Wordfence Intelligence Weekly WordPress Vulnerability Report (June 1, 2026 to June 7, 2026)

⚠️ CVE-Referenzen: CVE-2026-49771 CVE-2026-9016 CVE-2026-49770 CVE-2026-49056 CVE-2026-49782 CVE-2026-25439 CVE-2026-6448 CVE-2026-9719 CVE-2026-4080 CVE-2026-2382 CVE-2026-49105 CVE-2026-9722 CVE-2026-7796 CVE-2026-9594 CVE-2026-9234 CVE-2026-9281 CVE-2026-4081 CVE-2026-48886 CVE-2026-8901 CVE-2026-28116 CVE-2026-8502 CVE-2026-7566 CVE-2026-9691 CVE-2026-8653 CVE-2026-48873 CVE-2026-9732 CVE-2026-49768 CVE-2026-48883 CVE-2026-49774 CVE-2026-9197 CVE-2026-49765 CVE-2026-9290 CVE-2026-49764 CVE-2026-48889 CVE-2026-34892 CVE-2026-49113 CVE-2026-8978 CVE-2026-48874 CVE-2026-8900 CVE-2026-48970 CVE-2026-10737 CVE-2026-8608 CVE-2026-49107 CVE-2025-5085 CVE-2026-8385 CVE-2026-5073 CVE-2026-8206 CVE-2026-7654 CVE-2026-48867 CVE-2026-49077 CVE-2026-7624 CVE-2026-4071 CVE-2026-8893 CVE-2026-39451 CVE-2026-9730 CVE-2026-7523 CVE-2026-8611 CVE-2026-2425 CVE-2026-5076 CVE-2026-48965 CVE-2026-49780 CVE-2026-49781 CVE-2026-49776 CVE-2026-48885 CVE-2026-7795 CVE-2026-1829 CVE-2026-3722 CVE-2026-49078 CVE-2026-48966 CVE-2026-5191 CVE-2026-8991 CVE-2026-48964 CVE-2026-3620 CVE-2026-49104 CVE-2026-9723 CVE-2026-48870 CVE-2026-48880 CVE-2026-48875 CVE-2026-45437 CVE-2026-27089 CVE-2026-9008 CVE-2026-3011 CVE-2026-48878 CVE-2026-49773 CVE-2026-8438 CVE-2026-48882 CVE-2026-9851 CVE-2026-48839 CVE-2026-9599 CVE-2026-48871 CVE-2026-48876 CVE-2026-2500 CVE-2026-42761 CVE-2026-48872 CVE-2026-48969 CVE-2026-49767 CVE-2026-49108 CVE-2019-25727 CVE-2026-49055 CVE-2026-49110 CVE-2026-48836 CVE-2026-48879 CVE-2026-10100 CVE-2026-39435 CVE-2026-48868 CVE-2026-42762 CVE-2026-8885 CVE-2026-7565 CVE-2026-1451 CVE-2026-48869 CVE-2026-8422 CVE-2026-42775 CVE-2026-27351 CVE-2026-27410 CVE-2026-5305 CVE-2026-7792 CVE-2026-49085 CVE-2026-49775 CVE-2026-7665 CVE-2026-5411 CVE-2026-9050 CVE-2026-10580 CVE-2026-9280 CVE-2026-5074 CVE-2026-9690 CVE-2026-27395 CVE-2026-42378 CVE-2026-49106 CVE-2026-48887 CVE-2026-8839 CVE-2026-49766 CVE-2026-48967 CVE-2026-48881 CVE-2026-48865 CVE-2026-49079 CVE-2026-5415 CVE-2026-49763 CVE-2026-49769 CVE-2026-7421 CVE-2026-10586 CVE-2026-49112 CVE-2026-8976 CVE-2026-9829 CVE-2026-49081 CVE-2026-49109 CVE-2026-7537 CVE-2026-49083 CVE-2026-49777 CVE-2026-49778 CVE-2026-49082 CVE-2025-12656 CVE-2026-1450 CVE-2026-10038 CVE-2019-25738 CVE-2026-9048 CVE-2026-49057 CVE-2026-48866 CVE-2026-7047
Last week, there were 159 vulnerabilities disclosed in 140 WordPress Plugins and 2 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 96 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back. Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 35,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free. Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. New Firewall Rules Deployed Last Week The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection. The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week: UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 – Unauthenticated Authentication Bypass via UpdraftCentral udrpc Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay. Total Unpatched & Patched Vulnerabilities Last Week Patch Status Number of Vulnerabilities Patched 134 Unpatched 25 Total Vulnerabilities by CVSS Severity Last Week Severity Rating Number of Vulnerabilities Low Severity 1 Medium Severity 96 High Severity 53 Critical Severity 9 Total Vulnerabilities by CWE Type Last Week Vulnerability Type by CWE Number of Vulnerabilities Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 43 Missing Authorization 28 Deserialization of Untrusted Data 17 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 16 Cross-Site Request Forgery (CSRF) 9 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 9 Exposure of Sensitive Information to an Unauthorized Actor 7 Authorization Bypass Through User-Controlled Key 6 Improper Control of Generation of Code ('Code Injection') 5 Incorrect Privilege Assignment 4 Improper Privilege Management 2 Insufficient Verification of Data Authenticity 2 Unrestricted Upload of File with Dangerous Type 2 Authentication Bypass Using an Alternate Path or Channel 1 Embedded Malicious Code 1 External Control of File Name or Path 1 Improper Authentication 1 Improper Authorization 1 Improper Input Validation 1 Improper Output Neutralization for Logs 1 Incorrect Authorization 1 Server-Side Request Forgery (SSRF) 1 Researchers That Contributed to WordPress Security Last Week Researcher Name Number of Vulnerabilities Frissi0n 8 daroo 8 Jakub Herman 6 dodoh4t 4 san6051 4 kai63001 4 swat 4 h0xilo 4 VanTastic 3 hhhai 3 dutafi 2 Gilang - DJ 2 darkmode 2 Wannes Verwimp 2 João Pedro Soares de Alcântara 2 Jonathan Dersch 2 Nabil Irawan 2 ZAST.AI 2 Bonds 2 Nguyen Ngoc Duc (duc193) 2 Mukhlis Amien 2 KEVIN LEE (crattack) 2 Evan NR 2 Athiwat Tiprasaharn (Jitlada) 2 Itthidej Aramsri (Boeing777) 2 Valatty 2 benzdeus 2 zakaria 2 0xd4rk5id3 2 Nguyen Dinh Hai (HaiND) 2 Austin Ginder 2 endy 2 Nguyen Ba Khanh 2 Phat RiO 2 Yousef Alraddadi 2 Drew Webber (mcdruid) 2 Bao Luu Gia Nguyen 1 Osvaldo Noe Gonzalez Del Rio (Os) 1 Nguyen Khanh Hao 1 Shambles 1 Muhan Luo 1 thevietronin 1 Nvz 1 Muhammad Yudha - DJ 1 James Paremain 1 Endang Alfarisi 1 hongdo 1 xwii 1 longnv719 1 Webbernaut 1 anhcd05 1 Namdn 1 blue0x1 1 Abi Wiranata 1 siyuan shao 1 sequence_X0 1 CHOIGYEONGMIN 1 Ryan Kozak 1 Mohamed Wajih Hichri (Assaults) 1 Kyokito 1 Khanh Nguyen 1 Aliefis 1 Vincent Sevkli 1 Mitchell 1 Ilay Striechman 1 Md. Moniruzzaman Prodhan (NomanProdhan) 1 Yat 1 she11f 1 Anirudh Makkar 1 Tiago Ventura (perses) 1 afnaan 1 Nguyen Duong 1 Kitch 1 UKO 1 Jamshed Yergashvoyev (CVE Guy) 1 PeterPatter 1 Pablo Santiago 1 Peleg Nagli (ultrared.ai) 1 RyuuKhagetsu 1 Tran Nguyen Bao Khanh 1 stealthcopter 1 Kirasec 1 Jonah Burgess (CryptoCat) 1 Dmitrii Ignatyev 1 NAKLEH ZEIDAN 1 Sudhanshu Chauhan 1 Prickly Cactus 1 Muhammad Nur Ibnu Hubab 1 Jack Pas (Dark.) 1 fayespiegel 1 ParkHyunWoo 1 Teerachai Somprasong 1 Rafie Muhammad 1 Shane 1 Niv Kochan 1 adhikara13 1 Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report. WordPress Plugins with Reported Vulnerabilities Last Week Software Name Software Slug 10WebAdManager ad-manager-wd Active Products Tables for WooCommerce. Use constructor to create tables  profit-products-tables-for-woocommerce Ad Inserter – Ad Manager & AdSense Ads ad-inserter Admin Columns codepress-admin-columns Advanced Google reCAPTCHA advanced-google-recaptcha AI Chatbot & Workflow Automation by AIWU ai-copilot-content-generator Alba Board alba-board All-In-One Security (AIOS) – Security and Firewall all-in-one-wp-security-and-firewall ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup armember Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) auto-image-attributes-from-filename-with-bulk-updater AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress automatorwp Backup, Restore and Migrate your sites with XCloner xcloner-backup-and-restore BirdSeed birdseed Booking for Appointments and Events Calendar – Amelia ameliabooking Booking Package booking-package Booknetic booknetic cformsII cforms2 Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More charitable Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons chatway-live-chat Click to Chat – HoliThemes click-to-chat-for-whatsapp Content Visibility for Divi Builder