Wordfence Intelligence Weekly WordPress Vulnerability Report (April 20, 2026 to April 26, 2026)
Autor: Chloe Chamberland
⚠️ CVE-Referenzen:
CVE-2026-6674
CVE-2026-25440
CVE-2026-40762
CVE-2026-4106
CVE-2026-39490
CVE-2026-3569
CVE-2026-40783
CVE-2026-40785
CVE-2025-64215
CVE-2026-39503
CVE-2026-5428
CVE-2026-40748
CVE-2026-40757
CVE-2026-39467
CVE-2024-7083
CVE-2026-39498
CVE-2025-62110
CVE-2025-60085
CVE-2026-4074
CVE-2026-40788
CVE-2026-40772
CVE-2026-40787
CVE-2026-4085
CVE-2026-6041
CVE-2026-2951
CVE-2026-2028
CVE-2026-4138
CVE-2026-40754
CVE-2026-39574
CVE-2026-4089
CVE-2026-40732
CVE-2026-39514
CVE-2026-5347
CVE-2026-40758
CVE-2025-62104
CVE-2026-39481
CVE-2026-5767
CVE-2026-40779
CVE-2026-6294
CVE-2026-4090
CVE-2026-2717
CVE-2026-40755
CVE-2026-40789
CVE-2026-6235
CVE-2026-39589
CVE-2026-4279
CVE-2026-3362
CVE-2026-39465
CVE-2026-39584
CVE-2026-4126
CVE-2026-4512
CVE-2026-40743
CVE-2026-4082
CVE-2026-5464
CVE-2026-39437
CVE-2026-3565
CVE-2026-39590
CVE-2026-40759
CVE-2026-1395
CVE-2026-6675
CVE-2026-4280
CVE-2026-40773
CVE-2026-40761
CVE-2026-39446
CVE-2026-1930
CVE-2026-39449
CVE-2026-40793
CVE-2026-4133
CVE-2025-69332
CVE-2026-40790
CVE-2026-5478
CVE-2026-7106
CVE-2026-6703
CVE-2026-39581
CVE-2026-5364
CVE-2026-39478
CVE-2026-6236
CVE-2026-6246
CVE-2026-40752
CVE-2026-4139
CVE-2026-40749
CVE-2026-39529
CVE-2026-39450
CVE-2026-1923
CVE-2026-39440
CVE-2026-5820
CVE-2026-39515
CVE-2026-5721
CVE-2026-40781
CVE-2026-2719
CVE-2026-3361
CVE-2026-4128
CVE-2026-40791
CVE-2026-4078
CVE-2026-1845
CVE-2026-40768
CVE-2026-40767
CVE-2026-4140
CVE-2026-4132
CVE-2026-41557
CVE-2026-4076
CVE-2026-40775
CVE-2026-5748
CVE-2026-40769
CVE-2026-4353
CVE-2026-40780
CVE-2026-40809
CVE-2026-40750
CVE-2025-11762
CVE-2026-41556
CVE-2026-3844
CVE-2026-34900
CVE-2026-4121
CVE-2026-40760
CVE-2026-40753
CVE-2026-39472
CVE-2026-6711
CVE-2026-40774
CVE-2026-40792
CVE-2026-39441
CVE-2026-6393
CVE-2026-39438
CVE-2026-40746
CVE-2026-40794
CVE-2026-40756
CVE-2026-1379
CVE-2026-40765
CVE-2026-40782
CVE-2026-6248
CVE-2026-40770
CVE-2026-4118
CVE-2026-39518
CVE-2026-4117
CVE-2026-39443
CVE-2026-4088
CVE-2026-40751
CVE-2026-39442
CVE-2026-39499
CVE-2026-6810
CVE-2026-5488
CVE-2026-40766
CVE-2026-4852
CVE-2026-1913
CVE-2026-40747
CVE-2026-4142
CVE-2026-39445
CVE-2026-4125
CVE-2026-39489
CVE-2026-39471
CVE-2026-28040
CVE-2026-6712
CVE-2026-4119
CVE-2026-6396
CVE-2026-41554
CVE-2026-40771
CVE-2025-58922
CVE-2026-4131
Last week, there were 157 vulnerabilities disclosed in 122 WordPress Plugins and 27 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 69 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 35,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
WAF-RULE-908 – Data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status
Number of Vulnerabilities
Patched
115
Unpatched
42
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating
Number of Vulnerabilities
Medium Severity
104
High Severity
47
Critical Severity
6
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE
Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
47
Missing Authorization
34
Deserialization of Untrusted Data
23
Cross-Site Request Forgery (CSRF)
12
Unrestricted Upload of File with Dangerous Type
9
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
8
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
6
Exposure of Sensitive Information to an Unauthorized Actor
5
Authorization Bypass Through User-Controlled Key
4
Improper Control of Generation of Code ('Code Injection')
3
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
2
External Control of File Name or Path
1
Improper Input Validation
1
Improper Neutralization of CRLF Sequences ('CRLF Injection')
1
Improper Privilege Management
1
Researchers That Contributed to WordPress Security Last Week
Researcher Name
Number of Vulnerabilities
Denver Jackson
17
Jakub Herman
12
Muhammad Nur Ibnu Hubab (Ibnu)
9
daroo
9
afnaan
6
Muhammad Yudha - DJ
5
Phat RiO
5
Nabil Irawan
5
Athiwat Tiprasaharn (Jitlada)
4
hivesec
4
Dmitrii Ignatyev
4
MAJidox
4
Nguyen Ba Khanh
4
Trương Hữu Phúc (truonghuuphuc)
4
Gilang - DJ
3
Itthidej Aramsri (Boeing777)
3
Legion Hunter
2
Even Stokkedalen
2
Kazuma Matsumoto
2
Bonds
2
zakaria
2
theviper17y
2
João Pedro Soares de Alcântara
2
Chiao-Lin Yu (Steven Meow)
2
zaim
2
3ele / Sebastian Weiss
1
Daniel Basta (whizzu)
1
Thomas Sanzey
1
Nguyen Ngoc Duc (duc193)
1
Marc-André Beaulieu (h3dg3h0g)
1
Rafie Muhammad
1
Skoobi
1
TruongLV1 From FPT Night Wolf
1
HuajiHD
1
h0xilo
1
t0ann9uy3n
1
Dahmani Toumi (pegaSUS)
1
loris4py
1
Weerawat Pawanawiwat (ErbaZZ)
1
Alexis Lafontaine
1
Kai Aizen
1
James Pirstin
1
0xd4rk5id3
1
wackydawg
1
w41bu1
1
0xHerc
1
ll
1
Lio
1
TheNetRunner Security Research
1
Lubin Regnault
1
Daniel Wade
1
Que Thanh Tuan
1
Md. Moniruzzaman Prodhan (NomanProdhan)
1
Mehdi Ouassou
1
Régis SENET
1
kai63001
1
babyhack
1
Ritsuy
1
Niv Kochan
1
davidfdzmorilla
1
Tarcísio Luchesi De Almeida Silva (Poystick)
1
Vilaysone CHANTHAVONG (0xJ0cKkY)
1
Hung Nguyen (bashu)
1
lagi bljr
1
Tran Nguyen Bao Khanh
1
Mustafa
1
Teerachai Somprasong
1
Saleh Elsayed (0xManticore)
1
benzdeus
1
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name
Software Slug
ACF Galerie 4
acf-galerie-4
Advanced Product Fields (Product Addons) for WooCommerce
advanced-product-fields-for-woocommerce
Anti-Malware Security and Brute-Force Firewall
gotmls
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress
automatorwp
BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor
betterdocs
Blocksy Companion Pro
blocksy-companion-pro
Bookify – Appointment Booking & Scheduling for WordPress
bookify
Booking Calendar Contact Form
booking-calendar-contact-form
Booking for Appointments and Events Calendar – Amelia
ameliabooking
Booking Package
booking-package
Bookit — Booking & Appointment Calendar
bookit
Bread & Butter: AI-Powered Lead Intelligence
bread-butter
Breaking News WP
breaking-news-wp
Breeze Cache
breeze
Buzz Comments
buzz-comments
CalJ Shabbat Times
calj
Call To Action Plugin
call-to-action-plugin
Chatbot for WordPress by Collect.chat
collectchat
CI HUB Connector
ci-hub-connector
Contact Form Extender for Divi – Submissions DB & Extra Fields
contact-form-extender-for-divi-builder
Contact Form to Any API
contact-form-to-any-api
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe
contest-gallery
Coupon Affiliates – Affiliate Plugin for WooCommerce
woo-coupon-usage
Create DB Tables
create-db-tables
Download Monitor
download-monitor
Drag and Drop File Upload for Contact Form 7
drag-and-drop-file-upload-for-contact-form-7
DX Unanswered Comments
dx-unanswered-comments
E-cab Taxi Booking Manager for Woocommerce
ecab-taxi-booking-manager
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
easy-digital-downloads
Easy Social Photos Gallery – MIF
my-instagram-feed
Email Encoder – Protect Email Addresses and Phone Numbers
email-encoder-bundle
Emailchef
emailchef
ER Swiffy Insert
er-swiffy-insert
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
EventPrime – Events Calendar, Bookings and Tickets
