Wordfence Intelligence Weekly WordPress Vulnerability Report (April 20, 2026 to April 26, 2026)

⚠️ CVE-Referenzen: CVE-2026-6674 CVE-2026-25440 CVE-2026-40762 CVE-2026-4106 CVE-2026-39490 CVE-2026-3569 CVE-2026-40783 CVE-2026-40785 CVE-2025-64215 CVE-2026-39503 CVE-2026-5428 CVE-2026-40748 CVE-2026-40757 CVE-2026-39467 CVE-2024-7083 CVE-2026-39498 CVE-2025-62110 CVE-2025-60085 CVE-2026-4074 CVE-2026-40788 CVE-2026-40772 CVE-2026-40787 CVE-2026-4085 CVE-2026-6041 CVE-2026-2951 CVE-2026-2028 CVE-2026-4138 CVE-2026-40754 CVE-2026-39574 CVE-2026-4089 CVE-2026-40732 CVE-2026-39514 CVE-2026-5347 CVE-2026-40758 CVE-2025-62104 CVE-2026-39481 CVE-2026-5767 CVE-2026-40779 CVE-2026-6294 CVE-2026-4090 CVE-2026-2717 CVE-2026-40755 CVE-2026-40789 CVE-2026-6235 CVE-2026-39589 CVE-2026-4279 CVE-2026-3362 CVE-2026-39465 CVE-2026-39584 CVE-2026-4126 CVE-2026-4512 CVE-2026-40743 CVE-2026-4082 CVE-2026-5464 CVE-2026-39437 CVE-2026-3565 CVE-2026-39590 CVE-2026-40759 CVE-2026-1395 CVE-2026-6675 CVE-2026-4280 CVE-2026-40773 CVE-2026-40761 CVE-2026-39446 CVE-2026-1930 CVE-2026-39449 CVE-2026-40793 CVE-2026-4133 CVE-2025-69332 CVE-2026-40790 CVE-2026-5478 CVE-2026-7106 CVE-2026-6703 CVE-2026-39581 CVE-2026-5364 CVE-2026-39478 CVE-2026-6236 CVE-2026-6246 CVE-2026-40752 CVE-2026-4139 CVE-2026-40749 CVE-2026-39529 CVE-2026-39450 CVE-2026-1923 CVE-2026-39440 CVE-2026-5820 CVE-2026-39515 CVE-2026-5721 CVE-2026-40781 CVE-2026-2719 CVE-2026-3361 CVE-2026-4128 CVE-2026-40791 CVE-2026-4078 CVE-2026-1845 CVE-2026-40768 CVE-2026-40767 CVE-2026-4140 CVE-2026-4132 CVE-2026-41557 CVE-2026-4076 CVE-2026-40775 CVE-2026-5748 CVE-2026-40769 CVE-2026-4353 CVE-2026-40780 CVE-2026-40809 CVE-2026-40750 CVE-2025-11762 CVE-2026-41556 CVE-2026-3844 CVE-2026-34900 CVE-2026-4121 CVE-2026-40760 CVE-2026-40753 CVE-2026-39472 CVE-2026-6711 CVE-2026-40774 CVE-2026-40792 CVE-2026-39441 CVE-2026-6393 CVE-2026-39438 CVE-2026-40746 CVE-2026-40794 CVE-2026-40756 CVE-2026-1379 CVE-2026-40765 CVE-2026-40782 CVE-2026-6248 CVE-2026-40770 CVE-2026-4118 CVE-2026-39518 CVE-2026-4117 CVE-2026-39443 CVE-2026-4088 CVE-2026-40751 CVE-2026-39442 CVE-2026-39499 CVE-2026-6810 CVE-2026-5488 CVE-2026-40766 CVE-2026-4852 CVE-2026-1913 CVE-2026-40747 CVE-2026-4142 CVE-2026-39445 CVE-2026-4125 CVE-2026-39489 CVE-2026-39471 CVE-2026-28040 CVE-2026-6712 CVE-2026-4119 CVE-2026-6396 CVE-2026-41554 CVE-2026-40771 CVE-2025-58922 CVE-2026-4131
Last week, there were 157 vulnerabilities disclosed in 122 WordPress Plugins and 27 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 69 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back. Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 35,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free. Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. New Firewall Rules Deployed Last Week The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection. The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week: WAF-RULE-908 – Data redacted while we work with the vendor on a patch. Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay. Total Unpatched & Patched Vulnerabilities Last Week Patch Status Number of Vulnerabilities Patched 115 Unpatched 42 Total Vulnerabilities by CVSS Severity Last Week Severity Rating Number of Vulnerabilities Medium Severity 104 High Severity 47 Critical Severity 6 Total Vulnerabilities by CWE Type Last Week Vulnerability Type by CWE Number of Vulnerabilities Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 47 Missing Authorization 34 Deserialization of Untrusted Data 23 Cross-Site Request Forgery (CSRF) 12 Unrestricted Upload of File with Dangerous Type 9 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 8 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 6 Exposure of Sensitive Information to an Unauthorized Actor 5 Authorization Bypass Through User-Controlled Key 4 Improper Control of Generation of Code ('Code Injection') 3 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 2 External Control of File Name or Path 1 Improper Input Validation 1 Improper Neutralization of CRLF Sequences ('CRLF Injection') 1 Improper Privilege Management 1 Researchers That Contributed to WordPress Security Last Week Researcher Name Number of Vulnerabilities Denver Jackson 17 Jakub Herman 12 Muhammad Nur Ibnu Hubab (Ibnu) 9 daroo 9 afnaan 6 Muhammad Yudha - DJ 5 Phat RiO 5 Nabil Irawan 5 Athiwat Tiprasaharn (Jitlada) 4 hivesec 4 Dmitrii Ignatyev 4 MAJidox 4 Nguyen Ba Khanh 4 Trương Hữu Phúc (truonghuuphuc) 4 Gilang - DJ 3 Itthidej Aramsri (Boeing777) 3 Legion Hunter 2 Even Stokkedalen 2 Kazuma Matsumoto 2 Bonds 2 zakaria 2 theviper17y 2 João Pedro Soares de Alcântara 2 Chiao-Lin Yu (Steven Meow) 2 zaim 2 3ele / Sebastian Weiss 1 Daniel Basta (whizzu) 1 Thomas Sanzey 1 Nguyen Ngoc Duc (duc193) 1 Marc-André Beaulieu (h3dg3h0g) 1 Rafie Muhammad 1 Skoobi 1 TruongLV1 From FPT Night Wolf 1 HuajiHD 1 h0xilo 1 t0ann9uy3n 1 Dahmani Toumi (pegaSUS) 1 loris4py 1 Weerawat Pawanawiwat (ErbaZZ) 1 Alexis Lafontaine 1 Kai Aizen 1 James Pirstin 1 0xd4rk5id3 1 wackydawg 1 w41bu1 1 0xHerc 1 ll 1 Lio 1 TheNetRunner Security Research 1 Lubin Regnault 1 Daniel Wade 1 Que Thanh Tuan 1 Md. Moniruzzaman Prodhan (NomanProdhan) 1 Mehdi Ouassou 1 Régis SENET 1 kai63001 1 babyhack 1 Ritsuy 1 Niv Kochan 1 davidfdzmorilla 1 Tarcísio Luchesi De Almeida Silva (Poystick) 1 Vilaysone CHANTHAVONG (0xJ0cKkY) 1 Hung Nguyen (bashu) 1 lagi bljr 1 Tran Nguyen Bao Khanh 1 Mustafa 1 Teerachai Somprasong 1 Saleh Elsayed (0xManticore) 1 benzdeus 1 Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report. WordPress Plugins with Reported Vulnerabilities Last Week Software Name Software Slug ACF Galerie 4 acf-galerie-4 Advanced Product Fields (Product Addons) for WooCommerce advanced-product-fields-for-woocommerce Anti-Malware Security and Brute-Force Firewall gotmls AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress automatorwp BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor betterdocs Blocksy Companion Pro blocksy-companion-pro Bookify – Appointment Booking & Scheduling for WordPress bookify Booking Calendar Contact Form booking-calendar-contact-form Booking for Appointments and Events Calendar – Amelia ameliabooking Booking Package booking-package Bookit — Booking & Appointment Calendar bookit Bread & Butter: AI-Powered Lead Intelligence bread-butter Breaking News WP breaking-news-wp Breeze Cache breeze Buzz Comments buzz-comments CalJ Shabbat Times calj Call To Action Plugin call-to-action-plugin Chatbot for WordPress by Collect.chat collectchat CI HUB Connector ci-hub-connector Contact Form Extender for Divi – Submissions DB & Extra Fields contact-form-extender-for-divi-builder Contact Form to Any API contact-form-to-any-api Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe contest-gallery Coupon Affiliates – Affiliate Plugin for WooCommerce woo-coupon-usage Create DB Tables create-db-tables Download Monitor download-monitor Drag and Drop File Upload for Contact Form 7 drag-and-drop-file-upload-for-contact-form-7 DX Unanswered Comments dx-unanswered-comments E-cab Taxi Booking Manager for Woocommerce ecab-taxi-booking-manager Easy Digital Downloads – eCommerce Payments and Subscriptions made easy easy-digital-downloads Easy Social Photos Gallery – MIF my-instagram-feed Email Encoder – Protect Email Addresses and Phone Numbers email-encoder-bundle