content-visibility-for-divi-builder Cornerstone cornerstone Debug Log Manager – Conveniently Monitor and Inspect Errors debug-log-manager DeMomentSomTres Shortcodes demomentsomtres-shortcodes Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy dokan-lite Drag and Drop Multiple File Upload for Contact Form 7 drag-and-drop-multiple-file-upload-contact-form-7 Easy Cart easy-cart Easy Invoice – Invoice Generator, PDF Quotes & Payments easy-invoice Elementor Website Builder – more than just a page builder elementor ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-customer-support-ticket-system Email Address Encoder email-address-encoder email-encoder-premium email-encoder-premium EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more embedpress EmergencyWP – Dead Man's switch & legacy deliverance emergencywp Employee, Leave and Recruitment Management System – Crew HRM hr-management Essential Addons for Elementor – Popular Elementor Templates & Widgets essential-addons-for-elementor-lite Event Monster – Event Manager, Ticket Booking & Registration event-monster Express Payment For Stripe wp-stripe-express FPW Category Thumbnails fpw-category-thumbnails Frontend User Notes frontend-user-notes FunnelKit – Funnel Builder for WooCommerce Checkout funnel-builder FV Flowplayer Video Player fv-wordpress-flowplayer GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress gamipress Geo Mashup geo-mashup Google Plus One Bottom google-plus-one-bottom GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites gptranslate Gravity Forms gravityforms Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns essential-blocks Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms happyforms Hippoo Mobile App for WooCommerce hippoo hiWeb Migration Simple hiweb-migration-simple HollerBox — Fast & Effective Popups & Lead-Generation holler-box Hybrid Composer hybrid-composer Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms cf7-active-campaign Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms cf7-constant-contact Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More crm-integration-freshworks-any-form Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms cf7-hubspot Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms cf7-infusionsoft Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms cf7-mailchimp Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms cf7-salesforce JetSearch jet-search JetSmartFilters jet-smart-filters JobSearch WP Job Board wp-jobsearch JS Help Desk – AI-Powered Support & Ticketing System js-support-ticket JTL-Connector for WooCommerce woo-jtl-connector King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder king-addons Kirki – Freeform Page Builder, Website Builder & Customizer kirki Klamra Paycal for Aspaclaria klamra-paycal-for-aspaclaria Laiser Tag laiser-tag LatePoint – Calendar Booking Plugin for Appointments and Events latepoint LearnPress – Backup & Migration Tool learnpress-import-export LearnPress – WordPress LMS Plugin for Create and Sell Online Courses learnpress MapPress Maps for WordPress mappress-google-maps-for-wordpress Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits master-addons MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro MDJM Event Management mobile-dj-manager Media folder Addon wp-media-folder-addon Montonio for WooCommerce montonio-for-woocommerce MW WP Form mw-wp-form OptinCraft – Drag & Drop Optins & Popup Builder for WordPress optincraft OttoKit: All-in-One Automation Platform suretriggers Page-list page-list Passeum Ticketing passeum-ticketing Photo Gallery by 10Web – Mobile-Friendly Image Gallery photo-gallery Product Filter Widget for Elementor product-filter-widget-for-elementor Product Slider Pro for WooCommerce woo-product-slider-pro Progress Planner progress-planner Quick Playground quick-playground Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker quiz-master-next Rank Math SEO – AI SEO Tools to Dominate SEO Rankings seo-by-rank-math RD Station integracao-rd-station Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) really-simple-ssl Recipe Card Blocks Lite recipe-card-blocks-by-wpzoom RegistrationMagic – User Registration Forms Plugin custom-registration-form-builder-with-submission-manager Remove meta boxes per user role remove-meta-boxes-per-user-role Remove NoFollow Commenter URL remove-nofollow-commenter-link rognone rognone RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator feedzy-rss-feeds SEO Plugin by Squirrly SEO squirrly-seo Shared Files – Frontend File Upload Form & Secure File Sharing shared-files Simple Custom Login Page simple-custom-login-page Simple SEO Slideshow simple-seo-slideshow Simple Shopping Cart wordpress-simple-paypal-shopping-cart Slider Revolution revslider SlimStat Analytics wp-slimstat Smart Slider 3 smart-slider-3 SP Project & Document Manager sp-client-document-manager Stop Spammers Classic stop-spammer-registrations-plugin Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions wp-full-stripe-free Support Board supportboard Tectite Forms tectite-forms Thrive Apprentice thrive-apprentice Tiled Gallery Carousel Without JetPack tiled-gallery-carousel-without-jetpack Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Solution tour-booking-manager TrueBooker – Appointment Booking and Scheduler System truebooker-appointment-booking Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups. upsell-order-bump-offer-for-woocommerce User Registration Stripe user-registration-stripe VikBooking Hotel Booking Engine & PMS vikbooking Visual Link Preview visual-link-preview WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels print-invoices-packing-slip-labels-for-woocommerce Welcart e-Commerce usc-e-shop Word Replacer word-replacer Wp EMember wp-eMember WP Go Maps – Google Maps, OpenStreetMap, Leaflet Map wp-google-maps WP Google Review Slider wp-google-places-review-slider WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-insightly WP Job Portal – AI-Powered Recruitment System for Company or Job Board website wp-job-portal WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters wp-google-map-plugin WP Nano AD wp-nano-ad WP Statistics – Simple, privacy-friendly Google Analytics alternative wp-statistics WP Time Slots Booking Form wp-time-slots-booking-form WP Travel Engine – Tour Booking Plugin – Tour Operator Software wp-travel-engine WP User Manager – User Profile Builder & Membership wp-user-manager WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-zendesk WPC Product Bundles for WooCommerce woo-product-bundle WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More wpforms-lite wpForo Forum wpforo WPFunnels Pro wpfunnels-pro WPvivid — Backup, Migration & Staging wpvivid-backuprestore ZeM STL zem-stl-viewer WordPress Themes with Reported Vulnerabilities Last Week Software Name Software Slug enfold enfold Moderno – Fashion & Clothing, Furniture moderno Vulnerability Details Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize. AI Chatbot & Workflow Automation by AIWU <= 1.4.17 - Unauthenticated Privilege Escalation 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-48879 Patch Status Patched Published Jun 1, 2026 Affected Software AI Chatbot & Workflow Automation by AIWU [ai-copilot-content-generator] Researcher daroo More Details > ARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-5076 