eventprime-event-calendar-management
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder
everest-forms
ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)
google-analytics-dashboard-for-wp
Fast & Fancy Filter – 3F
fast-fancy-filter-3f
Feed KuantoKusta for WooCommerce – Free
feed-kuantokusta-for-woocommerce
FunnelFormsPro
Funnelforms-pro
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce
wp-marketing-automations
Gallagher Website Design
gallagher-website-design
GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content
geeky-bot
GiveWP – Donation Plugin and Fundraising Platform
give
Google PageRank Display
google-pagerank-display
Groundhogg — CRM, Newsletters, and Marketing Automation
groundhogg
Gutentools
gutentools
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor
gutentor
Highland Software Custom Role Manager
highland-software-custom-role-manager
HT Mega Addons for Elementor – Elementor Widgets & Template Builder
ht-mega-for-elementor
HTTP Headers
http-headers
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
Image Source Control Lite – Show Image Credits and Captions
image-source-control-isc
InPost Gallery
inpost-gallery
Inquiry cart
inquiry-cart
ITERAS
iteras
Jupiter X Core
jupiterx-core
Kcaptcha
kcaptcha
KiviCare – Clinic & Patient Management System (EHR)
kivicare-clinic-management-system
Liaison Site Prober
liaison-site-prober
Link Library
link-library
ListingPro Plugin
listingpro-plugin
MasterStudy LMS Pro
masterstudy-lms-learning-management-system-pro
MasterStudy LMS WordPress Plugin – for Online Courses and Education
masterstudy-lms-learning-management-system
MaxiBlocks Builder | 17,000+ Design Assets, Patterns, Icons & Starter Sites
maxi-blocks
mCatFilter
mcatfilter
Min Max Step Quantity Limits Manager for WooCommerce
product-quantity-for-woocommerce
Modula Image Gallery – Photo Grid & Video Gallery
modula-best-grid-gallery
Motors – Car Dealership & Classified Listings Plugin
motors-car-dealership-classified-listings
Ni WooCommerce Order Export
ni-woocommerce-order-export
Notification for Telegram
notification-for-telegram
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
wp-user-avatar
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
paid-member-subscriptions
PDF Invoices & Packing Slips for WooCommerce
woocommerce-pdf-invoices-packing-slips
Plugin: CMS für Motorrad Werkstätten
cms-fuer-motorrad-werkstaetten
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred
mycred
Posts map
posts-map
Private WP suite
private-wp-suite
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker
quiz-master-next
Quran Live Multilanguage
quran-live
Real Estate Pro
re-pro
reCaptcha by WebDesignBy
webdesignby-recaptcha
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress
computer-repair-shop
Rescue Shortcodes
rescue-shortcodes
Responsive Blocks – Page Builder for Blocks & Patterns
responsive-block-editor-addons
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Royal Addons for Elementor – Addons and Templates Kit for Elementor
royal-elementor-addons
Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini
royal-mcp
rtMedia for WordPress, BuddyPress and bbPress
buddypress-media
Salon Booking System – Free Version
salon-booking-system
Sendmachine for WordPress
sendmachine
Sentence To SEO (keywords, description and tags)
sentence-to-seo
Short Comment Filter
short-comment-filter
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF
shortpixel-image-optimiser
Simple Random Posts Shortcode
simple-random-posts-shortcode
Slider Bootstrap Carousel
slider-bootstrap-carousel
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider
ml-slider
SlideShowPro SC
slideshowpro-shortcode
Social Rocket – Social Sharing Plugin
social-rocket
Switch CTA Box
switch-cta-box
Table Manager
table-manager
Taqnix
taqnix
Text Snippets
text-snippet
TextP2P Texting Widget
textp2p-texting-widget
TP Restore Categories And Taxonomies
tp-restore-categories-and-taxonomies
Tutor LMS – eLearning and online course solution
tutor
Twittee Text Tweet
twittee-text-tweet
Website LLMs.txt
website-llms-txt
WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes
wp-books-gallery
WP Responsive Popup + Optin
wp-popup-optin
WP Sessions Time Monitoring Full Automatic
activitytime
WP Store Locator
wp-store-locator
WP Time Slots Booking Form
wp-time-slots-booking-form
WPAdverts – Classifieds Plugin
wpadverts
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services
chatbot
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin
wpdatatables
wpForo Forum
wpforo
WPGraphQL
wp-graphql
WPMK Block
wpmk-block
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
YayMail – WooCommerce Email Customizer
yaymail
Zypento Blocks
zypento-blocks
WordPress Themes with Reported Vulnerabilities Last Week
Software Name
Software Slug
Alukas – Luxury Jewelry Store WooCommerce WordPress Theme
alukas
Ashtanga - Yoga Studio WordPress Theme
ashtanga
Atomlab - Startup Landing Page WordPress Theme
atomlab
Avada | Website Builder For WordPress & WooCommerce
Avada
behold
behold
Bricks
bricks
Charity Zone
charity-zone
Château - Winery and Wine Shop WordPress Theme
chateau
EasyMeals - Food Blog WordPress Theme
easymeals
Ecommerce Zone
ecommerce-zone
Elementra - 100% Elementor WordPress Theme
elementra
EmallShop - Responsive WooCommerce WordPress Theme
emallshop
Esmée - Fashion Store WordPress Theme
esme
Kapee - Modern Multipurpose WooCommerce Theme
kapee
Kids Gift Shop
kids-gift-shop
Kids Online Store
kids-online-store
Learnify - Online Courses Education WordPress Theme
learnify
Léonie - Nail and Beauty Salon WordPress Theme
lonie
Manufaktur Solutions - Industry and Factory WordPress Theme
manufaktursolutions
Metro Magazine
metro-magazine
PressMart - Modern Elementor WooCommerce WordPress Theme
presssmart
Restaurant Zone
restaurant-zone
Roisin - Flower Shop and Florist WordPress Theme
roisin
TechLink - Technology and IT Solutions WordPress Theme
techlink
Valeska - Fashion eCommerce WordPress Theme
valeska
Webenvo
webenvo
Zoya - Minimal Blog Elementor Template Kit
zoya
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-3844
Patch Status
Patched
Published
Apr 22, 2026
Affected Software
Breeze Cache [breeze]
Researcher
Hung Nguyen (bashu)
More Details >
Charity Zone <= 1.1.1 - Authenticated (Subscriber+) Arbitrary File Upload
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-40749
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Charity Zone [charity-zone]
Researcher
Denver Jackson
More Details >
Restaurant Zone <= 0.7.8 - Authenticated (Subscriber+) Arbitrary File Upload
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-40746
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Restaurant Zone [restaurant-zone]
Researcher
Denver Jackson
More Details >
Sendmachine for WordPress <= 1.0.20 - Unauthenticated SMTP Hijack to Privilege Escalation via manage_admin_requests
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-6235
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Sendmachine for WordPress [sendmachine]