Emailchef emailchef ER Swiffy Insert er-swiffy-insert Essential Addons for Elementor – Popular Elementor Templates & Widgets essential-addons-for-elementor-lite EventPrime – Events Calendar, Bookings and Tickets eventprime-event-calendar-management Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder everest-forms ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) google-analytics-dashboard-for-wp Fast & Fancy Filter – 3F fast-fancy-filter-3f Feed KuantoKusta for WooCommerce – Free feed-kuantokusta-for-woocommerce FunnelFormsPro Funnelforms-pro FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce wp-marketing-automations Gallagher Website Design gallagher-website-design GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content geeky-bot GiveWP – Donation Plugin and Fundraising Platform give Google PageRank Display google-pagerank-display Groundhogg — CRM, Newsletters, and Marketing Automation groundhogg Gutentools gutentools Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor gutentor Highland Software Custom Role Manager highland-software-custom-role-manager HT Mega Addons for Elementor – Elementor Widgets & Template Builder ht-mega-for-elementor HTTP Headers http-headers HubSpot All-In-One Marketing – Forms, Popups, Live Chat leadin Image Source Control Lite – Show Image Credits and Captions image-source-control-isc InPost Gallery inpost-gallery Inquiry cart inquiry-cart ITERAS iteras Jupiter X Core jupiterx-core Kcaptcha kcaptcha KiviCare – Clinic & Patient Management System (EHR) kivicare-clinic-management-system Liaison Site Prober liaison-site-prober Link Library link-library ListingPro Plugin listingpro-plugin MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro MasterStudy LMS WordPress Plugin – for Online Courses and Education masterstudy-lms-learning-management-system MaxiBlocks Builder | 17,000+ Design Assets, Patterns, Icons & Starter Sites maxi-blocks mCatFilter mcatfilter Min Max Step Quantity Limits Manager for WooCommerce product-quantity-for-woocommerce Modula Image Gallery – Photo Grid & Video Gallery modula-best-grid-gallery Motors – Car Dealership & Classified Listings Plugin motors-car-dealership-classified-listings Ni WooCommerce Order Export ni-woocommerce-order-export Notification for Telegram notification-for-telegram Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress wp-user-avatar Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction paid-member-subscriptions PDF Invoices & Packing Slips for WooCommerce woocommerce-pdf-invoices-packing-slips Plugin: CMS für Motorrad Werkstätten cms-fuer-motorrad-werkstaetten Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred mycred Posts map posts-map Private WP suite private-wp-suite Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker quiz-master-next Quran Live Multilanguage quran-live Real Estate Pro re-pro reCaptcha by WebDesignBy webdesignby-recaptcha RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress computer-repair-shop Rescue Shortcodes rescue-shortcodes Responsive Blocks – Page Builder for Blocks & Patterns responsive-block-editor-addons ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema reviewx Royal Addons for Elementor – Addons and Templates Kit for Elementor royal-elementor-addons Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini royal-mcp rtMedia for WordPress, BuddyPress and bbPress buddypress-media Salon Booking System – Free Version salon-booking-system Sendmachine for WordPress sendmachine Sentence To SEO (keywords, description and tags) sentence-to-seo Short Comment Filter short-comment-filter ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF shortpixel-image-optimiser Simple Random Posts Shortcode simple-random-posts-shortcode Slider Bootstrap Carousel slider-bootstrap-carousel Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider ml-slider SlideShowPro SC slideshowpro-shortcode Social Rocket – Social Sharing Plugin social-rocket Switch CTA Box switch-cta-box Table Manager table-manager Taqnix taqnix Text Snippets text-snippet TextP2P Texting Widget textp2p-texting-widget TP Restore Categories And Taxonomies tp-restore-categories-and-taxonomies Tutor LMS – eLearning and online course solution tutor Twittee Text Tweet twittee-text-tweet Website LLMs.txt website-llms-txt WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes wp-books-gallery WP Responsive Popup + Optin wp-popup-optin WP Sessions Time Monitoring Full Automatic activitytime WP Store Locator wp-store-locator WP Time Slots Booking Form wp-time-slots-booking-form WPAdverts – Classifieds Plugin wpadverts WPBot – AI ChatBot for Live Support, Lead Generation, AI Services chatbot wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin wpdatatables wpForo Forum wpforo WPGraphQL wp-graphql WPMK Block wpmk-block WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce wp-sms YayMail – WooCommerce Email Customizer yaymail Zypento Blocks zypento-blocks WordPress Themes with Reported Vulnerabilities Last Week Software Name Software Slug Alukas – Luxury Jewelry Store WooCommerce WordPress Theme alukas Ashtanga - Yoga Studio WordPress Theme ashtanga Atomlab - Startup Landing Page WordPress Theme atomlab Avada | Website Builder For WordPress & WooCommerce Avada behold behold Bricks bricks Charity Zone charity-zone Château - Winery and Wine Shop WordPress Theme chateau EasyMeals - Food Blog WordPress Theme easymeals Ecommerce Zone ecommerce-zone Elementra - 100% Elementor WordPress Theme elementra EmallShop - Responsive WooCommerce WordPress Theme emallshop Esmée - Fashion Store WordPress Theme esme Kapee - Modern Multipurpose WooCommerce Theme kapee Kids Gift Shop kids-gift-shop Kids Online Store kids-online-store Learnify - Online Courses Education WordPress Theme learnify Léonie - Nail and Beauty Salon WordPress Theme lonie Manufaktur Solutions - Industry and Factory WordPress Theme manufaktursolutions Metro Magazine metro-magazine PressMart - Modern Elementor WooCommerce WordPress Theme presssmart Restaurant Zone restaurant-zone Roisin - Flower Shop and Florist WordPress Theme roisin TechLink - Technology and IT Solutions WordPress Theme techlink Valeska - Fashion eCommerce WordPress Theme valeska Webenvo webenvo Zoya - Minimal Blog Elementor Template Kit zoya Vulnerability Details Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize. Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-3844 Patch Status Patched Published Apr 22, 2026 Affected Software Breeze Cache [breeze] Researcher Hung Nguyen (bashu) More Details > Charity Zone <= 1.1.1 - Authenticated (Subscriber+) Arbitrary File Upload 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-40749 Patch Status Patched Published Apr 20, 2026 Affected Software Charity Zone [charity-zone] Researcher Denver Jackson More Details > Restaurant Zone <= 0.7.8 - Authenticated (Subscriber+) Arbitrary File Upload 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-40746 Patch Status Patched Published Apr 20, 2026 Affected Software Restaurant Zone [restaurant-zone] Researcher Denver Jackson More Details > Sendmachine for WordPress <= 1.0.20 - Unauthenticated SMTP Hijack to Privilege Escalation via manage_admin_requests 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-6235 Patch Status Unpatched Published Apr 21, 2026 Affected Software Sendmachine for WordPress [sendmachine] Researcher Nabil Irawan More Details > Contact Form Extender for Divi – Submissions DB & Extra Fields <= 1.0.6 - Unauthenticated Arbitrary File Deletion 9.1 CVSS Rating 9.1 (Critical) CVE-ID CVE-2026-40769 Patch Status Patched Published Apr 21, 2026 Affected Software Contact Form Extender for Divi – Submissions DB & Extra Fields [contact-form-extender-for-divi-builder] Researcher babyhack More Details > Create DB Tables <= 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Database Table Creation/Deletion via admin-post.php 9.1 CVSS Rating 9.1 (Critical) CVE-ID CVE-2026-4119 Patch Status Unpatched Published Apr 21, 2026 Affected Software Create DB Tables [create-db-tables] Researcher theviper17y More Details > Ecommerce Zone <= 0.9.7 - Authenticated (Subscriber+) Arbitrary File Upload 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-40747 Patch Status Patched Published Apr 20, 2026 Affected Software Ecommerce Zone [ecommerce-zone] Researcher Denver Jackson More Details > FunnelFormsPro <= 3.8.1 - Authenticated (Subscriber+) Remote Code Execution 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-39440 Patch Status Unpatched Published Apr 21, 2026 Affected Software FunnelFormsPro [Funnelforms-pro] Researcher 3ele / Sebastian Weiss More Details > GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content <= 1.2.2 - Unauthenticated Arbitrary File Upload 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-40772 Patch Status Patched Published Apr 21, 2026 Affected Software GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content [geeky-bot] Researcher Nguyen Ba Khanh More Details > Highland Software Custom Role Manager <= 1.0.0 - Authenticated (Subscriber+) Privilege Escalation 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-7106 Patch Status Patched Published Apr 26, 2026 Affected Software Highland Software Custom Role Manager [highland-software-custom-role-manager] Researcher 0xHerc More Details > Kids Gift Shop <= 0.5.4 - Authenticated (Subscriber+) Arbitrary File Upload 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-40748 Patch Status Patched Published Apr 20, 2026 Affected Software Kids Gift Shop [kids-gift-shop] Researcher Denver Jackson More Details > Kids Online Store <= 0.8.9 - Authenticated (Subscriber+) Arbitrary File Upload 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-40750 Patch Status Patched Published Apr 20, 2026 Affected Software Kids Online Store [kids-online-store] Researcher Denver Jackson More Details > Webenvo <= 0.0.6 - Authenticated (Subscriber+) Arbitrary File Upload 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-39589 Patch Status Patched Published Apr 20, 2026 Affected Software Webenvo [webenvo] Researcher Denver Jackson More Details > Alukas < 3.0.0 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-39445 Patch Status Patched Published Apr 22, 2026 Affected Software Alukas – Luxury Jewelry Store WooCommerce WordPress Theme [alukas] Researcher Phat RiO More Details > Ashtanga <= 1.2 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40751 Patch Status Patched Published Apr 20, 2026 Affected Software Ashtanga - Yoga Studio WordPress Theme [ashtanga] Researcher Denver Jackson More Details > Atomlab <= 2.4.5 - Unauthenticated Local File Inclusion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-39590 Patch Status Patched Published Apr 20, 2026 Affected Software Atomlab - Startup Landing Page WordPress Theme [atomlab] Researcher João Pedro Soares de Alcântara More Details > Behold <= 1.5 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40760 Patch Status Patched Published Apr 20, 2026 Affected Software behold [behold] Researcher Denver Jackson More Details > Château <= 1.2.1 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40757 Patch Status Patched Published Apr 20, 2026 Affected Software Château - Winery and Wine Shop WordPress Theme [chateau] Researcher Denver Jackson More Details > Drag and Drop File Upload for Contact Form 7 <= 1.1.3 - Unauthenticated Arbitrary File Upload via sanitize_file_name Bypass 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-5364 Patch Status Patched Published Apr 23, 2026 Affected Software Drag and Drop File Upload for Contact Form 7 [drag-and-drop-file-upload-for-contact-form-7] Researcher Thomas Sanzey More Details > EasyMeals <= 1.5.1 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40753 Patch Status Patched Published Apr 20, 2026 Affected Software EasyMeals - Food Blog WordPress Theme [easymeals] Researcher Denver Jackson More Details > Elementra - 100% Elementor WordPress Theme <= 1.0.9 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-39529 Patch Status Patched Published Apr 20, 2026 Affected Software Elementra - 100% Elementor WordPress Theme [elementra] Researcher Bonds More Details > EmallShop <= 2.4.21 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-39443 Patch Status Patched Published Apr 22, 2026 Affected Software EmallShop - Responsive WooCommerce WordPress Theme [emallshop] Researcher Phat RiO More Details > Esmée <= 1.4 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40759 Patch Status Patched Published Apr 20, 2026 Affected Software Esmée - Fashion Store WordPress Theme [esme] Researcher Denver Jackson More Details > Everest Forms <= 3.4.4 - Unauthenticated Arbitrary File Read and Deletion via Upload Field 'old_files' Parameter 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-5478 Patch Status Patched Published Apr 20, 2026 Affected Software Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder [everest-forms] Researcher ll More Details > Kapee < 1.7.0 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-39446 Patch Status Patched Published Apr 22, 2026 Affected Software Kapee - Modern Multipurpose WooCommerce Theme [kapee] Researcher Phat RiO More Details > Learnify - Online Courses Education WordPress Theme <= 1.15.0 - Unauthenticated Local File Inclusion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2025-60085 Patch Status Unpatched Published Apr 23, 2026 Affected Software Learnify - Online Courses Education WordPress Theme [learnify] Researcher Bonds More Details > Léonie <= 1.2.1 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40758 Patch Status Patched Published Apr 20, 2026 Affected Software Léonie - Nail and Beauty Salon WordPress Theme [lonie] Researcher Denver Jackson More Details > Link Library <= 7.8.8 - Authenticated (Contributor+) Arbitrary File Deletion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40779 Patch Status Patched Published Apr 22, 2026 Affected Software Link Library [link-library] Researcher Trương Hữu Phúc (truonghuuphuc) More Details > Manufaktur Solutions <= 1.1.1 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40752 Patch Status Patched Published Apr 20, 2026 Affected Software Manufaktur Solutions - Industry and Factory WordPress Theme [manufaktursolutions] Researcher Denver Jackson More Details > PressMart <= 1.2.26 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-39442 Patch Status Patched Published Apr 22, 2026 Affected Software PressMart - Modern Elementor WooCommerce WordPress Theme [presssmart] Researcher Phat RiO More Details > Roisin - Flower Shop and Florist WordPress Theme <= 1.4 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40754 Patch Status Patched Published