Patch Status Patched Published Jun 2, 2026 Affected Software ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup [armember] Researcher h0xilo More Details > Easy Invoice – Invoice Generator, PDF Quotes & Payments <= 2.1.19 - Unauthenticated Remote Code Execution 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-48836 Patch Status Patched Published Jun 1, 2026 Affected Software Easy Invoice – Invoice Generator, PDF Quotes & Payments [easy-invoice] Researcher Nguyen Dinh Hai (HaiND) More Details > Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-10580 Patch Status Patched Published Jun 5, 2026 Affected Software Hippoo Mobile App for WooCommerce [hippoo] Researcher Mitchell More Details > Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password' 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-8206 Patch Status Patched Published Jun 1, 2026 Affected Software Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] Researcher CHOIGYEONGMIN More Details > Product Slider Pro for WooCommerce < 3.5.4 - Backdoored Software 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-49777 Patch Status Patched Published Jun 4, 2026 Affected Software Product Slider Pro for WooCommerce [woo-product-slider-pro] Researcher Shane More Details > Support Board < 3.8.9 - Unauthenticated Privilege Escalation 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-27395 Patch Status Patched Published Jun 1, 2026 Affected Software Support Board [supportboard] Researcher Phat RiO More Details > Gravity Forms <= 2.10.0.1 - Unauthenticated Arbitrary File Deletion 9.1 CVSS Rating 9.1 (Critical) CVE-ID CVE-2026-48866 Patch Status Patched Published Jun 1, 2026 Affected Software Gravity Forms [gravityforms] Researcher daroo More Details > Media folder Addon <= 4.0.1 - Unauthenticated Arbitrary File Download 9.1 CVSS Rating 9.1 (Critical) CVE-ID CVE-2026-9690 Patch Status Patched Published Jun 4, 2026 Affected Software Media folder Addon [wp-media-folder-addon] Researcher 0xd4rk5id3 More Details > Admin Columns <= 7.0.18 - Authenticated (Contributor+) PHP Object Injection to Remote Code Execution via Custom Field Meta Value 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-7654 Patch Status Patched Published Jun 5, 2026 Affected Software Admin Columns [codepress-admin-columns] Researcher Osvaldo Noe Gonzalez Del Rio (Os) More Details > Booking for Appointments and Events Calendar – Amelia <= 2.3 - Authenticated (Subscriber+) Privilege Escalation 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-48889 Patch Status Patched Published Jun 2, 2026 Affected Software Booking for Appointments and Events Calendar – Amelia [ameliabooking] Researcher dodoh4t More Details > Content Visibility for Divi Builder <= 4.02 - Authenticated (Contributor+) Remote Code Execution 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-1829 Patch Status Patched Published Jun 2, 2026 Affected Software Content Visibility for Divi Builder [content-visibility-for-divi-builder] Researcher ZAST.AI More Details > Content Visibility for Divi Builder <= 4.02 - Authenticated (Contributor+) Remote Code Execution 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-1829 Patch Status Patched Published Jun 4, 2026 Affected Software Content Visibility for Divi Builder [content-visibility-for-divi-builder] Researcher ZAST.AI More Details > Cornerstone < 7.8.8 - Authenticated (Subscriber+) Arbitrary Code Execution 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-49113 Patch Status Patched Published Jun 4, 2026 Affected Software Cornerstone [cornerstone] Researcher Nguyen Ba Khanh More Details > Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.2 - Authenticated (Customer+) Privilege Escalation 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-49780 Patch Status Patched Published Jun 3, 2026 Affected Software Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] Researcher Nguyen Ba Khanh More Details > LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.5.1 - Authenticated (Contributor+) Privilege Escalation 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-49083 Patch Status Patched Published Jun 5, 2026 Affected Software LatePoint – Calendar Booking Plugin for Appointments and Events [latepoint] Researcher VanTastic More Details > RD Station <= 5.6.0 - Authenticated (Contributor+) Remote Code Execution 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-49774 Patch Status Patched Published Jun 4, 2026 Affected Software RD Station [integracao-rd-station] Researcher ParkHyunWoo More Details > WP Captcha PRO <= 5.38 - Authenticated (Subscriber+) Authentication Bypass via Temporary Login Link 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-5415 Patch Status Patched Published Jun 5, 2026 Affected Software Advanced Google reCAPTCHA [advanced-google-recaptcha] Researcher Nguyen Ngoc Duc (duc193) More Details > WP Captcha PRO <= 5.38 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-5411 Patch Status Patched Published Jun 5, 2026 Affected Software Advanced Google reCAPTCHA [advanced-google-recaptcha] Researcher h0xilo More Details > Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms <= 1.26.13 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-49768 Patch Status Patched Published Jun 4, 2026 Affected Software Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms [happyforms] Researcher longnv719 More Details > Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-9691 Patch Status Patched Published Jun 5, 2026 Affected Software Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms [cf7-active-campaign] Researcher Frissi0n More Details > Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.6 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-49106 Patch Status Patched Published Jun 4, 2026 Affected Software Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms [cf7-constant-contact] Researcher Frissi0n More Details > Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.3.7 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-49763 Patch Status Patched Published Jun 4, 2026 Affected Software Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms [cf7-hubspot] Researcher Frissi0n More Details > Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-49104 Patch Status Patched Published Jun 5, 2026 Affected Software Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms [cf7-infusionsoft] Researcher Frissi0n More Details > Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-49765 Patch Status Patched Published Jun 4, 2026 Affected Software Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms [cf7-mailchimp] Researcher Frissi0n More Details > Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-49109 Patch Status Patched Published Jun 4, 2026 Affected Software Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms [cf7-salesforce] Researcher Frissi0n More Details > Moderno < 1.43 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-49108 Patch Status Patched Published Jun 4, 2026 Affected Software Moderno – Fashion & Clothing, Furniture [moderno] Researcher João Pedro Soares de Alcântara More Details > OttoKit: All-in-One Automation Platform <= 1.1.27 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-49781 Patch Status Patched Published Jun 4, 2026 Affected Software OttoKit: All-in-One Automation Platform [suretriggers] Researcher