Researcher
Nabil Irawan
More Details >
Contact Form Extender for Divi – Submissions DB & Extra Fields <= 1.0.6 - Unauthenticated Arbitrary File Deletion
9.1
CVSS Rating
9.1 (Critical)
CVE-ID
CVE-2026-40769
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
Contact Form Extender for Divi – Submissions DB & Extra Fields [contact-form-extender-for-divi-builder]
Researcher
babyhack
More Details >
Create DB Tables <= 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Database Table Creation/Deletion via admin-post.php
9.1
CVSS Rating
9.1 (Critical)
CVE-ID
CVE-2026-4119
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Create DB Tables [create-db-tables]
Researcher
theviper17y
More Details >
Ecommerce Zone <= 0.9.7 - Authenticated (Subscriber+) Arbitrary File Upload
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-40747
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Ecommerce Zone [ecommerce-zone]
Researcher
Denver Jackson
More Details >
FunnelFormsPro <= 3.8.1 - Authenticated (Subscriber+) Remote Code Execution
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-39440
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
FunnelFormsPro [Funnelforms-pro]
Researcher
3ele / Sebastian Weiss
More Details >
GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content <= 1.2.2 - Unauthenticated Arbitrary File Upload
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-40772
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content [geeky-bot]
Researcher
Nguyen Ba Khanh
More Details >
Highland Software Custom Role Manager <= 1.0.0 - Authenticated (Subscriber+) Privilege Escalation
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-7106
Patch Status
Patched
Published
Apr 26, 2026
Affected Software
Highland Software Custom Role Manager [highland-software-custom-role-manager]
Researcher
0xHerc
More Details >
Kids Gift Shop <= 0.5.4 - Authenticated (Subscriber+) Arbitrary File Upload
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-40748
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Kids Gift Shop [kids-gift-shop]
Researcher
Denver Jackson
More Details >
Kids Online Store <= 0.8.9 - Authenticated (Subscriber+) Arbitrary File Upload
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-40750
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Kids Online Store [kids-online-store]
Researcher
Denver Jackson
More Details >
Webenvo <= 0.0.6 - Authenticated (Subscriber+) Arbitrary File Upload
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-39589
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Webenvo [webenvo]
Researcher
Denver Jackson
More Details >
Alukas < 3.0.0 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-39445
Patch Status
Patched
Published
Apr 22, 2026
Affected Software
Alukas – Luxury Jewelry Store WooCommerce WordPress Theme [alukas]
Researcher
Phat RiO
More Details >
Ashtanga <= 1.2 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40751
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Ashtanga - Yoga Studio WordPress Theme [ashtanga]
Researcher
Denver Jackson
More Details >
Atomlab <= 2.4.5 - Unauthenticated Local File Inclusion
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-39590
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Atomlab - Startup Landing Page WordPress Theme [atomlab]
Researcher
João Pedro Soares de Alcântara
More Details >
Behold <= 1.5 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40760
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
behold [behold]
Researcher
Denver Jackson
More Details >
Château <= 1.2.1 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40757
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Château - Winery and Wine Shop WordPress Theme [chateau]
Researcher
Denver Jackson
More Details >
Drag and Drop File Upload for Contact Form 7 <= 1.1.3 - Unauthenticated Arbitrary File Upload via sanitize_file_name Bypass
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-5364
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
Drag and Drop File Upload for Contact Form 7 [drag-and-drop-file-upload-for-contact-form-7]
Researcher
Thomas Sanzey
More Details >
EasyMeals <= 1.5.1 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40753
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
EasyMeals - Food Blog WordPress Theme [easymeals]
Researcher
Denver Jackson
More Details >
Elementra - 100% Elementor WordPress Theme <= 1.0.9 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-39529
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Elementra - 100% Elementor WordPress Theme [elementra]
Researcher
Bonds
More Details >
EmallShop <= 2.4.21 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-39443
Patch Status
Patched
Published
Apr 22, 2026
Affected Software
EmallShop - Responsive WooCommerce WordPress Theme [emallshop]
Researcher
Phat RiO
More Details >
Esmée <= 1.4 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40759
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Esmée - Fashion Store WordPress Theme [esme]
Researcher
Denver Jackson
More Details >
Everest Forms <= 3.4.4 - Unauthenticated Arbitrary File Read and Deletion via Upload Field 'old_files' Parameter
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-5478
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder [everest-forms]
Researcher
ll
More Details >
Kapee < 1.7.0 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-39446
Patch Status
Patched
Published
Apr 22, 2026
Affected Software
Kapee - Modern Multipurpose WooCommerce Theme [kapee]
Researcher
Phat RiO
More Details >
Learnify - Online Courses Education WordPress Theme <= 1.15.0 - Unauthenticated Local File Inclusion
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2025-60085
Patch Status
Unpatched
Published
Apr 23, 2026
Affected Software
Learnify - Online Courses Education WordPress Theme [learnify]
Researcher
Bonds
More Details >
Léonie <= 1.2.1 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40758
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Léonie - Nail and Beauty Salon WordPress Theme [lonie]
Researcher
Denver Jackson
More Details >
Link Library <= 7.8.8 - Authenticated (Contributor+) Arbitrary File Deletion
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40779
Patch Status
Patched
Published
Apr 22, 2026
Affected Software
Link Library [link-library]
Researcher
Trương Hữu Phúc (truonghuuphuc)
More Details >
Manufaktur Solutions <= 1.1.1 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40752
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Manufaktur Solutions - Industry and Factory WordPress Theme [manufaktursolutions]
Researcher
Denver Jackson
More Details >
PressMart <= 1.2.26 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-39442
Patch Status
Patched
Published
Apr 22, 2026
Affected Software
PressMart - Modern Elementor WooCommerce WordPress Theme [presssmart]
Researcher
Phat RiO
More Details >
Roisin - Flower Shop and Florist WordPress Theme <= 1.4 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40754