Apr 20, 2026 Affected Software Roisin - Flower Shop and Florist WordPress Theme [roisin] Researcher Denver Jackson More Details > TechLink <= 1.3 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40755 Patch Status Patched Published Apr 20, 2026 Affected Software TechLink - Technology and IT Solutions WordPress Theme [techlink] Researcher Denver Jackson More Details > Valeska <= 1.2.2 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40761 Patch Status Patched Published Apr 20, 2026 Affected Software Valeska - Fashion eCommerce WordPress Theme [valeska] Researcher Denver Jackson More Details > wpForo Forum <= 3.0.5 - Authenticated (Subscriber+) Arbitrary File Deletion via Custom Profile Field File Path 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-6248 Patch Status Patched Published Apr 20, 2026 Affected Software wpForo Forum [wpforo] Researchers 0xd4rk5id3wackydawg More Details > Zoya <= 1.4 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-40756 Patch Status Patched Published Apr 20, 2026 Affected Software Zoya - Minimal Blog Elementor Template Kit [zoya] Researcher Denver Jackson More Details > Anti-Malware Security and Brute-Force Firewall <= 4.23.87 - Authenticated (Contributor+) PHP Object Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-39478 Patch Status Patched Published Apr 20, 2026 Affected Software Anti-Malware Security and Brute-Force Firewall [gotmls] Researcher daroo More Details > Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-40771 Patch Status Patched Published Apr 21, 2026 Affected Software Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe [contest-gallery] Researcher Trương Hữu Phúc (truonghuuphuc) More Details > Feed KuantoKusta for WooCommerce – Free <= 5.3 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-39441 Patch Status Patched Published Apr 22, 2026 Affected Software Feed KuantoKusta for WooCommerce – Free [feed-kuantokusta-for-woocommerce] Researcher TruongLV1 From FPT Night Wolf More Details > InPost Gallery <= 2.1.4.6 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-39574 Patch Status Patched Published Apr 20, 2026 Affected Software InPost Gallery [inpost-gallery] Researcher hivesec More Details > ListingPro Plugin <= 2.9.10 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-39438 Patch Status Patched Published Apr 21, 2026 Affected Software ListingPro Plugin [listingpro-plugin] Researcher Phat RiO More Details > Modula Image Gallery – Photo Grid & Video Gallery <= 2.14.18 - Authenticated (Author+) PHP Object Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-39481 Patch Status Patched Published Apr 20, 2026 Affected Software Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] Researcher daroo More Details > ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF <= 6.4.3 - Authenticated (Author+) PHP Object Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-39471 Patch Status Patched Published Apr 20, 2026 Affected Software ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF [shortpixel-image-optimiser] Researcher daroo More Details > WPGraphQL < 2.11.1 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-40762 Patch Status Patched Published Apr 21, 2026 Affected Software WPGraphQL [wp-graphql] Researcher daroo More Details > Chatbot for WordPress by Collect.chat <= 2.4.9 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-40765 Patch Status Patched Published Apr 21, 2026 Affected Software Chatbot for WordPress by Collect.chat [collectchat] Researcher Ritsuy More Details > Contact Form to Any API <= 3.0.3 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-39449 Patch Status Unpatched Published Apr 22, 2026 Affected Software Contact Form to Any API [contact-form-to-any-api] Researcher Saleh Elsayed (0xManticore) More Details > Coupon Affiliates – Affiliate Plugin for WooCommerce <= 7.5.3 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-40770 Patch Status Patched Published Apr 21, 2026 Affected Software Coupon Affiliates – Affiliate Plugin for WooCommerce [woo-coupon-usage] Researcher Nguyen Ba Khanh More Details > ExactMetrics <= 9.1.2 - Authenticated (Editor+) Arbitrary Plugin Installation/Activation via exactmetrics_connect_process 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-5464 Patch Status Patched Published Apr 22, 2026 Affected Software ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) [google-analytics-dashboard-for-wp] Researcher Nguyen Ngoc Duc (duc193) More Details > HTTP Headers <= 1.19.2 - Authenticated (Administrator+) External Control of File Name or Path to RCE via 'hh_htpasswd_path' and 'hh_www_authenticate_user' Parameters 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-4132 Patch Status Unpatched Published Apr 21, 2026 Affected Software HTTP Headers [http-headers] Researcher Chiao-Lin Yu (Steven Meow) More Details > Kapee < 1.7.1 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-41557 Patch Status Patched Published Apr 23, 2026 Affected Software Kapee - Modern Multipurpose WooCommerce Theme [kapee] Researcher Tran Nguyen Bao Khanh More Details > Notification for Telegram <= 3.5 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-40732 Patch Status Patched Published Apr 20, 2026 Affected Software Notification for Telegram [notification-for-telegram] Researcher Nguyen Ba Khanh More Details > Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 11.0.0 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-40787 Patch Status Patched Published Apr 23, 2026 Affected Software Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker [quiz-master-next] Researcher Jakub Herman More Details > Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.106.0 - Authenticated (Editor+) Remote Code Execution 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-39465 Patch Status Patched Published Apr 20, 2026 Affected Software Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] Researcher Marc-André Beaulieu (h3dg3h0g) More Details > WP Time Slots Booking Form <= 1.2.46 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-40791 Patch Status Patched Published Apr 23, 2026 Affected Software WP Time Slots Booking Form [wp-time-slots-booking-form] Researcher Daniel Wade More Details > Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 - Authenticated (Shop manager+) PHP Object Injection 6.6 CVSS Rating 6.6 (Medium) CVE-ID CVE-2026-39499 Patch Status Patched Published Apr 20, 2026 Affected Software Advanced Product Fields (Product Addons) for WooCommerce [advanced-product-fields-for-woocommerce] Researcher daroo More Details > PDF Invoices & Packing Slips for WooCommerce < 5.9.0 - Authenticated (Shop manager+) PHP Object Injection 6.6 CVSS Rating 6.6 (Medium) CVE-ID CVE-2026-39472 Patch Status Patched Published Apr 20, 2026 Affected Software PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] Researcher daroo More Details > Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.106.0 - Authenticated (Editor+) PHP Object Injection 6.6 CVSS Rating 6.6 (Medium) CVE-ID CVE-2026-39467 Patch Status Patched Published Apr 20, 2026 Affected Software Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] Researcher daroo More Details > YayMail – WooCommerce Email Customizer <= 4.3.3 - Authenticated (Shop manager+) PHP Object Injection 6.6 CVSS Rating 6.6 (Medium) CVE-ID CVE-2026-39498 Patch Status Patched