Wordfence Intelligence Weekly WordPress Vulnerability Report (April 13, 2026 to April 19, 2026)

⚠️ CVE-Referenzen: CVE-2026-3596 CVE-2026-39540 CVE-2026-3649 CVE-2026-1541 CVE-2026-6372 CVE-2026-40724 CVE-2026-40725 CVE-2026-3464 CVE-2026-6080 CVE-2026-6203 CVE-2026-39594 CVE-2026-4666 CVE-2026-40735 CVE-2025-15635 CVE-2026-4005 CVE-2026-4091 CVE-2026-1782 CVE-2026-4388 CVE-2026-0718 CVE-2026-3642 CVE-2026-39494 CVE-2026-5718 CVE-2026-3369 CVE-2026-5502 CVE-2026-1559 CVE-2025-15441 CVE-2026-39512 CVE-2026-4109 CVE-2026-6048 CVE-2026-3299 CVE-2026-6439 CVE-2026-2840 CVE-2026-39593 CVE-2026-40784 CVE-2026-5234 CVE-2026-5231 CVE-2026-39598 CVE-2026-39468 CVE-2026-2986 CVE-2026-5710 CVE-2026-3878 CVE-2026-3155 CVE-2026-2505 CVE-2026-40733 CVE-2026-40720 CVE-2026-40727 CVE-2026-3830 CVE-2026-3330 CVE-2025-15565 CVE-2026-5717 CVE-2026-39527 CVE-2026-6293 CVE-2026-40786 CVE-2026-1572 CVE-2026-2834 CVE-2026-40726 CVE-2026-4479 CVE-2026-40739 CVE-2026-3489 CVE-2026-4059 CVE-2026-39531 CVE-2026-1838 CVE-2026-3876 CVE-2026-3875 CVE-2026-1607 CVE-2026-4812 CVE-2025-15470 CVE-2026-3659 CVE-2026-4352 CVE-2026-3595 CVE-2026-6441 CVE-2026-5797 CVE-2026-5427 CVE-2026-1620 CVE-2026-4853 CVE-2026-3581 CVE-2025-63029 CVE-2026-3885 CVE-2026-2582 CVE-2026-3017 CVE-2026-0894 CVE-2026-1852 CVE-2026-3995 CVE-2026-5694 CVE-2026-2262 CVE-2026-6370 CVE-2026-6451 CVE-2026-39513 CVE-2026-5162 CVE-2026-40731 CVE-2025-15636 CVE-2026-6518 CVE-2026-4817 CVE-2026-4365 CVE-2026-40738 CVE-2026-1314 CVE-2026-39597 CVE-2026-2434 CVE-2026-4011 CVE-2026-3773 CVE-2026-4801 CVE-2026-40736 CVE-2025-14868 CVE-2026-39548 CVE-2026-5070 CVE-2026-1509 CVE-2026-39463 CVE-2026-40741 CVE-2025-13364 CVE-2026-4002 CVE-2026-39579 CVE-2026-39491 CVE-2026-39511 CVE-2026-39474 CVE-2026-4032 CVE-2026-3488 CVE-2026-3551 CVE-2026-3998 CVE-2026-4659 CVE-2026-5617 CVE-2026-39530 CVE-2026-1555 CVE-2026-3599 CVE-2026-2396 CVE-2026-0868 CVE-2026-3355 CVE-2026-4160 CVE-2026-4949 CVE-2026-39507 CVE-2026-39532 CVE-2026-3461 CVE-2026-39525 CVE-2025-53444 CVE-2026-4880 CVE-2026-5050 CVE-2026-3643 CVE-2026-6227 CVE-2026-3614
Last week, there were 139 vulnerabilities disclosed in 116 WordPress Plugins and 10 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 84 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back. Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 33,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free. Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. Total Unpatched & Patched Vulnerabilities Last Week Patch Status Number of Vulnerabilities Patched 109 Unpatched 30 Total Vulnerabilities by CVSS Severity Last Week Severity Rating Number of Vulnerabilities Low Severity 1 Medium Severity 86 High Severity 46 Critical Severity 6 Total Vulnerabilities by CWE Type Last Week Vulnerability Type by CWE Number of Vulnerabilities Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 48 Missing Authorization 27 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 15 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 10 Deserialization of Untrusted Data 9 Cross-Site Request Forgery (CSRF) 7 Authorization Bypass Through User-Controlled Key 5 Unrestricted Upload of File with Dangerous Type 5 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 2 Improper Control of Generation of Code ('Code Injection') 2 Authentication Bypass Using an Alternate Path or Channel 1 Embedded Malicious Code 1 Exposure of Sensitive Information to an Unauthorized Actor 1 Improper Input Validation 1 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1 Improper Privilege Management 1 Improper Verification of Cryptographic Signature 1 Incorrect Privilege Assignment 1 URL Redirection to Untrusted Site ('Open Redirect') 1 Researchers That Contributed to WordPress Security Last Week Researcher Name Number of Vulnerabilities Nguyen Ba Khanh 9 Muhammad Yudha - DJ 9 Muhammad Nur Ibnu Hubab (Ibnu) 7 Athiwat Tiprasaharn (Jitlada) 6 Denver Jackson 5 Kai Aizen 4 daroo 4 Supakiad S. (m3ez) 3 Webbernaut 3 Chawabhon Netisingha (JNX03) 3 0xd4rk5id3 3 Itthidej Aramsri (Boeing777) 3 Martín Martín 3 zakaria 2 Gilang - DJ 2 Osvaldo Noe Gonzalez Del Rio (Os) 2 Drew Webber (mcdruid) 2 Naoya Takahashi (nakko) 2 Leonid Semenenko (lsemenenko) 2 Tharadol Suksamran (d3kc4rt_1) 2 Nabil Irawan 2 Fernando Mecozzi 2 Poli 2 João Pedro Soares de Alcântara 2 Chiao-Lin Yu (Steven Meow) 2 Dmitrii Ignatyev 2 Anthony Cihan (Hann1bl3L3ct3r) 1 Louis Deschanel (JeanJeanLeHaxor) 1 Pascal SUN 1 Jared Reyes 1 Pixel_DefaultBR 1 Jakub Herman 1 Prickly Cactus 1 Caspian 1 Ananda Dhakal 1 theviper17y 1 h0xilo 1 Bee 1 Teerachai Somprasong 1 Martino Spagnuolo 1 Sandeep V 1 luc 1 Vilaysone CHANTHAVONG (0xJ0cKkY) 1 hiariz 1 kai63001 1 lucsob 1 Muhammad Sharief 1 Sein Linn 1 Régis SENET 1 PRISM 1 Phat RiO 1 Nguyen Ngoc Duc (duc193) 1 Ivan Cese 1 Abu Hurayra (HurayraIIT) 1 Muhan Luo 1 Kévin Mosbahi (Mika) 1 Ali Osman ERBAS (0110m4n) 1 andrea bocchetti 1 Tin Pham aka TF1T 1 Ren Voza 1 shark3y 1 darkmode 1 Jack Pas (Dark.) 1 MAJidox 1 Victor Pasman 1 Steven Julian 1 BaroHaf 1 Legion Hunter 1 Pattama Tangpoonponwiwat (Kwan) 1 Mohammad Amin Hajian (mamadrce) 1 Jarno Vos (jarnovos) 1 Muhammad Sharief (Md Sharief) 1 ll 1 oolongeya 1 MD. TAREQ AHAMED JONY (itztrq) 1 Rafshanzani Suhada 1 momopon1415 1 Md. Moniruzzaman Prodhan (NomanProdhan) 1 Phat RiO 1 AXIS 1 chaeyp 1 Ronnachai Sretawat Na Ayutaya (Simonhaskelly) 1 Ronnachai Chaipha (rxnr) 1 zaim 1 Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report. WordPress Plugins with Reported Vulnerabilities Last Week Software Name Software Slug 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery interactive-3d-flipbook-powered-physics-engine Academy LMS Pro academy-pro Accept Cryptocurrencies with Plisio plisio-payment-gateway-for-woocommerce Accessibility Suite by Ability, Inc online-accessibility Accessibly – WordPress Website Accessibility otm-accessibly AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress acymailing Advanced Custom Fields (ACF®) advanced-custom-fields Age Verification & Identity Verification by Token of Trust token-of-trust Avada (Fusion) Builder fusion-builder BackWPup – WordPress Backup & Restore Plugin backwpup Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Basic Google Maps Placemarks basic-google-maps-placemarks bBlocks – Essential Gutenberg Blocks & Patterns Collection b-blocks Better Find and Replace – AI-Powered Suggestions real-time-auto-find-and-replace BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor betterdocs Booking Activities booking-activities Canto canto Career Section career-section Categories Images categories-images Client Portal Pro leco-client-portal CMP – Coming Soon & Maintenance Plugin by NiteoThemes cmp-coming-soon-maintenance Coachific Shortcode