AI Page Builder [kubio]
Researcher
oolongeya
More Details >
LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-5234
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
LatePoint – Calendar Booking Plugin for Appointments and Events [latepoint]
Researcher
darkmode
More Details >
MetForm Pro <= 3.9.7 - Unauthenticated Payment Amount Manipulation via 'mf-calculation'
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-1782
Patch Status
Patched
Published
Apr 14, 2026
Affected Software
MetForm Pro [metform-pro]
Researcher
andrea bocchetti
More Details >
Nexi XPay <= 8.3.0 - Missing Authorization to Unauthenticated Order Status Modification
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2025-15565
Patch Status
Patched
Published
Apr 14, 2026
Affected Software
Nexi XPay [cartasi-x-pay]
Researcher
Md. Moniruzzaman Prodhan (NomanProdhan)
More Details >
Payment Gateway for Redsys & WooCommerce Lite <= 7.0.0 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-40741
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Payment Gateway for Redsys & WooCommerce Lite [woo-redsys-gateway-light]
Researcher
Nguyen Ba Khanh
More Details >
Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.5 - Missing Authorization to Limited Post Meta Modification
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-0718
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX [ultimate-post]
Researcher
Mohammad Amin Hajian (mamadrce)
More Details >
Quiz and Survey Master (QSM) <= 11.1.0 - Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-5797
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker [quiz-master-next]
Researcher
Rafshanzani Suhada
More Details >
Riaxe Product Customizer <= 2.1.2 - Unauthenticated Arbitrary User Deletion via 'user_id' Parameter
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-3595
Patch Status
Unpatched
Published
Apr 15, 2026
Affected Software
Riaxe Product Customizer [riaxe-product-customizer]
Researcher
Kai Aizen
More Details >
Tutor LMS <= 3.9.8 - Authenticated (Subscriber+) Arbitrary Course Content Manipulation via tutor_update_course_content_order
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-5502
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Tutor LMS – eLearning and online course solution [tutor]
Researcher
momopon1415
More Details >
User Registration Stripe <= 1.3.14 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-40726
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
User Registration Stripe [user-registration-stripe]
Researcher
0xd4rk5id3
More Details >
Form Maker by 10Web <= 1.15.40 - Authenticated (Administrator+) SQL Injection via 'ip_search' Parameter
4.9
CVSS Rating
4.9 (Medium)
CVE-ID
CVE-2026-3330
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker]
Researcher
Sein Linn
More Details >
JetBackup <= 3.1.19.8 - Authenticated (Administrator+) Arbitrary Directory Deletion via Path Traversal in 'fileName' Parameter
4.9
CVSS Rating
4.9 (Medium)
CVE-ID
CVE-2026-4853
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
JetBackup – Backup, Restore & Migrate [backup]
Researcher
lucsob
More Details >
Custom New User Notification <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'User Mail Subject' Setting
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-3551
Patch Status
Unpatched
Published
Apr 15, 2026
Affected Software
Custom New User Notification [custom-new-user-notification]
Researcher
Muhammad Nur Ibnu Hubab (Ibnu)
More Details >
List View Google Calendar <= 7.4.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via Event Description
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-2396
Patch Status
Patched
Published
Apr 14, 2026
Affected Software
List View Google Calendar [list-view-google-calendar]
Researcher
Pattama Tangpoonponwiwat (Kwan)
More Details >
OPEN-BRAIN <= 0.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'API Key' Setting
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-3995
Patch Status
Unpatched
Published
Apr 15, 2026
Affected Software
OPEN-BRAIN [open-brain]
Researcher
Muhammad Nur Ibnu Hubab (Ibnu)
More Details >
VideoZen <= 1.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'VideoZen available subtitles languages' Field
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-6439
Patch Status
Unpatched
Published
Apr 16, 2026
Affected Software
VideoZen [videozen]
Researcher
Muhammad Nur Ibnu Hubab (Ibnu)
More Details >
WholeSale Products Dynamic Pricing Management WooCommerce <= 1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-4479
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
WholeSale Products Dynamic Pricing Management WooCommerce [wholesale-products-dynamic-pricing-management-woocommerce]
Researcher
Muhammad Nur Ibnu Hubab (Ibnu)
More Details >
Avada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Sensitive Information Exposure via Insecure Direct Object Reference
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-1541
Patch Status
Patched
Published
Apr 14, 2026
Affected Software
Avada (Fusion) Builder [fusion-builder]
Researcher
Webbernaut
More Details >
Canto <= 3.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Setting Modification
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-6441
Patch Status
Unpatched
Published
Apr 16, 2026
Affected Software
Canto [canto]
Researcher
Legion Hunter
More Details >
CMS für Motorrad Werkstätten <= 1.0.0 - Cross-Site Request Forgery
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-6451
Patch Status
Unpatched
Published
Apr 16, 2026
Affected Software
Plugin: CMS für Motorrad Werkstätten [cms-fuer-motorrad-werkstaetten]
Researcher
Régis SENET
More Details >
Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) <= 4.1.8 Missing Authorization to Authenticated (Subscriber+) Order Information Exposure
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-4109
Patch Status
Patched
Published
Apr 13, 2026
Affected Software
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) [wp-event-solution]
Researcher
Supakiad S. (m3ez)
More Details >
FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration <= 1.91.2 - Authenticated (Board Member+) Insecure Direct Object Reference
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-40784
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration [fluent-boards]
Researcher
Jakub Herman
More Details >
Inquiry form to posts or pages <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'inq_header' Parameter
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-6293
Patch Status
Unpatched
Published
Apr 14, 2026
Affected Software
Inquiry form to posts or pages [inquiry-form-to-posts-or-pages]
Researcher
Muhammad Nur Ibnu Hubab (Ibnu)
More Details >
MyRewards <= 5.7.3 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-40786
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
MyRewards [woorewards]
Researcher
Muhan Luo
More Details >
Petje.af <= 2.1.8 - Cross-Site Request Forgery to Account Deletion via 'petjeaf_disconnect' AJAX Action
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-4002
Patch Status
Unpatched
Published
Apr 14, 2026
Affected Software
Petje.af [petje-af]
Researcher
theviper17y
More Details >
ProfilePress <= 4.16.12 - Missing Authorization to Authenticated (Subscriber+) Inactive Membership Plan Subscription
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-4949
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress [wp-user-avatar]
Researcher
Supakiad S. (m3ez)
More Details >
Smart Online Order for Clover <= 1.6.0 - Cross-Site Request Forgery
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2025-15635
Patch Status
Unpatched
Published
Apr 15, 2026
Affected Software
Smart Online Order for Clover [clover-online-orders]
Researcher
Kévin Mosbahi (Mika)
More Details >
Ultra Addons for WPForms <= 1.0.11 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-39594
Patch Status
Patched
Published
Apr 16, 2026
Affected Software
Ultra Addons for WPForms [ultra-addons-for-wpforms]
Researcher
Sandeep V
More Details >
UserPro - Community and User Profile WordPress Plugin < 5.1.11 - Cross-Site Request Forgery
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2025-53444
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
UserPro - Community and User Profile WordPress Plugin [userpro]
Researcher
Ananda Dhakal
More Details >
OneSignal – Web Push Notifications <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Post Meta Deletion via 'post_id'
3.1
CVSS Rating
3.1 (Low)
CVE-ID
CVE-2026-3155
Patch Status
Patched
Published
Apr 15, 2026
Affected Software
OneSignal – Web Push Notifications [onesignal-free-web-push-notifications]
Researcher
Muhammad Sharief
More Details >
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (April 13, 2026 to April 19, 2026) appeared first on Wordfence.
Quelle: www.wordfence.com