Published Apr 20, 2026 Affected Software YayMail – WooCommerce Email Customizer [yaymail] Researcher daroo More Details > Breaking News WP <= 1.3 - Missing Authorization to Authenticated (Subscriber+) Local File Inclusion/Read 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-4280 Patch Status Unpatched Published Apr 21, 2026 Affected Software Breaking News WP [breaking-news-wp] Researcher t0ann9uy3n More Details > MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.25 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-40766 Patch Status Patched Published Apr 21, 2026 Affected Software MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] Researcher Jakub Herman More Details > Plugin: CMS für Motorrad Werkstätten <= 1.0.0 - Authenticated (Subscriber+) SQL Injection via 'arttype' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-6674 Patch Status Unpatched Published Apr 20, 2026 Affected Software Plugin: CMS für Motorrad Werkstätten [cms-fuer-motorrad-werkstaetten] Researcher Régis SENET More Details > WP Sessions Time Monitoring Full Automatic <= 1.1.4 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-39581 Patch Status Patched Published Apr 20, 2026 Affected Software WP Sessions Time Monitoring Full Automatic [activitytime] Researcher hivesec More Details > Bread & Butter: Content Gating for Verified Leads <= 8.2.0.25 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4279 Patch Status Unpatched Published Apr 21, 2026 Affected Software Bread & Butter: AI-Powered Lead Intelligence [bread-butter] Researcher Athiwat Tiprasaharn (Jitlada) More Details > CI HUB Connector <= 1.2.106 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4353 Patch Status Unpatched Published Apr 21, 2026 Affected Software CI HUB Connector [ci-hub-connector] Researcher zaim More Details > E-cab Taxi Booking Manager for Woocommerce <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-28040 Patch Status Patched Published Apr 23, 2026 Affected Software E-cab Taxi Booking Manager for Woocommerce [ecab-taxi-booking-manager] Researcher Muhammad Yudha - DJ More Details > Easy Social Photos Gallery <= 3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrapper_class' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4085 Patch Status Unpatched Published Apr 21, 2026 Affected Software Easy Social Photos Gallery – MIF [my-instagram-feed] Researcher Muhammad Yudha - DJ More Details > ER Swiffy Insert <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4082 Patch Status Unpatched Published Apr 21, 2026 Affected Software ER Swiffy Insert [er-swiffy-insert] Researcher Gilang - DJ More Details > Gallagher Website Design <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'prefix' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-1913 Patch Status Patched Published Apr 21, 2026 Affected Software Gallagher Website Design [gallagher-website-design] Researcher zaim More Details > Gutentools <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Slider Block Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-1395 Patch Status Patched Published Apr 21, 2026 Affected Software Gutentools [gutentools] Researchers Athiwat Tiprasaharn (Jitlada)Itthidej Aramsri (Boeing777) More Details > Image Source Control Lite – Show Image Credits and Captions <= 3.9.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'Image Source' Field 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4852 Patch Status Patched Published Apr 20, 2026 Affected Software Image Source Control Lite – Show Image Credits and Captions [image-source-control-isc] Researchers Athiwat Tiprasaharn (Jitlada)Vilaysone CHANTHAVONG (0xJ0cKkY) More Details > ITERAS <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4078 Patch Status Patched Published Apr 23, 2026 Affected Software ITERAS [iteras] Researcher Muhammad Yudha - DJ More Details > Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-41556 Patch Status Patched Published Apr 23, 2026 Affected Software Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress [wp-user-avatar] Researcher Niv Kochan More Details > Posts map <= 0.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'name' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-6236 Patch Status Unpatched Published Apr 21, 2026 Affected Software Posts map [posts-map] Researcher MAJidox More Details > Quran Live Multilanguage <= 1.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4074 Patch Status Unpatched Published Apr 21, 2026 Affected Software Quran Live Multilanguage [quran-live] Researcher Gilang - DJ More Details > Rescue Shortcodes <= 3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2025-62110 Patch Status Patched Published Apr 23, 2026 Affected Software Rescue Shortcodes [rescue-shortcodes] Researcher Nabil Irawan More Details > Royal Addons for Elementor <= 1.7.1056 - Authenticated (Author+) Stored Cross-Site Scripting via Image Caption Field 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-5428 Patch Status Patched Published Apr 23, 2026 Affected Software Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] Researcher Dmitrii Ignatyev More Details > Simple Random Posts Shortcode <= 0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'container_right_width' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-6246 Patch Status Unpatched Published Apr 21, 2026 Affected Software Simple Random Posts Shortcode [simple-random-posts-shortcode] Researcher MAJidox More Details > Slider Bootstrap Carousel <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4076 Patch Status Unpatched Published Apr 21, 2026 Affected Software Slider Bootstrap Carousel [slider-bootstrap-carousel] Researcher Gilang - DJ More Details > SlideShowPro SC <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'album' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-5767 Patch Status Unpatched Published Apr 21, 2026 Affected Software SlideShowPro SC [slideshowpro-shortcode] Researcher MAJidox More Details > Social Rocket – Social Sharing Plugin <= 1.3.4.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via id 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-1923 Patch Status Patched Published Apr 22, 2026 Affected Software Social Rocket – Social Sharing Plugin [social-rocket] Researcher Tarcísio Luchesi De Almeida Silva (Poystick) More Details > Switch CTA Box <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4088 Patch Status Unpatched Published Apr 21, 2026 Affected Software Switch CTA Box [switch-cta-box] Researcher Muhammad Yudha - DJ More Details > Text Snippets <= 0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'w' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-5748 Patch Status Unpatched Published Apr 21, 2026 Affected Software Text Snippets [text-snippet] Researcher MAJidox More Details > Twittee Text Tweet <= 1.