coachific-shortcode CodeColorer codecolorer Content Blocks (Custom Post Widget) custom-post-widget Contextual Related Posts contextual-related-posts Custom New User Notification custom-new-user-notification Customer Reviews for WooCommerce customer-reviews-woocommerce DirectoryPress – Business Directory And Classified Ad Listing directorypress Drag and Drop Multiple File Upload for Contact Form 7 drag-and-drop-multiple-file-upload-contact-form-7 e-shot e-shot-form-builder Easy Appointments easy-appointments Email Encoder – Protect Email Addresses and Phone Numbers email-encoder-bundle EMC – Easily Embed Calendly Scheduling embed-calendly-scheduling Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) wp-event-solution Events Calendar for GeoDirectory events-for-geodirectory Flipbox Addon for Elementor ultimate-flipbox-addon-for-elementor Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder fluentform FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration fluent-boards Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder form-maker GeoDirectory – WP Business Directory Plugin and Classified Listings Directory geodirectory Germanized for WooCommerce woocommerce-germanized Groundhogg — CRM, Newsletters, and Marketing Automation groundhogg HAPPY – Helpdesk Support Ticket System happy-helpdesk-support-ticket-system Hostel hostel Inquiry form to posts or pages inquiry-form-to-posts-or-pages JetBackup – Backup, Restore & Migrate backup JetEngine jet-engine Jupiter X Core jupiterx-core Katalogportal-pdf-sync Widget katalogportal-pdf-sync Kubio AI Page Builder kubio LatePoint – Calendar Booking Plugin for Appointments and Events latepoint LearnPress – WordPress LMS Plugin for Create and Sell Online Courses learnpress List View Google Calendar list-view-google-calendar Livemesh Addons by Elementor addons-for-elementor Login as User – Switch User & WooCommerce Login as Customer one-click-login-as-user ManageWP Worker worker MasterStudy LMS WordPress Plugin – for Online Courses and Education masterstudy-lms-learning-management-system Meta Box meta-box MetForm Pro metform-pro Mini Ajax Cart for WooCommerce mini-ajax-woo-cart MyRewards woorewards Nexi XPay cartasi-x-pay OneSignal – Web Push Notifications onesignal-free-web-push-notifications OPEN-BRAIN open-brain Page Builder Gutenberg Blocks – CoBlocks coblocks Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress wp-user-avatar Payment Gateway for Redsys & WooCommerce Lite woo-redsys-gateway-light Petje.af petje-af Plugin: CMS für Motorrad Werkstätten cms-fuer-motorrad-werkstaetten Post Duplicator post-duplicator Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX ultimate-post Power Charts – Responsive Beautiful Charts & Graphs wpgo-power-charts-lite Prismatic prismatic Product Filter for WooCommerce by WBW woo-product-filter Product Pricing Table by WooBeWoo woo-product-pricing-tables Pz-LinkCard pz-linkcard Quick Interest Slider quick-interest-slider Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker quiz-master-next Riaxe Product Customizer riaxe-product-customizer Royal Addons for Elementor – Addons and Templates Kit for Elementor royal-elementor-addons Royal Elementor Addons Pro wpr-addons-pro Shipment Tracker for Woocommerce shipment-tracker-for-woocommerce ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin woolentor-addons Smart Online Order for Clover clover-online-orders Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts post-carousel Social Slider Feed instagram-slider-widget SpeakOut! Email Petitions speakout Surbma | Booking.com Shortcode surbma-bookingcom-shortcode Tutor LMS – eLearning and online course solution tutor Ultra Addons for WPForms ultra-addons-for-wpforms Unlimited Elements For Elementor unlimited-elements-for-elementor User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder user-registration User Registration Stripe user-registration-stripe UserPro - Community and User Profile WordPress Plugin userpro VI: Include Post By vi-include-post-by Video Gallery – YouTube Gallery & Responsive Video Playlist youtube-showcase VideoZen videozen Visa Acceptance Solutions visa-acceptance-solutions WCFM Marketplace – Multivendor Marketplace for WooCommerce wc-multivendor-marketplace WholeSale Products Dynamic Pricing Management WooCommerce wholesale-products-dynamic-pricing-management-woocommerce WM JqMath wm-jqmath WooCommerce Product Filters woocommerce-product-filters WowShipping Pro table-rate-shipping-pro WP Circliful wp-circliful WP Customer Area customer-area WP Directory Kit wpdirectorykit WP Docs wp-docs WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters wp-google-map-plugin WP Photo Album Plus wp-photo-album-plus WP Shortcodes Plugin — Shortcodes Ultimate shortcodes-ultimate WP Statistics – Simple, privacy-friendly Google Analytics alternative wp-statistics WP YouTube Lyte wp-youtube-lyte wpForo Forum wpforo WpStream – Live Streaming, Video on Demand, Pay Per View wpstream WPZOOM Addons for Elementor – Starter Templates & Widgets wpzoom-elementor-addons Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress youzify WordPress Themes with Reported Vulnerabilities Last Week Software Name Software Slug ChapterOne - Bookstore and Publisher WordPress Theme chapterone Eldon - Artist Portfolio WordPress Theme eldon Eleganzo eleganzo Laurits - Portfolio and Agency WordPress Theme laurits LuxeDrive - Limousine and Car Rental WordPress Theme luxedrive magone magone Reina - Spa and Wellness WordPress Theme reina ShiftUp - Car Repair & Auto Services WordPress Theme shiftup Vantage vantage WebStack webstack Vulnerability Details Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize. Barcode Scanner (+Mobile App) <= 1.11.0 - Unauthenticated Privilege Escalation via Insecure Token Authentication 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-4880 Patch Status Patched Published Apr 15, 2026 Affected Software Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] Researcher 0xd4rk5id3 More Details > Riaxe Product Customizer <= 2.1.2 - Missing Authorization to Unauthenticated Arbitrary Options Update to Privilege Escalation via 'install-imprint' AJAX Action 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-3596 Patch Status Unpatched Published Apr 15, 2026 Affected Software Riaxe Product Customizer [riaxe-product-customizer] Researcher Kai Aizen More Details > Visa Acceptance Solutions <= 2.1.0 - Unauthenticated Authentication Bypass via Billing Email 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-3461 Patch Status Unpatched Published Apr 14, 2026 Affected Software Visa Acceptance Solutions [visa-acceptance-solutions] Researcher 0xd4rk5id3 More Details > WebStack <= 1.2024 - Unauthenticated Arbitrary File Upload 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-1555 Patch Status Unpatched Published Apr 14, 2026 Affected Software WebStack [webstack] Researcher Chiao-Lin Yu (Steven Meow) More Details > WowShipping Pro 1.0.6 - Injected Backdoor 9.8 CVSS Rating 9.8 (Critical) Patch Status Patched Published Apr 17, 2026 Affected Software WowShipping Pro [table-rate-shipping-pro] Researcher(s): Unknown More Details > LearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletion 9.1 CVSS Rating 9.1 (Critical) CVE-ID CVE-2026-4365 Patch Status Patched Published Apr 13, 2026 Affected Software LearnPress – WordPress LMS Plugin for Create and Sell Online Courses [learnpress] Researcher Supakiad S. (m3ez) More Details > Academy LMS Pro < 3.5.2 - Authenticated (Custom+) Arbitrary File Upload 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-39598 Patch Status Patched Published Apr 16, 2026 Affected Software Academy LMS Pro [academy-pro] Researcher luc More Details > AcyMailing 9.11.0 - 10.8.