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Roisin - Flower Shop and Florist WordPress Theme [roisin]
Researcher
Denver Jackson
More Details >
TechLink <= 1.3 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40755
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
TechLink - Technology and IT Solutions WordPress Theme [techlink]
Researcher
Denver Jackson
More Details >
Valeska <= 1.2.2 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40761
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Valeska - Fashion eCommerce WordPress Theme [valeska]
Researcher
Denver Jackson
More Details >
wpForo Forum <= 3.0.5 - Authenticated (Subscriber+) Arbitrary File Deletion via Custom Profile Field File Path
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-6248
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
wpForo Forum [wpforo]
Researchers
0xd4rk5id3wackydawg
More Details >
Zoya <= 1.4 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-40756
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Zoya - Minimal Blog Elementor Template Kit [zoya]
Researcher
Denver Jackson
More Details >
Anti-Malware Security and Brute-Force Firewall <= 4.23.87 - Authenticated (Contributor+) PHP Object Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-39478
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Anti-Malware Security and Brute-Force Firewall [gotmls]
Researcher
daroo
More Details >
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-40771
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe [contest-gallery]
Researcher
Trương Hữu Phúc (truonghuuphuc)
More Details >
Feed KuantoKusta for WooCommerce – Free <= 5.3 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-39441
Patch Status
Patched
Published
Apr 22, 2026
Affected Software
Feed KuantoKusta for WooCommerce – Free [feed-kuantokusta-for-woocommerce]
Researcher
TruongLV1 From FPT Night Wolf
More Details >
InPost Gallery <= 2.1.4.6 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-39574
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
InPost Gallery [inpost-gallery]
Researcher
hivesec
More Details >
ListingPro Plugin <= 2.9.10 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-39438
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
ListingPro Plugin [listingpro-plugin]
Researcher
Phat RiO
More Details >
Modula Image Gallery – Photo Grid & Video Gallery <= 2.14.18 - Authenticated (Author+) PHP Object Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-39481
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery]
Researcher
daroo
More Details >
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF <= 6.4.3 - Authenticated (Author+) PHP Object Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-39471
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF [shortpixel-image-optimiser]
Researcher
daroo
More Details >
WPGraphQL < 2.11.1 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-40762
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
WPGraphQL [wp-graphql]
Researcher
daroo
More Details >
Chatbot for WordPress by Collect.chat <= 2.4.9 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-40765
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
Chatbot for WordPress by Collect.chat [collectchat]
Researcher
Ritsuy
More Details >
Contact Form to Any API <= 3.0.3 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-39449
Patch Status
Unpatched
Published
Apr 22, 2026
Affected Software
Contact Form to Any API [contact-form-to-any-api]
Researcher
Saleh Elsayed (0xManticore)
More Details >
Coupon Affiliates – Affiliate Plugin for WooCommerce <= 7.5.3 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-40770
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
Coupon Affiliates – Affiliate Plugin for WooCommerce [woo-coupon-usage]
Researcher
Nguyen Ba Khanh
More Details >
ExactMetrics <= 9.1.2 - Authenticated (Editor+) Arbitrary Plugin Installation/Activation via exactmetrics_connect_process
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-5464
Patch Status
Patched
Published
Apr 22, 2026
Affected Software
ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) [google-analytics-dashboard-for-wp]
Researcher
Nguyen Ngoc Duc (duc193)
More Details >
HTTP Headers <= 1.19.2 - Authenticated (Administrator+) External Control of File Name or Path to RCE via 'hh_htpasswd_path' and 'hh_www_authenticate_user' Parameters
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-4132
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
HTTP Headers [http-headers]
Researcher
Chiao-Lin Yu (Steven Meow)
More Details >
Kapee < 1.7.1 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-41557
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
Kapee - Modern Multipurpose WooCommerce Theme [kapee]
Researcher
Tran Nguyen Bao Khanh
More Details >
Notification for Telegram <= 3.5 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-40732
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Notification for Telegram [notification-for-telegram]
Researcher
Nguyen Ba Khanh
More Details >
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 11.0.0 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-40787
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker [quiz-master-next]
Researcher
Jakub Herman
More Details >
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.106.0 - Authenticated (Editor+) Remote Code Execution
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-39465
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider]
Researcher
Marc-André Beaulieu (h3dg3h0g)
More Details >
WP Time Slots Booking Form <= 1.2.46 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-40791
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
WP Time Slots Booking Form [wp-time-slots-booking-form]
Researcher
Daniel Wade
More Details >
Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 - Authenticated (Shop manager+) PHP Object Injection
6.6
CVSS Rating
6.6 (Medium)
CVE-ID
CVE-2026-39499
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Advanced Product Fields (Product Addons) for WooCommerce [advanced-product-fields-for-woocommerce]
Researcher
daroo
More Details >
PDF Invoices & Packing Slips for WooCommerce < 5.9.0 - Authenticated (Shop manager+) PHP Object Injection
6.6
CVSS Rating
6.6 (Medium)
CVE-ID
CVE-2026-39472
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips]
Researcher
daroo
More Details >
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider <= 3.106.0 - Authenticated (Editor+) PHP Object Injection
6.6
CVSS Rating
6.6 (Medium)
CVE-ID
CVE-2026-39467
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider]
Researcher
daroo
More Details >
YayMail – WooCommerce Email Customizer <= 4.3.3 - Authenticated (Shop manager+) PHP Object Injection
6.6
CVSS Rating
6.6 (Medium)
CVE-ID
CVE-2026-39498
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
YayMail – WooCommerce Email Customizer [yaymail]
Researcher
daroo
More Details >