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4089 Patch Status Unpatched Published Apr 21, 2026 Affected Software Twittee Text Tweet [twittee-text-tweet] Researcher zakaria More Details > WP Store Locator <= 2.2.261 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpsl_address' Post Meta 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-3361 Patch Status Patched Published Apr 22, 2026 Affected Software WP Store Locator [wp-store-locator] Researcher kai63001 More Details > WPMK Block <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4125 Patch Status Unpatched Published Apr 21, 2026 Affected Software WPMK Block [wpmk-block] Researcher zakaria More Details > Zypento Blocks <= 1.0.6 - Authenticated (Author+) Stored Cross-Site Scripting via Table of Contents Block 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-5820 Patch Status Unpatched Published Apr 21, 2026 Affected Software Zypento Blocks [zypento-blocks] Researcher Athiwat Tiprasaharn (Jitlada) More Details > Bricks <= 1.9.2 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-41554 Patch Status Patched Published Apr 23, 2026 Affected Software Bricks [bricks] Researcher w41bu1 More Details > GiveWP – Donation Plugin and Fundraising Platform <= 4.14.2 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-34900 Patch Status Patched Published Apr 21, 2026 Affected Software GiveWP – Donation Plugin and Fundraising Platform [give] Researcher HuajiHD More Details > Inquiry cart <= 3.4.2 - Cross-Site Request Forgery via Settings Form 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-4090 Patch Status Unpatched Published Apr 21, 2026 Affected Software Inquiry cart [inquiry-cart] Researcher Muhammad Nur Ibnu Hubab (Ibnu) More Details > Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-39437 Patch Status Patched Published Apr 21, 2026 Affected Software Min Max Step Quantity Limits Manager for WooCommerce [product-quantity-for-woocommerce] Researcher hivesec More Details > Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.17.3 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-39514 Patch Status Patched Published Apr 20, 2026 Affected Software Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction [paid-member-subscriptions] Researcher loris4py More Details > Website LLMs.txt <= 8.2.6 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-6711 Patch Status Patched Published Apr 20, 2026 Affected Software Website LLMs.txt [website-llms-txt] Researcher Kazuma Matsumoto More Details > WP Responsive Popup + Optin <= 1.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'wpo_image_url' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-4131 Patch Status Unpatched Published Apr 21, 2026 Affected Software WP Responsive Popup + Optin [wp-popup-optin] Researcher Muhammad Nur Ibnu Hubab (Ibnu) More Details > HTTP Headers <= 1.19.2 - Authenticated (Administrator+) CRLF Injection via Custom Header Values 5.5 CVSS Rating 5.5 (Medium) CVE-ID CVE-2026-2717 Patch Status Unpatched Published Apr 21, 2026 Affected Software HTTP Headers [http-headers] Researcher Kai Aizen More Details > Real Estate Pro <= 1.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting via Settings 5.5 CVSS Rating 5.5 (Medium) CVE-ID CVE-2026-1845 Patch Status Unpatched Published Apr 21, 2026 Affected Software Real Estate Pro [re-pro] Researcher Muhammad Nur Ibnu Hubab (Ibnu) More Details > Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutentor Block HTML 5.4 CVSS Rating 5.4 (Medium) CVE-ID CVE-2026-2951 Patch Status Patched Published Apr 22, 2026 Affected Software Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor [gutentor] Researcher Muhammad Yudha - DJ More Details > Booking Calendar Contact Form <= 1.2.63 - Authenticated (Subscriber+) Insecure Direct Object Reference to Calendar Takeover 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-6810 Patch Status Patched Published Apr 23, 2026 Affected Software Booking Calendar Contact Form [booking-calendar-contact-form] Researcher Md. Moniruzzaman Prodhan (NomanProdhan) More Details > Booking for Appointments and Events Calendar – Amelia <= 2.2 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-40789 Patch Status Patched Published Apr 23, 2026 Affected Software Booking for Appointments and Events Calendar – Amelia [ameliabooking] Researcher Weerawat Pawanawiwat (ErbaZZ) More Details > Booking Package <= 1.7.06 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-40774 Patch Status Patched Published Apr 21, 2026 Affected Software Booking Package [booking-package] Researcher Skoobi More Details > Bookit — Booking & Appointment Calendar <= 2.5.1 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-40780 Patch Status Patched Published Apr 22, 2026 Affected Software Bookit — Booking & Appointment Calendar [bookit] Researcher davidfdzmorilla More Details > CalJ <= 1.5 - Authenticated (Subscriber+) Arbitrary Settings Modification via 'save-obtained-key' Action 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-4117 Patch Status Unpatched Published Apr 21, 2026 Affected Software CalJ Shabbat Times [calj] Researcher Nabil Irawan More Details > Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.6.5 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-39503 Patch Status Patched Published Apr 20, 2026 Affected Software Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] Researcher Jakub Herman More Details > Essential Addons for Elementor – Popular Elementor Templates & Widgets < 6.6.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-25440 Patch Status Patched Published Apr 22, 2026 Affected Software Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] Researcher Que Thanh Tuan More Details > ExactMetrics <= 9.1.2 - Authenticated (Subscriber+) Missing Authorization to Google Ads Access Token Retrieval via AJAX Action 'exactmetrics_ads_get_token' 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-5488 Patch Status Patched Published Apr 23, 2026 Affected Software ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) [google-analytics-dashboard-for-wp] Researcher Dmitrii Ignatyev More Details > HT Mega Addons for Elementor – Elementor Widgets & Template Builder < 3.0.7 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-4106 Patch Status Patched Published Apr 24, 2026 Affected Software HT Mega Addons for Elementor – Elementor Widgets & Template Builder [ht-mega-for-elementor] Researcher Chiao-Lin Yu (Steven Meow) More Details > Jupiter X Core <= 4.14.1 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-39490 Patch Status Patched Published Apr 20, 2026 Affected Software Jupiter X Core [jupiterx-core] Researcher hivesec More Details > Liaison Site Prober <= 1.2.1 - Missing Authorization to Unauthenticated Information Exposure in '/logs' REST API Endpoint 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-3569 Patch Status Patched Published Apr 23, 2026 Affected Software Liaison Site Prober [liaison-site-prober] Researcher Itthidej Aramsri (Boeing777) More Details > MasterStudy LMS Pro < 4.7.16 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2025-64215 Patch Status Patched Published Apr 23, 2026 Affected Software MasterStudy LMS Pro [masterstudy-lms-learning-management-system-pro] Researcher Rafie Muhammad More Details > Maxi Blocks <= 2.1.8 - Missing Authorization to Authenticated (Author+) Media File Deletion via 'old_media_src' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-2028 Patch Status Patched Published Apr 23, 2026 Affected Software MaxiBlocks Builder | 17,000+ Design Assets, Patterns, Icons & Starter Sites [maxi-blocks] Researcher Teerachai Somprasong More Details > Metro Magazine <= 1.4.1 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-40809 Patch Status Patched Published Apr 23, 2026 Affected Software Metro Magazine [metro-magazine] Researcher Trương Hữu Phúc (truonghuuphuc) More Details > Responsive Blocks <= 2.2.0 - Unauthenticated Open Email Relay via REST API 'email_to' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-6675 Patch Status Patched Published Apr 20, 2026 Affected Software Responsive Blocks – Page Builder for Blocks & Patterns [responsive-block-editor-addons] Researcher Even Stokkedalen More Details > ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema <= 2.3.6 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-40781 Patch Status Patched Published Apr 22, 2026 Affected Software ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema [reviewx] Researcher Jakub Herman More Details > Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini <= 1.4.2 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-40775 Patch Status Patched Published Apr 21, 2026 Affected Software Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini [royal-mcp] Researcher Alexis Lafontaine More Details > Salon Booking System – Free Version <= 10.30.24 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-40768 Patch Status Patched Published Apr 21, 2026 Affected Software Salon Booking System – Free Version [salon-booking-system] Researcher Lubin Regnault More Details > Tutor LMS – eLearning and online course solution <= 3.9.7 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-40743 Patch Status Patched Published Apr 20, 2026 Affected Software Tutor LMS – eLearning and online course solution [tutor] Researcher lagi bljr More Details > WP Books Gallery <= 4.8.0 - Missing Authorization to Unauthenticated Settings Update via 'permalink_structure' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-5347 Patch Status Patched Published Apr 23, 2026 Affected Software WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes [wp-books-gallery] Researcher Legion Hunter More Details > WPAdverts – Classifieds Plugin <= 2.3.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-40782 Patch Status Patched Published Apr 22, 2026 Affected Software WPAdverts – Classifieds Plugin [wpadverts] Researcher TheNetRunner Security Research More Details > wpForo Forum < 3.0.2 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-40767 Patch Status Patched Published Apr 21, 2026 Affected Software wpForo Forum [wpforo] Researcher Dahmani Toumi (pegaSUS) More Details > wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 6.5.0.4 - Unauthenticated Stored Cross-Site Scripting via CSV/Excel Data Import 4.7 CVSS Rating 4.7 (Medium) CVE-ID CVE-2026-5721 Patch Status Patched Published Apr 20, 2026 Affected Software wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables] Researcher Lio More Details > Buzz Comments <= 0.9.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Custom Buzz Avatar' Setting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-6041 Patch Status Unpatched Published Apr 21, 2026 Affected Software Buzz Comments [buzz-comments] Researcher Muhammad Nur Ibnu Hubab (Ibnu) More Details > Email Encoder – Protect Email Addresses and Phone Numbers < 2.3.4 - Authenticated (Administrator+) Stored Cross-Site Scripting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2024-7083 Patch Status Patched Published Apr 21, 2026 Affected Software Email Encoder – Protect Email Addresses and Phone Numbers [email-encoder-bundle] Researcher Dmitrii Ignatyev More Details > HTTP Headers <= 1.19.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Custom Headers' Plugin Setting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-1379 Patch Status Unpatched Published Apr 21, 2026 Affected Software HTTP Headers [http-headers] Researcher Daniel Basta (whizzu) More Details > Private WP suite <= 0.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Exceptions' Setting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-2719 Patch Status Unpatched Published Apr 21, 2026 Affected Software Private WP suite [private-wp-suite] Researcher Muhammad Nur Ibnu Hubab (Ibnu) More Details > reCaptcha by WebDesignBy < 2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-4512 Patch Status Patched Published Apr 24, 2026 Affected Software reCaptcha by WebDesignBy [webdesignby-recaptcha] Researcher Mustafa More Details > Sentence To SEO (keywords, description and tags) <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Permanent keywords' Field 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-4142 Patch Status Unpatched Published Apr 21, 2026 Affected Software Sentence To SEO (keywords, description and tags) [sentence-to-seo] Researcher Muhammad Nur Ibnu Hubab (Ibnu) More Details > Short Comment Filter <= 2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Minimum Count' Setting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-3362 Patch Status Unpatched Published Apr 21, 2026 Affected Software Short Comment Filter [short-comment-filter] Researcher Muhammad Nur Ibnu Hubab (Ibnu) More Details > Website LLMs.txt <= 8.2.6 - Authenticated (Admin+) Stored Cross-Site Scripting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-6712 Patch Status Patched Published Apr 20, 2026 Affected Software Website LLMs.txt [website-llms-txt] Researcher Kazuma Matsumoto More Details > ACF Galerie 4 <= 1.4.2 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2025-62104 Patch Status Patched Published Apr 23, 2026 Affected Software ACF Galerie 4 [acf-galerie-4] Researcher Nabil Irawan More Details > AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.6.7 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-40785 Patch Status Patched Published Apr 23, 2026 Affected Software AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress [automatorwp] Researcher Jakub Herman More Details > Avada < 7.13.2 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2025-58922 Patch Status Patched Published Apr 22, 2026 Affected Software Avada | Website Builder For WordPress & WooCommerce [Avada] Researcher João Pedro Soares de Alcântara More Details > BetterDocs <= 4.3.11 - Missing Authorization to Authenticated (Subscriber+) Unauthorized AI API Usage 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-6393 Patch Status Patched Published Apr 23, 2026 Affected Software BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor [betterdocs] Researcher h0xilo More Details > Blocksy Companion Pro <= 2.1.37 - Authenticated (Contributor+) Remote Code Execution 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-40783 Patch Status Patched Published Apr 22, 2026 Affected Software Blocksy Companion Pro [blocksy-companion-pro] Researcher Nguyen Ba Khanh More Details > Bookify – Appointment Booking & Scheduling for WordPress <= 1.1.1 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2025-69332 Patch Status Patched Published Apr 23, 2026 Affected Software Bookify – Appointment Booking & Scheduling for WordPress [bookify] Researcher benzdeus More Details > Call To Action Plugin <= 3.1.3 - Cross-Site Request Forgery via Settings Update 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-4118 Patch Status Unpatched Published Apr 21, 2026 Affected Software Call To Action Plugin [call-to-action-plugin] Researcher afnaan More Details > Download Monitor <= 5.1.9 - Authenticated (Author+) Arbitrary File Download 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-39489 Patch Status Patched Published Apr 20, 2026 Affected Software Download Monitor [download-monitor] Researcher daroo More Details > DX Unanswered Comments <= 1.7 - Cross-Site Request Forgery via Settings Update 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-4138 Patch Status Unpatched Published Apr 21, 2026 Affected Software DX Unanswered Comments [dx-unanswered-comments] Researcher afnaan More Details > Emailchef <= 3.5.