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-3614 Patch Status Patched Published Apr 15, 2026 Affected Software AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress [acymailing] Researcher Ren Voza More Details > bBlocks – Essential Gutenberg Blocks & Patterns Collection <= 2.0.31 - Authenticated (Contributor+) Privilege Escalation 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-39579 Patch Status Patched Published Apr 16, 2026 Affected Software bBlocks – Essential Gutenberg Blocks & Patterns Collection [b-blocks] Researcher Abu Hurayra (HurayraIIT) More Details > Career Section <= 1.6 - Cross-Site Request Forgery to Arbitrary File Deletion 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2025-14868 Patch Status Patched Published Apr 15, 2026 Affected Software Career Section [career-section] Researcher Ivan Cese More Details > CMP – Coming Soon & Maintenance Plugin by NiteoThemes <= 4.1.16 - Missing Authorization to Authenticated (Administrator+) Arbitrary File Upload and Remote Code Execution 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-6518 Patch Status Patched Published Apr 17, 2026 Affected Software CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] Researcher ll More Details > Livemesh Addons by Elementor <= 9.0 - Authenticated (Contributor+) Local File Inclusion via Widget Template Parameter 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-1620 Patch Status Unpatched Published Apr 15, 2026 Affected Software Livemesh Addons by Elementor [addons-for-elementor] Researcher Webbernaut More Details > Login as User <= 1.0.3 - Authenticated (Subscriber+) Privilege Escalation via 'oclaup_original_admin' Cookie 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-5617 Patch Status Unpatched Published Apr 14, 2026 Affected Software Login as User – Switch User & WooCommerce Login as Customer [one-click-login-as-user] Researcher BaroHaf More Details > WP Customer Area <= 8.3.4 - Authenticated (Subscriber+) Arbitrary File Read/Deletion via ajax_attach_file 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-3464 Patch Status Patched Published Apr 17, 2026 Affected Software WP Customer Area [customer-area] Researcher shark3y More Details > WpStream – Live Streaming, Video on Demand, Pay Per View < 4.11.2 - Authenticated (Subscriber+) Arbitrary File Upload 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-39527 Patch Status Patched Published Apr 17, 2026 Affected Software WpStream – Live Streaming, Video on Demand, Pay Per View [wpstream] Researcher Muhammad Sharief (Md Sharief) More Details > ChapterOne <= 1.7 - Unauthenticated Local File Inclusion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40731 Patch Status Patched Published Apr 16, 2026 Affected Software ChapterOne - Bookstore and Publisher WordPress Theme [chapterone] Researcher João Pedro Soares de Alcântara More Details > Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.6 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-5718 Patch Status Patched Published Apr 17, 2026 Affected Software Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] Researcher Leonid Semenenko (lsemenenko) More Details > Eldon - Artist Portfolio WordPress Theme <= 1.4.1 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40738 Patch Status Patched Published Apr 16, 2026 Affected Software Eldon - Artist Portfolio WordPress Theme [eldon] Researcher Denver Jackson More Details > Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.4 - Authenticated (Sales Representative+) Arbitrary File Deletion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40727 Patch Status Patched Published Apr 16, 2026 Affected Software Groundhogg — CRM, Newsletters, and Marketing Automation [groundhogg] Researcher daroo More Details > Laurits <= 1.5.1 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40736 Patch Status Patched Published Apr 16, 2026 Affected Software Laurits - Portfolio and Agency WordPress Theme [laurits] Researcher Denver Jackson More Details > LuxeDrive - Limousine and Car Rental WordPress Theme <= 1.4 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40739 Patch Status Patched Published Apr 16, 2026 Affected Software LuxeDrive - Limousine and Car Rental WordPress Theme [luxedrive] Researcher Denver Jackson More Details > Meta Box <= 5.11.1 - Authenticated (Contributor+) Arbitrary File Deletion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-39468 Patch Status Patched Published Apr 13, 2026 Affected Software Meta Box [meta-box] Researcher Nguyen Ba Khanh More Details > Reina <= 2.1 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40735 Patch Status Patched Published Apr 16, 2026 Affected Software Reina - Spa and Wellness WordPress Theme [reina] Researcher Denver Jackson More Details > ShiftUp <= 1.3 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40733 Patch Status Patched Published Apr 16, 2026 Affected Software ShiftUp - Car Repair & Auto Services WordPress Theme [shiftup] Researcher Denver Jackson More Details > WooCommerce Product Filters < 2.0.6 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40725 Patch Status Patched Published Apr 16, 2026 Affected Software WooCommerce Product Filters [woocommerce-product-filters] Researcher Phat RiO More Details > DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.26 - Unauthenticated SQL Injection via 'packages' 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-3489 Patch Status Patched Published Apr 15, 2026 Affected Software DirectoryPress – Business Directory And Classified Ad Listing [directorypress] Researcher Leonid Semenenko (lsemenenko) More Details > Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.6 - Unauthenticated Limited Arbitrary File Read via mfile Field 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-5710 Patch Status