daroo More Details > SlimStat Analytics < 5.4.0 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-27410 Patch Status Patched Published Jun 1, 2026 Affected Software SlimStat Analytics [wp-slimstat] Researcher Drew Webber (mcdruid) More Details > Thrive Apprentice < 10.8.10.2 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-49107 Patch Status Patched Published Jun 4, 2026 Affected Software Thrive Apprentice [thrive-apprentice] Researcher dutafi More Details > WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-49085 Patch Status Patched Published Jun 5, 2026 Affected Software WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms [cf7-insightly] Researcher Frissi0n More Details > WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.7.12 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-49770 Patch Status Patched Published Jun 4, 2026 Affected Software WP Travel Engine – Tour Booking Plugin – Tour Operator Software [wp-travel-engine] Researcher daroo More Details > WP User Manager – User Profile Builder & Membership <= 2.9.16 - Authenticated (Subscriber+) Arbitrary File Deletion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-49766 Patch Status Patched Published Jun 5, 2026 Affected Software WP User Manager – User Profile Builder & Membership [wp-user-manager] Researcher endy More Details > WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-49105 Patch Status Patched Published Jun 5, 2026 Affected Software WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms [cf7-zendesk] Researcher Frissi0n More Details > wpForo Forum <= 3.1.0 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-49769 Patch Status Patched Published Jun 4, 2026 Affected Software wpForo Forum [wpforo] Researcher daroo More Details > Active Products Tables for WooCommerce. Use constructor to create tables  <= 1.0.9 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-42761 Patch Status Patched Published Jun 1, 2026 Affected Software Active Products Tables for WooCommerce. Use constructor to create tables  [profit-products-tables-for-woocommerce] Researcher hhhai More Details > ARMember Premium <= 7.3.1 - Unauthenticated SQL Injection via 'order' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-5073 Patch Status Patched Published Jun 2, 2026 Affected Software ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup [armember] Researcher h0xilo More Details > GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-49776 Patch Status Patched Published Jun 4, 2026 Affected Software GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites [gptranslate] Researcher Nguyen Dinh Hai (HaiND) More Details > JetSearch <= 3.5.17 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-49079 Patch Status Patched Published Jun 5, 2026 Affected Software JetSearch [jet-search] Researcher Bonds More Details > JetSmartFilters <= 3.8.1 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-48875 Patch Status Patched Published Jun 2, 2026 Affected Software JetSmartFilters [jet-smart-filters] Researcher Austin Ginder More Details > JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.9 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-48886 Patch Status Patched Published Jun 2, 2026 Affected Software JS Help Desk – AI-Powered Support & Ticketing System [js-support-ticket] Researcher sequence_X0 More Details > SP Project & Document Manager <= 4.71 - Missing Authorization to Unauthenticated Arbitrary File Information Disclosure via view_file() Function 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-10737 Patch Status Unpatched Published Jun 3, 2026 Affected Software SP Project & Document Manager [sp-client-document-manager] Researcher Namdn More Details > WP User Manager <= 2.9.17 - Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-9290 Patch Status Patched Published Jun 5, 2026 Affected Software WP User Manager – User Profile Builder & Membership [wp-user-manager] Researcher Yat More Details > All-In-One Security (AIOS) <= 5.4.7 - Unauthenticated Stored Cross-Site Scripting via REST API Request Path 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-8438 Patch Status Patched Published Jun 5, 2026 Affected Software All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall] Researcher Dmitrii Ignatyev More Details > AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.7.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-42775 Patch Status Patched Published Jun 3, 2026 Affected Software AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress [automatorwp] Researcher daroo More Details > Booking Package <= 1.7.16 - Authenticated (Editor+) Privilege Escalation via Account Takeover to updateUser AJAX Action 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-9851 Patch Status Patched Published Jun 5, 2026 Affected Software Booking Package [booking-package] Researcher Md. Moniruzzaman Prodhan (NomanProdhan) More Details > cformsII <= 15.1.3 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-39435 Patch Status Patched Published Jun 1, 2026 Affected Software cformsII [cforms2] Researcher Ilay Striechman More Details > Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-49055 Patch Status Patched Published Jun 3, 2026 Affected Software Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] Researcher fayespiegel More Details > Email Encoder < 0.3.12 (premium) < 1.0.25 (free) - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-5305 Patch Status Patched Published Jun 4, 2026 Affected Software Email Address Encoder [email-address-encoder]email-encoder-premium [email-encoder-premium] Researcher stealthcopter More Details > FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.15.0.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-48966 Patch Status Patched Published Jun 3, 2026 Affected Software FunnelKit – Funnel Builder for WooCommerce Checkout [funnel-builder] Researcher Tiago Ventura (perses) More Details > Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-10586 Patch Status Patched Published Jun 4, 2026 Affected Software Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] Researcher Shambles More Details > HollerBox — Fast & Effective Popups & Lead-Generation <= 2.3.10.1 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-48885 Patch Status Patched Published Jun 2, 2026 Affected Software HollerBox — Fast & Effective Popups & Lead-Generation [holler-box] Researcher she11f More Details > Integration for Freshsales <= 1.0.15 - Unauthenticated Stored Cross-Site Scripting via Form Submission Data 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-8901 Patch Status Patched Published Jun 5, 2026 Affected Software Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More [crm-integration-freshworks-any-form] Researcher PeterPatter More Details > MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-7537 Patch Status Patched Published Jun 5, 2026 Affected Software MDJM Event Management [mobile-dj-manager] Researcher Ryan Kozak More Details > MW WP Form <= 5.1.3 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-48871 Patch Status Patched Published Jun 1, 2026 Affected Software MW WP Form [mw-wp-form] Researcher VanTastic More Details > Product Filter Widget for Elementor <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-45437 Patch Status Unpatched Published Jun 1, 2026 Affected Software Product Filter Widget for Elementor [product-filter-widget-for-elementor] Researcher Evan NR More Details > Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 11.1.