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-1930 Patch Status Patched Published Apr 21, 2026 Affected Software Emailchef [emailchef] Researcher Legion Hunter More Details > EventPrime – Events Calendar, Bookings and Tickets <= 4.3.0.0 - Authenticated (Subscriber+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-39518 Patch Status Patched Published Apr 20, 2026 Affected Software EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] Researcher James Pirstin More Details > Fast & Fancy Filter – 3F <= 1.2.2 - Cross-Site Request Forgery to Settings Modification via fff_save_settins AJAX Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-6396 Patch Status Unpatched Published Apr 21, 2026 Affected Software Fast & Fancy Filter – 3F [fast-fancy-filter-3f] Researcher Muhammad Nur Ibnu Hubab (Ibnu) More Details > FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.7.3 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-39450 Patch Status Patched Published Apr 22, 2026 Affected Software FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce [wp-marketing-automations] Researcher Jakub Herman More Details > Google PageRank Display <= 1.4 - Cross-Site Request Forgery to Settings Update via Settings Page 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-6294 Patch Status Unpatched Published Apr 21, 2026 Affected Software Google PageRank Display [google-pagerank-display] Researcher Muhammad Nur Ibnu Hubab (Ibnu) More Details > Groundhogg — CRM, Newsletters, and Marketing Automation < 4.4.1 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-40793 Patch Status Patched Published Apr 24, 2026 Affected Software Groundhogg — CRM, Newsletters, and Marketing Automation [groundhogg] Researcher Jakub Herman More Details > HubSpot All-In-One Marketing - Forms, Popups, Live Chat <= 11.3.32 - Missing Authorization to Authenticated (Contributor+) Installed Plugin Disclosure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2025-11762 Patch Status Patched Published Apr 23, 2026 Affected Software HubSpot All-In-One Marketing – Forms, Popups, Live Chat [leadin] Researcher Dmitrii Ignatyev More Details > Kcaptcha <= 1.0.1 - Cross-Site Request Forgery to Settings Update 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-4121 Patch Status Unpatched Published Apr 21, 2026 Affected Software Kcaptcha [kcaptcha] Researcher afnaan More Details > KiviCare – Clinic & Patient Management System (EHR) <= 4.2.1 - Authenticated (Subscriber+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-40792 Patch Status Patched Published Apr 23, 2026 Affected Software KiviCare – Clinic & Patient Management System (EHR) [kivicare-clinic-management-system] Researcher Jakub Herman More Details > mCatFilter <= 0.5.2 - Cross-Site Request Forgery via compute_post() Function 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-4139 Patch Status Unpatched Published Apr 21, 2026 Affected Software mCatFilter [mcatfilter] Researcher afnaan More Details > Motors – Car Dealership & Classified Listings Plugin < 1.4.107 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-39515 Patch Status Patched Published Apr 21, 2026 Affected Software Motors – Car Dealership & Classified Listings Plugin [motors-car-dealership-classified-listings] Researcher Jakub Herman More Details > Ni WooCommerce Order Export <= 3.1.6 - Cross-Site Request Forgery to Settings Update via ni_order_export_action AJAX Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-4140 Patch Status Unpatched Published Apr 21, 2026 Affected Software Ni WooCommerce Order Export [ni-woocommerce-order-export] Researcher afnaan More Details > Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred <= 3.0.3 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-40794 Patch Status Patched Published Apr 24, 2026 Affected Software Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred [mycred] Researcher Jakub Herman More Details > RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress <= 4.1132 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-39584 Patch Status Patched Published Apr 20, 2026 Affected Software RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress [computer-repair-shop] Researcher Trương Hữu Phúc (truonghuuphuc) More Details > Responsive Blocks <= 2.2.1 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via AJAX Actions 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-6703 Patch Status Patched Published Apr 20, 2026 Affected Software Responsive Blocks – Page Builder for Blocks & Patterns [responsive-block-editor-addons] Researcher Even Stokkedalen More Details > rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-40773 Patch Status Patched Published Apr 21, 2026 Affected Software rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] Researcher Jakub Herman More Details > Table Manager <= 1.0.0 - Authenticated (Contributor+) Sensitive Information Exposure via 'table' Shortcode Attribute 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-4126 Patch Status Unpatched Published Apr 21, 2026 Affected Software Table Manager [table-manager] Researcher Itthidej Aramsri (Boeing777) More Details > Taqnix <= 1.0.3 - Cross-Site Request Forgery to Account Deletion via 'taqnix_delete_my_account' AJAX Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-3565 Patch Status Patched Published Apr 23, 2026 Affected Software Taqnix [taqnix] Researcher theviper17y More Details > TextP2P Texting Widget <= 1.7 - Cross-Site Request Forgery to Settings Update 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-4133 Patch Status Unpatched Published Apr 21, 2026 Affected Software TextP2P Texting Widget [textp2p-texting-widget] Researcher afnaan More Details > TP Restore Categories And Taxonomies <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Taxonomy Deletion via 'tpmcattt_delete_term' AJAX Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-4128 Patch Status Unpatched Published Apr 21, 2026 Affected Software TP Restore Categories And Taxonomies [tp-restore-categories-and-taxonomies] Researcher Nabil Irawan More Details > WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 7.9.7 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-40788 Patch Status Patched Published Apr 23, 2026 Affected Software WPBot – AI ChatBot for Live Support, Lead Generation, AI Services [chatbot] Researcher Mehdi Ouassou More Details > WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce <= 7.2.1 - Authenticated (Subscriber+) Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-40790 Patch Status Patched Published Apr 23, 2026 Affected Software WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce [wp-sms] Researcher Jakub Herman More Details > As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence. This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can. Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. The post Wordfence Intelligence Weekly WordPress Vulnerability Report (April 20, 2026 to April 26, 2026) appeared first on Wordfence.
Quelle: www.wordfence.com