Patched Published Apr 17, 2026 Affected Software Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] Researcher Osvaldo Noe Gonzalez Del Rio (Os) More Details > Easy Appointments <= 3.12.21 - Unauthenticated Sensitive Information Exposure via REST API 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-2262 Patch Status Patched Published Apr 17, 2026 Affected Software Easy Appointments [easy-appointments] Researcher MD. TAREQ AHAMED JONY (itztrq) More Details > Events Calendar for GeoDirectory <= 2.3.25 - Authenticated (Contributor+) PHP Object Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-39532 Patch Status Patched Published Apr 16, 2026 Affected Software Events Calendar for GeoDirectory [events-for-geodirectory] Researcher daroo More Details > Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder < 1.15.38 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2025-15441 Patch Status Patched Published Apr 14, 2026 Affected Software Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] Researcher hiariz More Details > GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.152 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-39512 Patch Status Patched Published Apr 13, 2026 Affected Software GeoDirectory – WP Business Directory Plugin and Classified Listings Directory [geodirectory] Researcher Tin Pham aka TF1T More Details > JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via '_cct_search' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-4352 Patch Status Patched Published Apr 13, 2026 Affected Software JetEngine [jet-engine] Researcher h0xilo More Details > Payment Gateway for Redsys & WooCommerce Lite <= 7.0.0 - Improper Verification of Cryptographic Signature to Unauthenticated Payment Status Manipulation 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-5050 Patch Status Patched Published Apr 15, 2026 Affected Software Payment Gateway for Redsys & WooCommerce Lite [woo-redsys-gateway-light] Researcher Nguyen Ngoc Duc (duc193) More Details > Post Duplicator <= 3.0.10 - Authenticated (Contributor+) PHP Object Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-39474 Patch Status Patched Published Apr 13, 2026 Affected Software Post Duplicator [post-duplicator] Researcher Nguyen Ba Khanh More Details > Product Filter for WooCommerce by WBW < 3.1.3 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-3830 Patch Status Patched Published Apr 14, 2026 Affected Software Product Filter for WooCommerce by WBW [woo-product-filter] Researcher Drew Webber (mcdruid) More Details > Product Filter for WooCommerce by WBW <= 3.1.2 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-39494 Patch Status Patched Published Apr 13, 2026 Affected Software Product Filter for WooCommerce by WBW [woo-product-filter] Researcher daroo More Details > Riaxe Product Customizer <= 2.1.2 - Unauthenticated SQL Injection via 'options' Parameter Keys in product_data 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-3599 Patch Status Unpatched Published Apr 15, 2026 Affected Software Riaxe Product Customizer [riaxe-product-customizer] Researcher Kai Aizen More Details > SpeakOut! Email Petitions <= 4.6.5 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-39530 Patch Status Patched Published Apr 13, 2026 Affected Software SpeakOut! Email Petitions [speakout] Researcher Nguyen Ba Khanh More Details > Unlimited Elements For Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File Read via Path Traversal in Repeater JSON/CSV URL with Path Traversal 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-4659 Patch Status Patched Published Apr 16, 2026 Affected Software Unlimited Elements For Elementor [unlimited-elements-for-elementor] Researcher Dmitrii Ignatyev More Details > WP Directory Kit <= 1.5.0 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-39531 Patch Status Patched Published Apr 13, 2026 Affected Software WP Directory Kit [wpdirectorykit] Researcher Martín Martín More Details > WP Photo Album Plus <= 9.1.08.001 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-39511 Patch Status Patched Published Apr 13, 2026 Affected Software WP Photo Album Plus [wp-photo-album-plus] Researcher Martín Martín More Details > Accessibly <= 3.0.3 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via Widget Source Injection via REST API 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-3643 Patch Status Unpatched Published Apr 14, 2026 Affected Software Accessibly – WordPress Website Accessibility [otm-accessibly] Researchers chaeypRonnachai Sretawat Na Ayutaya (Simonhaskelly)Ronnachai Chaipha (rxnr) More Details > Age Verification & Identity Verification by Token of Trust <= 3.32.3 - Unauthenticated Stored Cross-Site Scripting via 'description' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-2834 Patch Status Patched Published Apr 14, 2026 Affected Software Age Verification & Identity Verification by Token of Trust [token-of-trust] Researcher Teerachai Somprasong More Details > BackWPup <= 5.6.6 - Authenticated (Administrator+) Local File Inclusion via 'block_name' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-6227 Patch Status Patched Published Apr 13, 2026 Affected Software BackWPup – WordPress Backup & Restore Plugin [backwpup] Researcher Pixel_DefaultBR More Details > Form Maker by 10Web <= 1.15.40 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Text Box 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-4388 Patch Status Patched Published Apr 13, 2026 Affected Software Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] Researcher Naoya Takahashi (nakko) More Details > ManageWP Worker <= 4.9.31 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-39463 Patch Status Patched Published Apr 13, 2026 Affected Software ManageWP Worker [worker] Researcher Steven Julian More Details > Prismatic <= 3.7.3 - Unauthenticated Stored Cross-Site Scripting via 'prismatic_encoded' Pseudo-Shortcode 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-3876 Patch Status Patched Published Apr 15, 2026 Affected Software Prismatic [prismatic] Researcher Athiwat Tiprasaharn (Jitlada) More Details > Quick Interest Slider <= 3.1.5 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-5694 Patch Status Unpatched Published Apr 14, 2026 Affected Software Quick Interest Slider [quick-interest-slider] Researcher Chawabhon Netisingha (JNX03) More Details > Royal Elementor Addons Pro < 1.7.1041 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-40720 Patch Status Patched Published Apr 16, 2026 Affected Software Royal Elementor Addons Pro [wpr-addons-pro] Researcher Drew Webber (mcdruid) More Details > Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authenticated (Administrator+) PHP Object Injection 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-3017 Patch Status Patched Published Apr 13, 2026 Affected Software Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts [post-carousel] Researcher Vilaysone CHANTHAVONG (0xJ0cKkY) More Details > Social Slider Feed <= 2.3.