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-48867 Patch Status Patched Published Jun 3, 2026 Affected Software Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker [quiz-master-next] Researcher endy More Details > Stop Spammers Classic <= 2026.3 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-48876 Patch Status Patched Published Jun 1, 2026 Affected Software Stop Spammers Classic [stop-spammer-registrations-plugin] Researcher Peleg Nagli (ultrared.ai) More Details > VikBooking Hotel Booking Engine & PMS <= 1.8.9 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-42762 Patch Status Patched Published Jun 1, 2026 Affected Software VikBooking Hotel Booking Engine & PMS [vikbooking] Researcher anhcd05 More Details > WP Google Review Slider <= 17.9 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-39451 Patch Status Unpatched Published Jun 1, 2026 Affected Software WP Google Review Slider [wp-google-places-review-slider] Researcher hhhai More Details > WP Statistics – Simple, privacy-friendly Google Analytics alternative <= 14.16.6 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-48839 Patch Status Patched Published Jun 1, 2026 Affected Software WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] Researcher daroo More Details > WPFunnels Pro <= 2.9.4 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-49778 Patch Status Patched Published Jun 4, 2026 Affected Software WPFunnels Pro [wpfunnels-pro] Researcher dutafi More Details > LearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File Upload 6.6 CVSS Rating 6.6 (Medium) CVE-ID CVE-2026-7566 Patch Status Patched Published Jun 5, 2026 Affected Software LearnPress – Backup & Migration Tool [learnpress-import-export] Researcher Wannes Verwimp More Details > ARMember Premium <= 7.3.1 - Authenticated (Subscriber+) SQL Injection via 'sSortDir_0' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-5074 Patch Status Patched Published Jun 2, 2026 Affected Software ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup [armember] Researcher h0xilo More Details > ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-48964 Patch Status Patched Published Jun 2, 2026 Affected Software ELEX WordPress HelpDesk & Customer Ticketing System [elex-helpdesk-customer-support-ticket-system] Researcher Mukhlis Amien More Details > GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.8.7 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-48874 Patch Status Patched Published Jun 2, 2026 Affected Software GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress [gamipress] Researcher kai63001 More Details > Geo Mashup <= 1.13.19 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-48967 Patch Status Patched Published Jun 3, 2026 Affected Software Geo Mashup [geo-mashup] Researcher Jonathan Dersch More Details > MasterStudy LMS Pro Plus <= 4.8.20 - Authenticated (Instructor+) SQL Injection via 'columns' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-8653 Patch Status Patched Published Jun 3, 2026 Affected Software MasterStudy LMS Pro [masterstudy-lms-learning-management-system-pro] Researcher Rafie Muhammad More Details > Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.41 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-49771 Patch Status Patched Published Jun 4, 2026 Affected Software Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] Researcher daroo More Details > Photo Gallery by 10Web <= 1.8.41 - Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-9829 Patch Status Patched Published Jun 5, 2026 Affected Software Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] Researcher Jonah Burgess (CryptoCat) More Details > WP Time Slots Booking Form <= 1.2.50 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-48882 Patch Status Patched Published Jun 2, 2026 Affected Software WP Time Slots Booking Form [wp-time-slots-booking-form] Researcher xwii More Details > Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) <= 4.9 - Authenticated (Author+) Stored Cross-Site Scripting via Image Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-3722 Patch Status Patched Published Jun 1, 2026 Affected Software Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) [auto-image-attributes-from-filename-with-bulk-updater] Researcher kai63001 More Details > Click to Chat <= 4.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'num' Shortcode Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-7795 Patch Status Patched Published Jun 5, 2026 Affected Software Click to Chat – HoliThemes [click-to-chat-for-whatsapp] Researcher Valatty More Details > DeMomentSomTres Shortcodes <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-8885 Patch Status Unpatched Published Jun 1, 2026 Affected Software DeMomentSomTres Shortcodes [demomentsomtres-shortcodes] Researcher zakaria More Details > Easy Cart <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4080 Patch Status Unpatched Published Jun 1, 2026 Affected Software Easy Cart [easy-cart] Researcher zakaria More Details > EmbedPress <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block 'url' Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-7796 Patch Status Patched Published Jun 5, 2026 Affected Software EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more [embedpress] Researcher UKO More Details > Express Payment For Stripe <= 1.28.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-8893 Patch Status Patched Published Jun 5, 2026 Affected Software Express Payment For Stripe [wp-stripe-express] Researcher Muhammad Yudha - DJ More Details > FPW Category Thumbnails <= 1.9.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'id' Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-2382 Patch Status Unpatched Published Jun 1, 2026 Affected Software FPW Category Thumbnails [fpw-category-thumbnails] Researcher Nabil Irawan More Details > FV Flowplayer Video Player < 7.5.51.7212 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-49773 Patch Status Patched Published Jun 4, 2026 Affected Software FV Flowplayer Video Player [fv-wordpress-flowplayer] Researcher Jakub Herman More Details > King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder <= 51.1.62 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-48870 Patch Status Patched Published Jun 2, 2026 Affected Software King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder [king-addons] Researcher thevietronin More Details > Master Addons For Elementor <= 3.1.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'jtlma_custom_js' Page Setting (Custom JS Extension) 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-9281 Patch Status Patched Published Jun 5, 2026 Affected Software Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits [master-addons] Researchers KyokitoAthiwat Tiprasaharn (Jitlada)Itthidej Aramsri (Boeing777) More Details > Recipe Card Blocks Lite <= 3.4.13 - Authenticated (Author+) Stored Cross-Site Scripting via 'summary' and 'notes' 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-3011 Patch Status Patched Published Jun 7, 2026 Affected Software Recipe Card Blocks Lite [recipe-card-blocks-by-wpzoom] Researchers Athiwat Tiprasaharn (Jitlada)Itthidej Aramsri (Boeing777) More Details > Simple SEO Slideshow <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-8900 Patch Status Patched Published Jun 5, 2026 Affected Software Simple SEO Slideshow [simple-seo-slideshow] Researcher Gilang - DJ More Details > WP Job Portal – AI-Powered Recruitment System for Company or Job Board website <= 2.5.