Breaking News WP <= 1.3 - Missing Authorization to Authenticated (Subscriber+) Local File Inclusion/Read
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-4280
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Breaking News WP [breaking-news-wp]
Researcher
t0ann9uy3n
More Details >
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.25 - Authenticated (Subscriber+) SQL Injection
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-40766
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system]
Researcher
Jakub Herman
More Details >
Plugin: CMS für Motorrad Werkstätten <= 1.0.0 - Authenticated (Subscriber+) SQL Injection via 'arttype' Parameter
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-6674
Patch Status
Unpatched
Published
Apr 20, 2026
Affected Software
Plugin: CMS für Motorrad Werkstätten [cms-fuer-motorrad-werkstaetten]
Researcher
Régis SENET
More Details >
WP Sessions Time Monitoring Full Automatic <= 1.1.4 - Authenticated (Subscriber+) SQL Injection
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-39581
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
WP Sessions Time Monitoring Full Automatic [activitytime]
Researcher
hivesec
More Details >
Bread & Butter: Content Gating for Verified Leads <= 8.2.0.25 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-4279
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Bread & Butter: AI-Powered Lead Intelligence [bread-butter]
Researcher
Athiwat Tiprasaharn (Jitlada)
More Details >
CI HUB Connector <= 1.2.106 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-4353
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
CI HUB Connector [ci-hub-connector]
Researcher
zaim
More Details >
E-cab Taxi Booking Manager for Woocommerce <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-28040
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
E-cab Taxi Booking Manager for Woocommerce [ecab-taxi-booking-manager]
Researcher
Muhammad Yudha - DJ
More Details >
Easy Social Photos Gallery <= 3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrapper_class' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-4085
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Easy Social Photos Gallery – MIF [my-instagram-feed]
Researcher
Muhammad Yudha - DJ
More Details >
ER Swiffy Insert <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-4082
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
ER Swiffy Insert [er-swiffy-insert]
Researcher
Gilang - DJ
More Details >
Gallagher Website Design <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'prefix' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-1913
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
Gallagher Website Design [gallagher-website-design]
Researcher
zaim
More Details >
Gutentools <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Slider Block Attributes
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-1395
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
Gutentools [gutentools]
Researchers
Athiwat Tiprasaharn (Jitlada)Itthidej Aramsri (Boeing777)
More Details >
Image Source Control Lite – Show Image Credits and Captions <= 3.9.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'Image Source' Field
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-4852
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Image Source Control Lite – Show Image Credits and Captions [image-source-control-isc]
Researchers
Athiwat Tiprasaharn (Jitlada)Vilaysone CHANTHAVONG (0xJ0cKkY)
More Details >
ITERAS <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-4078
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
ITERAS [iteras]
Researcher
Muhammad Yudha - DJ
More Details >
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-41556
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress [wp-user-avatar]
Researcher
Niv Kochan
More Details >
Posts map <= 0.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'name' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-6236
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Posts map [posts-map]
Researcher
MAJidox
More Details >
Quran Live Multilanguage <= 1.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-4074
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Quran Live Multilanguage [quran-live]
Researcher
Gilang - DJ
More Details >
Rescue Shortcodes <= 3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2025-62110
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
Rescue Shortcodes [rescue-shortcodes]
Researcher
Nabil Irawan
More Details >
Royal Addons for Elementor <= 1.7.1056 - Authenticated (Author+) Stored Cross-Site Scripting via Image Caption Field
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-5428
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons]
Researcher
Dmitrii Ignatyev
More Details >
Simple Random Posts Shortcode <= 0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'container_right_width' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-6246
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Simple Random Posts Shortcode [simple-random-posts-shortcode]
Researcher
MAJidox
More Details >
Slider Bootstrap Carousel <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-4076
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Slider Bootstrap Carousel [slider-bootstrap-carousel]
Researcher
Gilang - DJ
More Details >
SlideShowPro SC <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'album' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-5767
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
SlideShowPro SC [slideshowpro-shortcode]
Researcher
MAJidox
More Details >
Social Rocket – Social Sharing Plugin <= 1.3.4.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via id
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-1923
Patch Status
Patched
Published
Apr 22, 2026
Affected Software
Social Rocket – Social Sharing Plugin [social-rocket]
Researcher
Tarcísio Luchesi De Almeida Silva (Poystick)
More Details >
Switch CTA Box <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-4088
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Switch CTA Box [switch-cta-box]
Researcher
Muhammad Yudha - DJ
More Details >
Text Snippets <= 0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'w' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-5748
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Text Snippets [text-snippet]
Researcher
MAJidox
More Details >
Twittee Text Tweet <= 1.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-4089
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Twittee Text Tweet [twittee-text-tweet]
Researcher
zakaria
More Details >
WP Store Locator <= 2.2.261 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpsl_address' Post Meta
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-3361
Patch Status
Patched
Published
Apr 22, 2026
Affected Software
WP Store Locator [wp-store-locator]
Researcher
kai63001
More Details >
WPMK Block <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-4125