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-39507 Patch Status Patched Published Apr 16, 2026 Affected Software Social Slider Feed [instagram-slider-widget] Researcher Nguyen Ba Khanh More Details > WP Statistics <= 14.16.4 - Unauthenticated Stored Cross-Site Scripting via 'utm_source' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-5231 Patch Status Patched Published Apr 16, 2026 Affected Software WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] Researcher daroo More Details > Accessibility Suite by Ability, Inc <= 4.20 - Authenticated (Subscriber+) SQL Injection via 'scan_id' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-3773 Patch Status Unpatched Published Apr 15, 2026 Affected Software Accessibility Suite by Ability, Inc [online-accessibility] Researcher Victor Pasman More Details > Client Portal (Pro) <= 5.6.2 - Authenticated (CP Client+) Arbitrary File Download 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-40724 Patch Status Patched Published Apr 16, 2026 Affected Software Client Portal Pro [leco-client-portal] Researcher Jarno Vos (jarnovos) More Details > Eleganzo <= 1.2 - Authenticated (Subscriber+) Arbitrary Directory Deletion 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2025-15470 Patch Status Patched Published Apr 14, 2026 Affected Software Eleganzo [eleganzo] Researcher Phat RiO More Details > Germanized for WooCommerce <= 3.20.5 - Unauthenticated Arbitrary Shortcode Execution 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-2582 Patch Status Patched Published Apr 13, 2026 Affected Software Germanized for WooCommerce [woocommerce-germanized] Researcher Chiao-Lin Yu (Steven Meow) More Details > MasterStudy LMS <= 3.7.25 - Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' Parameters 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-4817 Patch Status Patched Published Apr 16, 2026 Affected Software MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] Researcher Naoya Takahashi (nakko) More Details > Tutor LMS <= 3.9.8 - Authenticated (Admin+) SQL Injection via 'date' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-6080 Patch Status Patched Published Apr 16, 2026 Affected Software Tutor LMS – eLearning and online course solution [tutor] Researcher PRISM More Details > WCFM Marketplace – Multivendor Marketplace for WooCommerce <= 3.7.1 - Authenticated (Store vendor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2025-63029 Patch Status Unpatched Published Apr 15, 2026 Affected Software WCFM Marketplace – Multivendor Marketplace for WooCommerce [wc-multivendor-marketplace] Researcher Martino Spagnuolo More Details > WP Statistics <= 14.16.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure and Privacy Audit Manipulation 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-3488 Patch Status Patched Published Apr 16, 2026 Affected Software WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] Researcher Jack Pas (Dark.) More Details > wpForo Forum <= 2.4.16 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Forum Post Modification via 'guestposting' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-4666 Patch Status Patched Published Apr 16, 2026 Affected Software wpForo Forum [wpforo] Researcher Jared Reyes More Details > BetterDocs <= 4.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-3875 Patch Status Patched Published Apr 15, 2026 Affected Software BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor [betterdocs] Researcher Muhammad Yudha - DJ More Details > Coachific Shortcode <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'userhash' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4005 Patch Status Unpatched Published Apr 14, 2026 Affected Software Coachific Shortcode [coachific-shortcode] Researcher zakaria More Details > Content Blocks (Custom Post Widget) <= 3.3.9 - Authenticated (Author+) Stored Cross-Site Scripting via content_block Shortcode 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-0894 Patch Status Patched Published Apr 17, 2026 Affected Software Content Blocks (Custom Post Widget) [custom-post-widget] Researcher Muhammad Yudha - DJ More Details > Contextual Related Posts <= 4.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'other_attributes' 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-2986 Patch Status Patched Published Apr 17, 2026 Affected Software Contextual Related Posts [contextual-related-posts] Researchers Athiwat Tiprasaharn (Jitlada)Itthidej Aramsri (Boeing777) More Details > Email Encoder – Protect Email Addresses and Phone Numbers <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via eeb_mailto Shortcode 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-2840 Patch Status Patched Published Apr 15, 2026 Affected Software Email Encoder – Protect Email Addresses and Phone Numbers [email-encoder-bundle] Researcher Athiwat Tiprasaharn (Jitlada) More Details > EMC Scheduling Manager <= 4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via calendly Shortcode 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-0868 Patch Status Patched Published Apr 18, 2026 Affected Software EMC – Easily Embed Calendly Scheduling [embed-calendly-scheduling] Researcher Muhammad Yudha - DJ More Details > Flipbox Addon for Elementor <= 2.1.1 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-6048 Patch Status Patched Published Apr 17, 2026 Affected Software Flipbox Addon for Elementor [ultimate-flipbox-addon-for-elementor] Researchers Athiwat Tiprasaharn (Jitlada)Itthidej Aramsri (Boeing777) More Details > Jupiter X Core <= 4.14.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-39491 Patch Status Patched Published Apr 13, 2026 Affected Software Jupiter X Core [jupiterx-core] Researcher Nguyen Ba Khanh More Details > Livemesh Addons by Elementor <= 9.0 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via Plugin Settings 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-1572 Patch Status Unpatched Published Apr 15, 2026 Affected Software Livemesh Addons by Elementor [addons-for-elementor] Researcher Muhammad Yudha - DJ More Details > Mini Ajax Cart for WooCommerce <= 1.3.4 - Authenticated (Author+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-6370 Patch Status Patched Published Apr 15, 2026 Affected Software Mini Ajax Cart for WooCommerce [mini-ajax-woo-cart] Researcher Ali Osman ERBAS (0110m4n) More Details > Page Builder Gutenberg Blocks <= 3.