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-48880 Patch Status Patched Published Jun 2, 2026 Affected Software WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] Researcher Jonathan Dersch More Details > ZeM STL <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4081 Patch Status Unpatched Published Jun 1, 2026 Affected Software ZeM STL [zem-stl-viewer] Researcher Gilang - DJ More Details > Ad Inserter <= 2.8.15 - Reflected Cross-Site Scripting via URL Parameters in iframe Mode 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-9280 Patch Status Patched Published Jun 5, 2026 Affected Software Ad Inserter – Ad Manager & AdSense Ads [ad-inserter] Researcher darkmode More Details > Enfold - Responsive Multi-Purpose Theme <= 7.1.4 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-48869 Patch Status Patched Published Jun 1, 2026 Affected Software enfold [enfold] Researcher João Pedro Soares de Alcântara More Details > hiWeb Migration Simple <= 2.0.0.1 - Reflected Cross-Site Scripting via 'new_domain' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-2425 Patch Status Unpatched Published Jun 1, 2026 Affected Software hiWeb Migration Simple [hiweb-migration-simple] Researcher san6051 More Details > LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.6 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-48865 Patch Status Patched Published Jun 1, 2026 Affected Software LearnPress – WordPress LMS Plugin for Create and Sell Online Courses [learnpress] Researcher VanTastic More Details > rognone <= 0.6.2 - Reflected Cross-Site Scripting via 'a' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-1451 Patch Status Unpatched Published Jun 1, 2026 Affected Software rognone [rognone] Researcher san6051 More Details > rognone <= 0.6.2 - Reflected Cross-Site Scripting via 'mode' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-1450 Patch Status Unpatched Published Jun 1, 2026 Affected Software rognone [rognone] Researcher san6051 More Details > wp-nano-ad <= 1.31 - Authenticated (Administrator+) Stored Cross-Site Scripting via blogrole_link Parameter 5.5 CVSS Rating 5.5 (Medium) CVE-ID CVE-2025-5085 Patch Status Unpatched Published Jun 1, 2026 Affected Software WP Nano AD [wp-nano-ad] Researcher siyuan shao More Details > Tiled Gallery Carousel Without JetPack <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-image-title' 5.4 CVSS Rating 5.4 (Medium) CVE-ID CVE-2026-5191 Patch Status Unpatched Published Jun 1, 2026 Affected Software Tiled Gallery Carousel Without JetPack [tiled-gallery-carousel-without-jetpack] Researcher Webbernaut More Details > 10WebAdManager <= 1.0.11 - Unauthenticated Arbitrary File Download 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2019-25727 Patch Status Unpatched Published Jun 5, 2026 Affected Software 10WebAdManager [ad-manager-wd] Researcher(s): Unknown More Details > Booknetic <= 4.8.5 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-25439 Patch Status Unpatched Published Jun 1, 2026 Affected Software Booknetic [booknetic] Researcher Phat RiO More Details > Debug Log Manager <= 2.5.0 - Unauthenticated Improper Output Neutralization for Logs via log_js_errors AJAX Action 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-9016 Patch Status Patched Published Jun 5, 2026 Affected Software Debug Log Manager – Conveniently Monitor and Inspect Errors [debug-log-manager] Researcher Endang Alfarisi More Details > EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more <= 4.5.2 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-48872 Patch Status Patched Published Jun 1, 2026 Affected Software EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more [embedpress] Researcher Mukhlis Amien More Details > Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-7665 Patch Status Patched Published Jun 5, 2026 Affected Software Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] Researcher Anirudh Makkar More Details > Event Monster <= 2.1.0 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via em_capture_payment AJAX Action 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-8608 Patch Status Patched Published Jun 5, 2026 Affected Software Event Monster – Event Manager, Ticket Booking & Registration [event-monster] Researcher NAKLEH ZEIDAN More Details > Hybrid Composer <= 1.4.6 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2019-25738 Patch Status Patched Published Jun 5, 2026 Affected Software Hybrid Composer [hybrid-composer] Researcher(s): Unknown More Details > JobSearch WP Job Board <= 3.2.7 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-49057 Patch Status Patched Published Jun 3, 2026 Affected Software JobSearch WP Job Board [wp-jobsearch] Researcher adhikara13 More Details > JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.9 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-48887 Patch Status Patched Published Jun 2, 2026 Affected Software JS Help Desk – AI-Powered Support & Ticketing System [js-support-ticket] Researcher Nvz More Details > LearnPress <= 4.3.6 - Unauthenticated Sensitive Information Exposure via 'c_status' and 'return_type' Parameters 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-8502 Patch Status Patched Published Jun 5, 2026 Affected Software LearnPress – WordPress LMS Plugin for Create and Sell Online Courses [learnpress] Researcher Jamshed Yergashvoyev (CVE Guy) More Details > MapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Reference via REST API Endpoints 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-8839 Patch Status Patched Published Jun 5, 2026 Affected Software MapPress Maps for WordPress [mappress-google-maps-for-wordpress] Researcher Kitch More Details > Montonio for WooCommerce <= 10.1.2 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-48873 Patch Status Patched Published Jun 2, 2026 Affected Software Montonio for WooCommerce [montonio-for-woocommerce] Researcher Niv Kochan More Details > Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) <= 9.5.10 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-48970 Patch Status Patched Published Jun 3, 2026 Affected Software Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] Researcher RyuuKhagetsu More Details > RegistrationMagic – User Registration Forms Plugin <= 6.0.8.6 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-49764 Patch Status Patched Published Jun 4, 2026 Affected Software RegistrationMagic – User Registration Forms Plugin [custom-registration-form-builder-with-submission-manager] Researcher James Paremain More Details > Shared Files – Frontend File Upload Form & Secure File Sharing <= 1.7.64 - Unauthenticated Path Traversal 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-49112 Patch Status Patched Published Jun 5, 2026 Affected Software Shared Files – Frontend File Upload Form & Secure File Sharing [shared-files] Researcher kai63001 More Details > Simple Shopping Cart <= 5.2.9 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-48868 Patch