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
WPMK Block [wpmk-block]
Researcher
zakaria
More Details >
Zypento Blocks <= 1.0.6 - Authenticated (Author+) Stored Cross-Site Scripting via Table of Contents Block
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-5820
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Zypento Blocks [zypento-blocks]
Researcher
Athiwat Tiprasaharn (Jitlada)
More Details >
Bricks <= 1.9.2 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-41554
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
Bricks [bricks]
Researcher
w41bu1
More Details >
GiveWP – Donation Plugin and Fundraising Platform <= 4.14.2 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-34900
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
GiveWP – Donation Plugin and Fundraising Platform [give]
Researcher
HuajiHD
More Details >
Inquiry cart <= 3.4.2 - Cross-Site Request Forgery via Settings Form
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-4090
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Inquiry cart [inquiry-cart]
Researcher
Muhammad Nur Ibnu Hubab (Ibnu)
More Details >
Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-39437
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
Min Max Step Quantity Limits Manager for WooCommerce [product-quantity-for-woocommerce]
Researcher
hivesec
More Details >
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.17.3 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-39514
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction [paid-member-subscriptions]
Researcher
loris4py
More Details >
Website LLMs.txt <= 8.2.6 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-6711
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Website LLMs.txt [website-llms-txt]
Researcher
Kazuma Matsumoto
More Details >
WP Responsive Popup + Optin <= 1.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'wpo_image_url' Parameter
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-4131
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
WP Responsive Popup + Optin [wp-popup-optin]
Researcher
Muhammad Nur Ibnu Hubab (Ibnu)
More Details >
HTTP Headers <= 1.19.2 - Authenticated (Administrator+) CRLF Injection via Custom Header Values
5.5
CVSS Rating
5.5 (Medium)
CVE-ID
CVE-2026-2717
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
HTTP Headers [http-headers]
Researcher
Kai Aizen
More Details >
Real Estate Pro <= 1.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting via Settings
5.5
CVSS Rating
5.5 (Medium)
CVE-ID
CVE-2026-1845
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Real Estate Pro [re-pro]
Researcher
Muhammad Nur Ibnu Hubab (Ibnu)
More Details >
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutentor Block HTML
5.4
CVSS Rating
5.4 (Medium)
CVE-ID
CVE-2026-2951
Patch Status
Patched
Published
Apr 22, 2026
Affected Software
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor [gutentor]
Researcher
Muhammad Yudha - DJ
More Details >
Booking Calendar Contact Form <= 1.2.63 - Authenticated (Subscriber+) Insecure Direct Object Reference to Calendar Takeover
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-6810
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
Booking Calendar Contact Form [booking-calendar-contact-form]
Researcher
Md. Moniruzzaman Prodhan (NomanProdhan)
More Details >
Booking for Appointments and Events Calendar – Amelia <= 2.2 - Unauthenticated Information Exposure
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-40789
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
Booking for Appointments and Events Calendar – Amelia [ameliabooking]
Researcher
Weerawat Pawanawiwat (ErbaZZ)
More Details >
Booking Package <= 1.7.06 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-40774
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
Booking Package [booking-package]
Researcher
Skoobi
More Details >
Bookit — Booking & Appointment Calendar <= 2.5.1 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-40780
Patch Status
Patched
Published
Apr 22, 2026
Affected Software
Bookit — Booking & Appointment Calendar [bookit]
Researcher
davidfdzmorilla
More Details >
CalJ <= 1.5 - Authenticated (Subscriber+) Arbitrary Settings Modification via 'save-obtained-key' Action
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-4117
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
CalJ Shabbat Times [calj]
Researcher
Nabil Irawan
More Details >
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.6.5 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-39503
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads]
Researcher
Jakub Herman
More Details >
Essential Addons for Elementor – Popular Elementor Templates & Widgets < 6.6.0 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-25440
Patch Status
Patched
Published
Apr 22, 2026
Affected Software
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite]
Researcher
Que Thanh Tuan
More Details >
ExactMetrics <= 9.1.2 - Authenticated (Subscriber+) Missing Authorization to Google Ads Access Token Retrieval via AJAX Action 'exactmetrics_ads_get_token'
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-5488
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) [google-analytics-dashboard-for-wp]
Researcher
Dmitrii Ignatyev
More Details >
HT Mega Addons for Elementor – Elementor Widgets & Template Builder < 3.0.7 - Unauthenticated Information Exposure
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-4106
Patch Status
Patched
Published
Apr 24, 2026
Affected Software
HT Mega Addons for Elementor – Elementor Widgets & Template Builder [ht-mega-for-elementor]
Researcher
Chiao-Lin Yu (Steven Meow)
More Details >
Jupiter X Core <= 4.14.1 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-39490
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Jupiter X Core [jupiterx-core]
Researcher
hivesec
More Details >
Liaison Site Prober <= 1.2.1 - Missing Authorization to Unauthenticated Information Exposure in '/logs' REST API Endpoint
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-3569
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
Liaison Site Prober [liaison-site-prober]
Researcher
Itthidej Aramsri (Boeing777)
More Details >
MasterStudy LMS Pro < 4.7.16 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2025-64215
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
MasterStudy LMS Pro [masterstudy-lms-learning-management-system-pro]
Researcher
Rafie Muhammad
More Details >
Maxi Blocks <= 2.1.8 - Missing Authorization to Authenticated (Author+) Media File Deletion via 'old_media_src' Parameter
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-2028
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
MaxiBlocks Builder | 17,000+ Design Assets, Patterns, Icons & Starter Sites [maxi-blocks]
Researcher
Teerachai Somprasong
More Details >
Metro Magazine <= 1.4.1 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-40809
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