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via External iCal Feed Data 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4801 Patch Status Patched Published Apr 17, 2026 Affected Software Page Builder Gutenberg Blocks – CoBlocks [coblocks] Researcher Fernando Mecozzi More Details > Power Charts <= 0.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4011 Patch Status Unpatched Published Apr 14, 2026 Affected Software Power Charts – Responsive Beautiful Charts & Graphs [wpgo-power-charts-lite] Researcher Muhammad Yudha - DJ More Details > Pz-LinkCard <= 2.5.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-2434 Patch Status Unpatched Published Apr 17, 2026 Affected Software Pz-LinkCard [pz-linkcard] Researcher Muhammad Yudha - DJ More Details > Royal Addons for Elementor <= 1.7.1056 - Authenticated (Contributor+) Stored Cross-Site Scripting via Instagram Feed Widget 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-5162 Patch Status Patched Published Apr 16, 2026 Affected Software Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] Researcher Caspian More Details > Shipment Tracker for Woocommerce <= 1.5.3.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-39540 Patch Status Patched Published Apr 16, 2026 Affected Software Shipment Tracker for Woocommerce [shipment-tracker-for-woocommerce] Researcher Nguyen Ba Khanh More Details > ShopLentor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4059 Patch Status Patched Published Apr 13, 2026 Affected Software ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin [woolentor-addons] Researcher zaim More Details > Surbma | Booking.com <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-1607 Patch Status Patched Published Apr 13, 2026 Affected Software Surbma | Booking.com Shortcode [surbma-bookingcom-shortcode] Researcher zakaria More Details > Vantage <= 1.20.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Block Text Content 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-5070 Patch Status Patched Published Apr 15, 2026 Affected Software Vantage [vantage] Researcher Osvaldo Noe Gonzalez Del Rio (Os) More Details > VI: Include Post By <= 0.4.200706 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_container' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-5717 Patch Status Unpatched Published Apr 14, 2026 Affected Software VI: Include Post By [vi-include-post-by] Researcher MAJidox More Details > Video Gallery – YouTube Gallery & Responsive Video Playlist <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2025-15636 Patch Status Patched Published Apr 15, 2026 Affected Software Video Gallery – YouTube Gallery & Responsive Video Playlist [youtube-showcase] Researcher Muhammad Yudha - DJ More Details > WM JqMath <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-3998 Patch Status Unpatched Published Apr 14, 2026 Affected Software WM JqMath [wm-jqmath] Researcher Gilang - DJ More Details > WP Circliful <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-3659 Patch Status Unpatched Published Apr 14, 2026 Affected Software WP Circliful [wp-circliful] Researcher Gilang - DJ More Details > WP Docs <= 2.2.9 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wpdocs_options[icon_size]' 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-3878 Patch Status Patched Published Apr 15, 2026 Affected Software WP Docs [wp-docs] Researcher Nabil Irawan More Details > WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'put_wpgm' Shortcode 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2025-13364 Patch Status Patched Published Apr 15, 2026 Affected Software WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] Researcher Muhammad Yudha - DJ More Details > WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_box Shortcode 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-3885 Patch Status Patched Published Apr 15, 2026 Affected Software WP Shortcodes Plugin — Shortcodes Ultimate [shortcodes-ultimate] Researcher Dmitrii Ignatyev More Details > WP YouTube Lyte <= 1.7.29 - Authenticated (Contributor+) Stored Cross-Site Scripting via lyte Shortcode 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-3299 Patch Status Patched Published Apr 15, 2026 Affected Software WP YouTube Lyte [wp-youtube-lyte] Researcher Muhammad Yudha - DJ More Details > Youzify <= 1.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'checkin_place_id' Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-1559 Patch Status Patched Published Apr 17, 2026 Affected Software Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress [youzify] Researcher Tharadol Suksamran (d3kc4rt_1) More Details > CodeColorer <= 0.10.1 - Unauthenticated Stored Cross-Site Scripting via 'class' attribute in 'cc' Comment Shortcode 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-4032 Patch Status Patched Published Apr 15, 2026 Affected Software CodeColorer [codecolorer] Researcher Chawabhon Netisingha (JNX03) More Details > Customer Reviews for WooCommerce <= 5.101.0 - Reflected Cross-Site Scripting via 'crsearch' 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-3355 Patch Status Patched Published Apr 15, 2026 Affected Software Customer Reviews for WooCommerce [customer-reviews-woocommerce] Researchers Athiwat Tiprasaharn (Jitlada)Itthidej Aramsri (Boeing777) More Details > Hostel <= 1.1.6 - Reflected Cross-Site Scripting via 'shortcode_id' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-1838 Patch Status Patched Published Apr 17, 2026 Affected Software Hostel [hostel] Researcher Bee More Details > MagOne <= 9.0 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-39548 Patch Status Patched Published Apr 16, 2026 Affected Software magone [magone] Researcher João Pedro Soares de Alcântara More Details > OPEN-BRAIN <= 0.5.0 - Cross-Site Request Forgery 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-4091 Patch Status Unpatched Published Apr 14, 2026 Affected Software OPEN-BRAIN [open-brain] Researcher Muhammad Nur Ibnu Hubab (Ibnu) More Details > Product Pricing Table by WooBeWoo <= 1.1.0 - Cross-Site Request Forgery to Stored XSS and Pricing Table Deletion 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-1852 Patch Status Patched Published Apr 14, 2026 Affected Software Product Pricing Table by WooBeWoo [woo-product-pricing-tables] Researcher Muhammad Nur Ibnu Hubab (Ibnu) More Details > User Registration & Membership <= 5.1.4 - Unauthenticated Open Redirect via 'redirect_to_on_logout' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-6203 Patch Status Patched Published Apr 13, 2026 Affected Software User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder [user-registration] Researchers Anthony Cihan (Hann1bl3L3ct3r)Louis Deschanel (JeanJeanLeHaxor)Pascal SUN More Details > WPZOOM Addons for Elementor – Starter Templates & Widgets <= 1.3.4 