Status Patched Published Jun 2, 2026 Affected Software Simple Shopping Cart [wordpress-simple-paypal-shopping-cart] Researcher Austin Ginder More Details > Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Solution <= 2.1.7 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-27089 Patch Status Patched Published Jun 1, 2026 Affected Software Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Solution [tour-booking-manager] Researcher benzdeus More Details > TrueBooker – Appointment Booking and Scheduler System <= 1.1.9 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-48881 Patch Status Patched Published Jun 2, 2026 Affected Software TrueBooker – Appointment Booking and Scheduler System [truebooker-appointment-booking] Researcher Vincent Sevkli More Details > Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups. <= 3.1.4 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-49110 Patch Status Patched Published Jun 4, 2026 Affected Software Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups. [upsell-order-bump-offer-for-woocommerce] Researcher Jakub Herman More Details > User Registration Stripe <= 1.3.12 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-49081 Patch Status Patched Published Jun 5, 2026 Affected Software User Registration Stripe [user-registration-stripe] Researcher 0xd4rk5id3 More Details > WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 4.9.4 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-49056 Patch Status Patched Published Jun 3, 2026 Affected Software WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels [print-invoices-packing-slip-labels-for-woocommerce] Researcher Jakub Herman More Details > Welcart e-Commerce <= 2.11.28 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-49775 Patch Status Patched Published Jun 4, 2026 Affected Software Welcart e-Commerce [usc-e-shop] Researcher dodoh4t More Details > Wp EMember <= v10.2.2 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-49077 Patch Status Unpatched Published Jun 4, 2026 Affected Software Wp EMember [wp-eMember] Researcher Tran Nguyen Bao Khanh More Details > WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-8385 Patch Status Patched Published Jun 5, 2026 Affected Software WP Go Maps – Google Maps, OpenStreetMap, Leaflet Map [wp-google-maps] Researcher Sudhanshu Chauhan More Details > WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.7.10 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-49078 Patch Status Patched Published Jun 5, 2026 Affected Software WP Travel Engine – Tour Booking Plugin – Tour Operator Software [wp-travel-engine] Researcher dodoh4t More Details > WPC Product Bundles for WooCommerce <= 8.5.3 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-48883 Patch Status Patched Published Jun 1, 2026 Affected Software WPC Product Bundles for WooCommerce [woo-product-bundle] Researcher Jakub Herman More Details > WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-7792 Patch Status Patched Published Jun 5, 2026 Affected Software WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] Researcher Valatty More Details > wpForo Forum <= 3.1.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-49767 Patch Status Patched Published Jun 4, 2026 Affected Software wpForo Forum [wpforo] Researcher Jakub Herman More Details > LearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-7565 Patch Status Patched Published Jun 5, 2026 Affected Software LearnPress – Backup & Migration Tool [learnpress-import-export] Researcher Wannes Verwimp More Details > OptinCraft <= 1.2.0 - Authenticated (Administrator+) SQL Injection via 'order_by' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-8978 Patch Status Patched Published Jun 5, 2026 Affected Software OptinCraft – Drag & Drop Optins & Popup Builder for WordPress [optincraft] Researcher Yousef Alraddadi More Details > Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-6448 Patch Status Patched Published Jun 5, 2026 Affected Software Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker [quiz-master-next] Researcher Drew Webber (mcdruid) More Details > Smart Slider 3 <= 3.5.1.36 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'src'/'srcset' Attribute in HTML Export 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-9197 Patch Status Patched Published Jun 5, 2026 Affected Software Smart Slider 3 [smart-slider-3] Researcher Nguyen Khanh Hao More Details > Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-8991 Patch Status Patched Published Jun 5, 2026 Affected Software Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7] Researcher Bao Luu Gia Nguyen More Details > Passeum Ticketing <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'shop_name' Setting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-7421 Patch Status Unpatched Published Jun 2, 2026 Affected Software Passeum Ticketing [passeum-ticketing] Researcher KEVIN LEE (crattack) More Details > Progress Planner <= 1.9.0 - Authenticated (Editor+) Stored Cross-Site Scripting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-28116 Patch Status Patched Published Jun 2, 2026 Affected Software Progress Planner [progress-planner] Researcher hongdo More Details > Quick Playground <= 1.3.4 - Authenticated (Administrator+) Arbitrary File Read via 'filename' Parameter 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-2500 Patch Status Patched Published Jun 5, 2026 Affected Software Quick Playground [quick-playground] Researcher Pablo Santiago More Details > Simple Custom Login Page <= 1.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-10100 Patch Status Patched Published Jun 1, 2026 Affected Software Simple Custom Login Page [simple-custom-login-page] Researcher Nguyen Duong More Details > Word Replacer <= 0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Replacement' Parameter 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-3620 Patch Status Unpatched Published Jun 1, 2026 Affected Software Word Replacer [word-replacer] Researcher san6051 More Details > WP Maps <= 4.9.4 - Authenticated (Admin+) Stored Cross-Site Scripting via 'location_messages' Parameter 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-9594 Patch Status Patched Published Jun 5, 2026 Affected Software WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] Researcher Yousef Alraddadi More Details > Alba Board <= 2.1.