Metro Magazine [metro-magazine]
Researcher
Trương Hữu Phúc (truonghuuphuc)
More Details >
Responsive Blocks <= 2.2.0 - Unauthenticated Open Email Relay via REST API 'email_to' Parameter
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-6675
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Responsive Blocks – Page Builder for Blocks & Patterns [responsive-block-editor-addons]
Researcher
Even Stokkedalen
More Details >
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema <= 2.3.6 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-40781
Patch Status
Patched
Published
Apr 22, 2026
Affected Software
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema [reviewx]
Researcher
Jakub Herman
More Details >
Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini <= 1.4.2 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-40775
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini [royal-mcp]
Researcher
Alexis Lafontaine
More Details >
Salon Booking System – Free Version <= 10.30.24 - Unauthenticated Insecure Direct Object Reference
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-40768
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
Salon Booking System – Free Version [salon-booking-system]
Researcher
Lubin Regnault
More Details >
Tutor LMS – eLearning and online course solution <= 3.9.7 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-40743
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Tutor LMS – eLearning and online course solution [tutor]
Researcher
lagi bljr
More Details >
WP Books Gallery <= 4.8.0 - Missing Authorization to Unauthenticated Settings Update via 'permalink_structure' Parameter
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-5347
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes [wp-books-gallery]
Researcher
Legion Hunter
More Details >
WPAdverts – Classifieds Plugin <= 2.3.0 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-40782
Patch Status
Patched
Published
Apr 22, 2026
Affected Software
WPAdverts – Classifieds Plugin [wpadverts]
Researcher
TheNetRunner Security Research
More Details >
wpForo Forum < 3.0.2 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-40767
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
wpForo Forum [wpforo]
Researcher
Dahmani Toumi (pegaSUS)
More Details >
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 6.5.0.4 - Unauthenticated Stored Cross-Site Scripting via CSV/Excel Data Import
4.7
CVSS Rating
4.7 (Medium)
CVE-ID
CVE-2026-5721
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables]
Researcher
Lio
More Details >
Buzz Comments <= 0.9.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Custom Buzz Avatar' Setting
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-6041
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Buzz Comments [buzz-comments]
Researcher
Muhammad Nur Ibnu Hubab (Ibnu)
More Details >
Email Encoder – Protect Email Addresses and Phone Numbers < 2.3.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2024-7083
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
Email Encoder – Protect Email Addresses and Phone Numbers [email-encoder-bundle]
Researcher
Dmitrii Ignatyev
More Details >
HTTP Headers <= 1.19.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Custom Headers' Plugin Setting
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-1379
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
HTTP Headers [http-headers]
Researcher
Daniel Basta (whizzu)
More Details >
Private WP suite <= 0.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Exceptions' Setting
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-2719
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Private WP suite [private-wp-suite]
Researcher
Muhammad Nur Ibnu Hubab (Ibnu)
More Details >
reCaptcha by WebDesignBy < 2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-4512
Patch Status
Patched
Published
Apr 24, 2026
Affected Software
reCaptcha by WebDesignBy [webdesignby-recaptcha]
Researcher
Mustafa
More Details >
Sentence To SEO (keywords, description and tags) <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Permanent keywords' Field
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-4142
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Sentence To SEO (keywords, description and tags) [sentence-to-seo]
Researcher
Muhammad Nur Ibnu Hubab (Ibnu)
More Details >
Short Comment Filter <= 2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Minimum Count' Setting
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-3362
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Short Comment Filter [short-comment-filter]
Researcher
Muhammad Nur Ibnu Hubab (Ibnu)
More Details >
Website LLMs.txt <= 8.2.6 - Authenticated (Admin+) Stored Cross-Site Scripting
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-6712
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Website LLMs.txt [website-llms-txt]
Researcher
Kazuma Matsumoto
More Details >
ACF Galerie 4 <= 1.4.2 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2025-62104
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
ACF Galerie 4 [acf-galerie-4]
Researcher
Nabil Irawan
More Details >
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.6.7 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-40785
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress [automatorwp]
Researcher
Jakub Herman
More Details >
Avada < 7.13.2 - Cross-Site Request Forgery
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2025-58922
Patch Status
Patched
Published
Apr 22, 2026
Affected Software
Avada | Website Builder For WordPress & WooCommerce [Avada]
Researcher
João Pedro Soares de Alcântara
More Details >
BetterDocs <= 4.3.11 - Missing Authorization to Authenticated (Subscriber+) Unauthorized AI API Usage
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-6393
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor [betterdocs]
Researcher
h0xilo
More Details >
Blocksy Companion Pro <= 2.1.37 - Authenticated (Contributor+) Remote Code Execution
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-40783
Patch Status
Patched
Published
Apr 22, 2026
Affected Software
Blocksy Companion Pro [blocksy-companion-pro]
Researcher
Nguyen Ba Khanh
More Details >
Bookify – Appointment Booking & Scheduling for WordPress <= 1.1.1 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2025-69332
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
Bookify – Appointment Booking & Scheduling for WordPress [bookify]
Researcher
benzdeus
More Details >
Call To Action Plugin <= 3.1.3 - Cross-Site Request Forgery via Settings Update
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-4118
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Call To Action Plugin [call-to-action-plugin]
Researcher
afnaan
More Details >
Download Monitor <= 5.1.9 - Authenticated (Author+) Arbitrary File Download
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-39489
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Download Monitor [download-monitor]