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-39597 Patch Status Patched Published Apr 16, 2026 Affected Software WPZOOM Addons for Elementor – Starter Templates & Widgets [wpzoom-elementor-addons] Researcher Nguyen Ba Khanh More Details > Avada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Limited Arbitrary WordPress Action Execution 5.4 CVSS Rating 5.4 (Medium) CVE-ID CVE-2026-1509 Patch Status Patched Published Apr 14, 2026 Affected Software Avada (Fusion) Builder [fusion-builder] Researcher Webbernaut More Details > Better Find and Replace – AI-Powered Suggestions <= 1.7.9 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Title 5.4 CVSS Rating 5.4 (Medium) CVE-ID CVE-2026-3369 Patch Status Patched Published Apr 15, 2026 Affected Software Better Find and Replace – AI-Powered Suggestions [real-time-auto-find-and-replace] Researcher kai63001 More Details > Categories Images <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'z_taxonomy_image' Shortcode 5.4 CVSS Rating 5.4 (Medium) CVE-ID CVE-2026-2505 Patch Status Patched Published Apr 17, 2026 Affected Software Categories Images [categories-images] Researchers Athiwat Tiprasaharn (Jitlada)Tharadol Suksamran (d3kc4rt_1) More Details > 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.17 - Missing Authorization to Unauthenticated Private/Draft Flipbook Data Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-1314 Patch Status Patched Published Apr 14, 2026 Affected Software 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] Researcher Kai Aizen More Details > Accept Cryptocurrencies with Plisio <= 2.0.6 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-6372 Patch Status Unpatched Published Apr 15, 2026 Affected Software Accept Cryptocurrencies with Plisio [plisio-payment-gateway-for-woocommerce] Researcher AXIS More Details > Advanced Custom Fields (ACF®) <= 6.7.0 - Unauthenticated Missing Authorization to Arbitrary Post/Page Disclosure via AJAX Field Query Parameters 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-4812 Patch Status Patched Published Apr 14, 2026 Affected Software Advanced Custom Fields (ACF®) [advanced-custom-fields] Researcher Fernando Mecozzi More Details > Basic Google Maps Placemarks <= 1.10.7 - Missing Authorization to Unauthenticated Default Map Coordinate Update 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-3581 Patch Status Patched Published Apr 15, 2026 Affected Software Basic Google Maps Placemarks [basic-google-maps-placemarks] Researcher Chawabhon Netisingha (JNX03) More Details > Booking Activities <= 1.16.48.1 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-39525 Patch Status Patched Published Apr 13, 2026 Affected Software Booking Activities [booking-activities] Researcher Nguyen Ba Khanh More Details > e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Form Settings Modification via AJAX 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-3642 Patch Status Unpatched Published Apr 14, 2026 Affected Software e-shot [e-shot-form-builder] Researcher Poli More Details > Easy Appointments <= 3.12.21 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-39513 Patch Status Patched Published Apr 13, 2026 Affected Software Easy Appointments [easy-appointments] Researcher Martín Martín More Details > Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-4160 Patch Status Patched Published Apr 16, 2026 Affected Software Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] Researcher Prickly Cactus More Details > HAPPY – Helpdesk Support Ticket System <= 1.0.10 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-39593 Patch Status Patched Published Apr 16, 2026 Affected Software HAPPY – Helpdesk Support Ticket System [happy-helpdesk-support-ticket-system] Researcher Nabil Irawan More Details > Katalogportal-pdf-sync Widget <= 1.0.0 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure via 'katalogportal_shortcodePrinter' AJAX Action 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-3649 Patch Status Unpatched Published Apr 14, 2026 Affected Software Katalogportal-pdf-sync Widget [katalogportal-pdf-sync] Researcher Poli More Details > Kubio AI Page Builder <= 2.7.2 - Missing Authorization to Authenticated (Contributor+) Limited File Upload via Kubio Block Attributes 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-5427 Patch Status Patched Published Apr 16, 2026 Affected Software Kubio AI Page Builder [kubio] Researcher oolongeya More Details > LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-5234 Patch Status Patched Published Apr 16, 2026 Affected Software LatePoint – Calendar Booking Plugin for Appointments and Events [latepoint] Researcher darkmode More Details > MetForm Pro <= 3.9.7 - Unauthenticated Payment Amount Manipulation via 'mf-calculation' 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-1782 Patch Status Patched Published Apr 14, 2026 Affected Software MetForm Pro [metform-pro] Researcher andrea bocchetti More Details > Nexi XPay <= 8.3.0 - Missing Authorization to Unauthenticated Order Status Modification 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2025-15565 Patch Status Patched Published Apr 14, 2026 Affected Software Nexi XPay [cartasi-x-pay] Researcher Md. Moniruzzaman Prodhan (NomanProdhan) More Details > Payment Gateway for Redsys & WooCommerce Lite <= 7.0.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-40741 Patch Status Patched Published Apr 16, 2026 Affected Software Payment Gateway for Redsys & WooCommerce Lite [woo-redsys-gateway-light] Researcher Nguyen Ba Khanh More Details > Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.5 - Missing Authorization to Limited Post Meta Modification 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-0718 Patch Status Patched Published Apr 15, 2026 Affected Software Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX [ultimate-post] Researcher Mohammad Amin Hajian (mamadrce) More Details > Quiz and Survey Master (QSM) <= 11.1.0 - Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-5797 Patch Status Patched Published Apr 16, 2026 Affected Software Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker [quiz-master-next] Researcher Rafshanzani Suhada More Details > Riaxe Product Customizer <= 2.1.2 - Unauthenticated Arbitrary User Deletion via 'user_id' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-3595 Patch Status Unpatched Published Apr 15, 2026 Affected Software Riaxe Product Customizer [riaxe-product-customizer] Researcher Kai Aizen More Details > Tutor LMS <= 3.9.8 - Authenticated (Subscriber+) Arbitrary Course Content Manipulation via tutor_update_course_content_order 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-5502 Patch Status Patched Published Apr 16, 2026 Affected Software Tutor LMS – eLearning and