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'card_id' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-7523 Patch Status Patched Published Jun 5, 2026 Affected Software Alba Board [alba-board] Researcher Teerachai Somprasong More Details > Backup, Restore and Migrate your sites with XCloner <= 4.8.6 - Authenticated (Subscriber+) Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-48965 Patch Status Patched Published Jun 3, 2026 Affected Software Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore] Researcher kai63001 More Details > BirdSeed <= 2.2.0 - Cross-Site Request Forgery via BirdSeed Token Change 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-4071 Patch Status Unpatched Published Jun 1, 2026 Affected Software BirdSeed [birdseed] Researcher Nabil Irawan More Details > Charitable <= 1.8.11.1 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Attachment Deletion via 'avatar' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-10038 Patch Status Patched Published Jun 5, 2026 Affected Software Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] Researcher Khanh Nguyen More Details > Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons <= 1.4.8 - Authenticated (Subscriber+) Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-49082 Patch Status Patched Published Jun 5, 2026 Affected Software Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons [chatway-live-chat] Researcher dodoh4t More Details > Elementor Website Builder – more than just a page builder <= 4.1.0 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-49782 Patch Status Patched Published Jun 2, 2026 Affected Software Elementor Website Builder – more than just a page builder [elementor] Researcher Bonds More Details > EmergencyWP <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Update 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9732 Patch Status Unpatched Published Jun 2, 2026 Affected Software EmergencyWP – Dead Man's switch & legacy deliverance [emergencywp] Researcher swat More Details > Employee, Leave and Recruitment Management System – Crew HRM <= 1.2.2 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-27351 Patch Status Patched Published Jun 2, 2026 Affected Software Employee, Leave and Recruitment Management System – Crew HRM [hr-management] Researcher benzdeus More Details > Frontend User Notes <= 2.1.1 - Cross-Site Request Forgery to Note Content Modification via 'confirmEdit' Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-7047 Patch Status Patched Published Jun 5, 2026 Affected Software Frontend User Notes [frontend-user-notes] Researcher Mohamed Wajih Hichri (Assaults) More Details > Google Plus One Bottom <= 0.0.2 - Cross-Site Request Forgery to Plugin Settings Update via Settings Page 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9723 Patch Status Unpatched Published Jun 1, 2026 Affected Software Google Plus One Bottom [google-plus-one-bottom] Researcher swat More Details > JTL-Connector for WooCommerce <= 2.4.1 - Missing Authorization to Authenticated (Subscriber+) Settings Modification via Multiple Functions 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9234 Patch Status Unpatched Published Jun 1, 2026 Affected Software JTL-Connector for WooCommerce [woo-jtl-connector] Researcher Muhan Luo More Details > Klamra Paycal for Aspaclaria <= 1.1.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'invoice_id' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-8611 Patch Status Patched Published Jun 5, 2026 Affected Software Klamra Paycal for Aspaclaria [klamra-paycal-for-aspaclaria] Researcher KEVIN LEE (crattack) More Details > Laiser Tag <= 1.2.5 - Cross-Site Request Forgery to Plugin Settings Update via Settings Form 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9722 Patch Status Unpatched Published Jun 1, 2026 Affected Software Laiser Tag [laiser-tag] Researcher swat More Details > LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9719 Patch Status Patched Published Jun 5, 2026 Affected Software LatePoint – Calendar Booking Plugin for Appointments and Events [latepoint] Researcher Kirasec More Details > Page-list <= 6.2 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure via Shortcode Attributes 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9008 Patch Status Patched Published Jun 5, 2026 Affected Software Page-list [page-list] Researcher darkmode More Details > Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.271 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-34892 Patch Status Patched Published Jun 3, 2026 Affected Software Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] Researcher Jakub Herman More Details > Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) <= 9.5.9 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-48969 Patch Status Patched Published Jun 3, 2026 Affected Software Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] Researcher Evan NR More Details > Remove meta boxes per user role <= 1.01 - Cross-Site Request Forgery to Settings Update 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-8422 Patch Status Unpatched Published Jun 1, 2026 Affected Software Remove meta boxes per user role [remove-meta-boxes-per-user-role] Researcher Muhammad Nur Ibnu Hubab More Details > Remove NoFollow Commenter URL <= 1.0 - Cross-Site Request Forgery to Settings Update 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9730 Patch Status Unpatched Published Jun 1, 2026 Affected Software Remove NoFollow Commenter URL [remove-nofollow-commenter-link] Researcher swat More Details > RSS Aggregator by Feedzy <= 5.1.7 - Missing Authorization to Authenticated (Contributor+) Import Job Creation, Execution, Purge, Log Clearing, and Information Disclosure via Multiple AJAX Sub-Actions 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-8976 Patch Status Patched Published Jun 5, 2026 Affected Software RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] Researcher Jack Pas (Dark.) More Details > SEO Plugin by Squirrly SEO <= 12.4.16 - Missing Authorization to Authenticated (Contributor+) Privileged Cloud API Operations 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-7624 Patch Status Patched Published Jun 5, 2026 Affected Software SEO Plugin by Squirrly SEO [squirrly-seo] Researcher Abi Wiranata More Details > Slider Revolution 6.0.0-6.7.55 and 7.0.0-7.0.14 - Missing Authorization to Authenticated (Contributor+) Arbitrary Plugin Deactivation 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9050 Patch Status Patched Published Jun 1, 2026 Affected Software Slider Revolution [revslider] Researcher Nguyen Ngoc Duc (duc193) More Details > Slider Revolution 7.0.0 - 7.0.14 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9048 Patch Status Patched Published Jun 1, 2026 Affected Software Slider Revolution [revslider] Researcher Prickly Cactus More Details > Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions <= 8.4.1 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-42378 Patch Status Patched Published Jun 1, 2026 Affected Software Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions [wp-full-stripe-free] Researcher hhhai More Details > Tectite Forms <= 1.3 - Cross-Site Request Forgery to Settings Update 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9599 Patch Status Unpatched Published Jun 1, 2026 Affected Software Tectite Forms [tectite-forms] Researcher afnaan More Details > Visual Link Preview <= 2.4.1 - Authenticated (Subscriber+) Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-48878 Patch Status Patched Published Jun 2, 2026 Affected Software Visual Link Preview [visual-link-preview] Researcher Aliefis More Details > Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.128 - Authenticated (Admin+) Arbitrary Directory Deletion 3.8 CVSS Rating 3.8 (Low) CVE-ID CVE-2025-12656 Patch Status Patched Published Jun 5, 2026 Affected Software WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] Researcher blue0x1 More Details > As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence. This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can. Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. The post Wordfence Intelligence Weekly WordPress Vulnerability Report (June 1, 2026 to June 7, 2026) appeared first on Wordfence.
Quelle: www.wordfence.com