Researcher
daroo
More Details >
DX Unanswered Comments <= 1.7 - Cross-Site Request Forgery via Settings Update
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-4138
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
DX Unanswered Comments [dx-unanswered-comments]
Researcher
afnaan
More Details >
Emailchef <= 3.5.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-1930
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
Emailchef [emailchef]
Researcher
Legion Hunter
More Details >
EventPrime – Events Calendar, Bookings and Tickets <= 4.3.0.0 - Authenticated (Subscriber+) Insecure Direct Object Reference
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-39518
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management]
Researcher
James Pirstin
More Details >
Fast & Fancy Filter – 3F <= 1.2.2 - Cross-Site Request Forgery to Settings Modification via fff_save_settins AJAX Action
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-6396
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Fast & Fancy Filter – 3F [fast-fancy-filter-3f]
Researcher
Muhammad Nur Ibnu Hubab (Ibnu)
More Details >
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.7.3 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-39450
Patch Status
Patched
Published
Apr 22, 2026
Affected Software
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce [wp-marketing-automations]
Researcher
Jakub Herman
More Details >
Google PageRank Display <= 1.4 - Cross-Site Request Forgery to Settings Update via Settings Page
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-6294
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Google PageRank Display [google-pagerank-display]
Researcher
Muhammad Nur Ibnu Hubab (Ibnu)
More Details >
Groundhogg — CRM, Newsletters, and Marketing Automation < 4.4.1 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-40793
Patch Status
Patched
Published
Apr 24, 2026
Affected Software
Groundhogg — CRM, Newsletters, and Marketing Automation [groundhogg]
Researcher
Jakub Herman
More Details >
HubSpot All-In-One Marketing - Forms, Popups, Live Chat <= 11.3.32 - Missing Authorization to Authenticated (Contributor+) Installed Plugin Disclosure
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2025-11762
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
HubSpot All-In-One Marketing – Forms, Popups, Live Chat [leadin]
Researcher
Dmitrii Ignatyev
More Details >
Kcaptcha <= 1.0.1 - Cross-Site Request Forgery to Settings Update
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-4121
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Kcaptcha [kcaptcha]
Researcher
afnaan
More Details >
KiviCare – Clinic & Patient Management System (EHR) <= 4.2.1 - Authenticated (Subscriber+) Insecure Direct Object Reference
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-40792
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
KiviCare – Clinic & Patient Management System (EHR) [kivicare-clinic-management-system]
Researcher
Jakub Herman
More Details >
mCatFilter <= 0.5.2 - Cross-Site Request Forgery via compute_post() Function
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-4139
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
mCatFilter [mcatfilter]
Researcher
afnaan
More Details >
Motors – Car Dealership & Classified Listings Plugin < 1.4.107 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-39515
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
Motors – Car Dealership & Classified Listings Plugin [motors-car-dealership-classified-listings]
Researcher
Jakub Herman
More Details >
Ni WooCommerce Order Export <= 3.1.6 - Cross-Site Request Forgery to Settings Update via ni_order_export_action AJAX Action
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-4140
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Ni WooCommerce Order Export [ni-woocommerce-order-export]
Researcher
afnaan
More Details >
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred <= 3.0.3 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-40794
Patch Status
Patched
Published
Apr 24, 2026
Affected Software
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred [mycred]
Researcher
Jakub Herman
More Details >
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress <= 4.1132 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-39584
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress [computer-repair-shop]
Researcher
Trương Hữu Phúc (truonghuuphuc)
More Details >
Responsive Blocks <= 2.2.1 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via AJAX Actions
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-6703
Patch Status
Patched
Published
Apr 20, 2026
Affected Software
Responsive Blocks – Page Builder for Blocks & Patterns [responsive-block-editor-addons]
Researcher
Even Stokkedalen
More Details >
rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-40773
Patch Status
Patched
Published
Apr 21, 2026
Affected Software
rtMedia for WordPress, BuddyPress and bbPress [buddypress-media]
Researcher
Jakub Herman
More Details >
Table Manager <= 1.0.0 - Authenticated (Contributor+) Sensitive Information Exposure via 'table' Shortcode Attribute
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-4126
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
Table Manager [table-manager]
Researcher
Itthidej Aramsri (Boeing777)
More Details >
Taqnix <= 1.0.3 - Cross-Site Request Forgery to Account Deletion via 'taqnix_delete_my_account' AJAX Action
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-3565
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
Taqnix [taqnix]
Researcher
theviper17y
More Details >
TextP2P Texting Widget <= 1.7 - Cross-Site Request Forgery to Settings Update
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-4133
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
TextP2P Texting Widget [textp2p-texting-widget]
Researcher
afnaan
More Details >
TP Restore Categories And Taxonomies <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Taxonomy Deletion via 'tpmcattt_delete_term' AJAX Action
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-4128
Patch Status
Unpatched
Published
Apr 21, 2026
Affected Software
TP Restore Categories And Taxonomies [tp-restore-categories-and-taxonomies]
Researcher
Nabil Irawan
More Details >
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 7.9.7 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-40788
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services [chatbot]
Researcher
Mehdi Ouassou
More Details >
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce <= 7.2.1 - Authenticated (Subscriber+) Information Exposure
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-40790
Patch Status
Patched
Published
Apr 23, 2026
Affected Software
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce [wp-sms]
Researcher
Jakub Herman
More Details >
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (April 20, 2026 to April 26, 2026) appeared first on Wordfence.
Quelle: www.wordfence.com