online course solution [tutor] Researcher momopon1415 More Details > User Registration Stripe <= 1.3.14 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-40726 Patch Status Patched Published Apr 16, 2026 Affected Software User Registration Stripe [user-registration-stripe] Researcher 0xd4rk5id3 More Details > Form Maker by 10Web <= 1.15.40 - Authenticated (Administrator+) SQL Injection via 'ip_search' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-3330 Patch Status Patched Published Apr 16, 2026 Affected Software Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] Researcher Sein Linn More Details > JetBackup <= 3.1.19.8 - Authenticated (Administrator+) Arbitrary Directory Deletion via Path Traversal in 'fileName' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-4853 Patch Status Patched Published Apr 16, 2026 Affected Software JetBackup – Backup, Restore & Migrate [backup] Researcher lucsob More Details > Custom New User Notification <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'User Mail Subject' Setting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-3551 Patch Status Unpatched Published Apr 15, 2026 Affected Software Custom New User Notification [custom-new-user-notification] Researcher Muhammad Nur Ibnu Hubab (Ibnu) More Details > List View Google Calendar <= 7.4.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via Event Description 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-2396 Patch Status Patched Published Apr 14, 2026 Affected Software List View Google Calendar [list-view-google-calendar] Researcher Pattama Tangpoonponwiwat (Kwan) More Details > OPEN-BRAIN <= 0.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'API Key' Setting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-3995 Patch Status Unpatched Published Apr 15, 2026 Affected Software OPEN-BRAIN [open-brain] Researcher Muhammad Nur Ibnu Hubab (Ibnu) More Details > VideoZen <= 1.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'VideoZen available subtitles languages' Field 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-6439 Patch Status Unpatched Published Apr 16, 2026 Affected Software VideoZen [videozen] Researcher Muhammad Nur Ibnu Hubab (Ibnu) More Details > WholeSale Products Dynamic Pricing Management WooCommerce <= 1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-4479 Patch Status Patched Published Apr 13, 2026 Affected Software WholeSale Products Dynamic Pricing Management WooCommerce [wholesale-products-dynamic-pricing-management-woocommerce] Researcher Muhammad Nur Ibnu Hubab (Ibnu) More Details > Avada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Sensitive Information Exposure via Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-1541 Patch Status Patched Published Apr 14, 2026 Affected Software Avada (Fusion) Builder [fusion-builder] Researcher Webbernaut More Details > Canto <= 3.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Setting Modification 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-6441 Patch Status Unpatched Published Apr 16, 2026 Affected Software Canto [canto] Researcher Legion Hunter More Details > CMS für Motorrad Werkstätten <= 1.0.0 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-6451 Patch Status Unpatched Published Apr 16, 2026 Affected Software Plugin: CMS für Motorrad Werkstätten [cms-fuer-motorrad-werkstaetten] Researcher Régis SENET More Details > Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) <= 4.1.8 Missing Authorization to Authenticated (Subscriber+) Order Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-4109 Patch Status Patched Published Apr 13, 2026 Affected Software Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) [wp-event-solution] Researcher Supakiad S. (m3ez) More Details > FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration <= 1.91.2 - Authenticated (Board Member+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-40784 Patch Status Patched Published Apr 15, 2026 Affected Software FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration [fluent-boards] Researcher Jakub Herman More Details > Inquiry form to posts or pages <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'inq_header' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-6293 Patch Status Unpatched Published Apr 14, 2026 Affected Software Inquiry form to posts or pages [inquiry-form-to-posts-or-pages] Researcher Muhammad Nur Ibnu Hubab (Ibnu) More Details > MyRewards <= 5.7.3 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-40786 Patch Status Patched Published Apr 16, 2026 Affected Software MyRewards [woorewards] Researcher Muhan Luo More Details > Petje.af <= 2.1.8 - Cross-Site Request Forgery to Account Deletion via 'petjeaf_disconnect' AJAX Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-4002 Patch Status Unpatched Published Apr 14, 2026 Affected Software Petje.af [petje-af] Researcher theviper17y More Details > ProfilePress <= 4.16.12 - Missing Authorization to Authenticated (Subscriber+) Inactive Membership Plan Subscription 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-4949 Patch Status Patched Published Apr 15, 2026 Affected Software Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress [wp-user-avatar] Researcher Supakiad S. (m3ez) More Details > Smart Online Order for Clover <= 1.6.0 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2025-15635 Patch Status Unpatched Published Apr 15, 2026 Affected Software Smart Online Order for Clover [clover-online-orders] Researcher Kévin Mosbahi (Mika) More Details > Ultra Addons for WPForms <= 1.0.11 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-39594 Patch Status Patched Published Apr 16, 2026 Affected Software Ultra Addons for WPForms [ultra-addons-for-wpforms] Researcher Sandeep V More Details > UserPro - Community and User Profile WordPress Plugin < 5.1.11 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2025-53444 Patch Status Patched Published Apr 15, 2026 Affected Software UserPro - Community and User Profile WordPress Plugin [userpro] Researcher Ananda Dhakal More Details > OneSignal – Web Push Notifications <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Post Meta Deletion via 'post_id' 3.1 CVSS Rating 3.1 (Low) CVE-ID CVE-2026-3155 Patch Status Patched Published Apr 15, 2026 Affected Software OneSignal – Web Push Notifications [onesignal-free-web-push-notifications] Researcher Muhammad Sharief More Details > As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence. This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can. Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. The post Wordfence Intelligence Weekly WordPress Vulnerability Report (April 13, 2026 to April 19, 2026) appeared first on Wordfence.
Quelle: www.wordfence.com