Wordfence Intelligence Weekly WordPress Vulnerability Report (June 1, 2026 to June 7, 2026)
Autor: Chloe Chamberland
⚠️ CVE-Referenzen:
CVE-2026-49771
CVE-2026-9016
CVE-2026-49770
CVE-2026-49056
CVE-2026-49782
CVE-2026-25439
CVE-2026-6448
CVE-2026-9719
CVE-2026-4080
CVE-2026-2382
CVE-2026-49105
CVE-2026-9722
CVE-2026-7796
CVE-2026-9594
CVE-2026-9234
CVE-2026-9281
CVE-2026-4081
CVE-2026-48886
CVE-2026-8901
CVE-2026-28116
CVE-2026-8502
CVE-2026-7566
CVE-2026-9691
CVE-2026-8653
CVE-2026-48873
CVE-2026-9732
CVE-2026-49768
CVE-2026-48883
CVE-2026-49774
CVE-2026-9197
CVE-2026-49765
CVE-2026-9290
CVE-2026-49764
CVE-2026-48889
CVE-2026-34892
CVE-2026-49113
CVE-2026-8978
CVE-2026-48874
CVE-2026-8900
CVE-2026-48970
CVE-2026-10737
CVE-2026-8608
CVE-2026-49107
CVE-2025-5085
CVE-2026-8385
CVE-2026-5073
CVE-2026-8206
CVE-2026-7654
CVE-2026-48867
CVE-2026-49077
CVE-2026-7624
CVE-2026-4071
CVE-2026-8893
CVE-2026-39451
CVE-2026-9730
CVE-2026-7523
CVE-2026-8611
CVE-2026-2425
CVE-2026-5076
CVE-2026-48965
CVE-2026-49780
CVE-2026-49781
CVE-2026-49776
CVE-2026-48885
CVE-2026-7795
CVE-2026-1829
CVE-2026-3722
CVE-2026-49078
CVE-2026-48966
CVE-2026-5191
CVE-2026-8991
CVE-2026-48964
CVE-2026-3620
CVE-2026-49104
CVE-2026-9723
CVE-2026-48870
CVE-2026-48880
CVE-2026-48875
CVE-2026-45437
CVE-2026-27089
CVE-2026-9008
CVE-2026-3011
CVE-2026-48878
CVE-2026-49773
CVE-2026-8438
CVE-2026-48882
CVE-2026-9851
CVE-2026-48839
CVE-2026-9599
CVE-2026-48871
CVE-2026-48876
CVE-2026-2500
CVE-2026-42761
CVE-2026-48872
CVE-2026-48969
CVE-2026-49767
CVE-2026-49108
CVE-2019-25727
CVE-2026-49055
CVE-2026-49110
CVE-2026-48836
CVE-2026-48879
CVE-2026-10100
CVE-2026-39435
CVE-2026-48868
CVE-2026-42762
CVE-2026-8885
CVE-2026-7565
CVE-2026-1451
CVE-2026-48869
CVE-2026-8422
CVE-2026-42775
CVE-2026-27351
CVE-2026-27410
CVE-2026-5305
CVE-2026-7792
CVE-2026-49085
CVE-2026-49775
CVE-2026-7665
CVE-2026-5411
CVE-2026-9050
CVE-2026-10580
CVE-2026-9280
CVE-2026-5074
CVE-2026-9690
CVE-2026-27395
CVE-2026-42378
CVE-2026-49106
CVE-2026-48887
CVE-2026-8839
CVE-2026-49766
CVE-2026-48967
CVE-2026-48881
CVE-2026-48865
CVE-2026-49079
CVE-2026-5415
CVE-2026-49763
CVE-2026-49769
CVE-2026-7421
CVE-2026-10586
CVE-2026-49112
CVE-2026-8976
CVE-2026-9829
CVE-2026-49081
CVE-2026-49109
CVE-2026-7537
CVE-2026-49083
CVE-2026-49777
CVE-2026-49778
CVE-2026-49082
CVE-2025-12656
CVE-2026-1450
CVE-2026-10038
CVE-2019-25738
CVE-2026-9048
CVE-2026-49057
CVE-2026-48866
CVE-2026-7047
Last week, there were 159 vulnerabilities disclosed in 140 WordPress Plugins and 2 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 96 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 35,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 – Unauthenticated Authentication Bypass via UpdraftCentral udrpc
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status
Number of Vulnerabilities
Patched
134
Unpatched
25
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating
Number of Vulnerabilities
Low Severity
1
Medium Severity
96
High Severity
53
Critical Severity
9
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE
Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
43
Missing Authorization
28
Deserialization of Untrusted Data
17
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
16
Cross-Site Request Forgery (CSRF)
9
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
9
Exposure of Sensitive Information to an Unauthorized Actor
7
Authorization Bypass Through User-Controlled Key
6
Improper Control of Generation of Code ('Code Injection')
5
Incorrect Privilege Assignment
4
Improper Privilege Management
2
Insufficient Verification of Data Authenticity
2
Unrestricted Upload of File with Dangerous Type
2
Authentication Bypass Using an Alternate Path or Channel
1
Embedded Malicious Code
1
External Control of File Name or Path
1
Improper Authentication
1
Improper Authorization
1
Improper Input Validation
1
Improper Output Neutralization for Logs
1
Incorrect Authorization
1
Server-Side Request Forgery (SSRF)
1
Researchers That Contributed to WordPress Security Last Week
Researcher Name
Number of Vulnerabilities
Frissi0n
8
daroo
8
Jakub Herman
6
dodoh4t
4
san6051
4
kai63001
4
swat
4
h0xilo
4
VanTastic
3
hhhai
3
dutafi
2
Gilang - DJ
2
darkmode
2
Wannes Verwimp
2
João Pedro Soares de Alcântara
2
Jonathan Dersch
2
Nabil Irawan
2
ZAST.AI
2
Bonds
2
Nguyen Ngoc Duc (duc193)
2
Mukhlis Amien
2
KEVIN LEE (crattack)
2
Evan NR
2
Athiwat Tiprasaharn (Jitlada)
2
Itthidej Aramsri (Boeing777)
2
Valatty
2
benzdeus
2
zakaria
2
0xd4rk5id3
2
Nguyen Dinh Hai (HaiND)
2
Austin Ginder
2
endy
2
Nguyen Ba Khanh
2
Phat RiO
2
Yousef Alraddadi
2
Drew Webber (mcdruid)
2
Bao Luu Gia Nguyen
1
Osvaldo Noe Gonzalez Del Rio (Os)
1
Nguyen Khanh Hao
1
Shambles
1
Muhan Luo
1
thevietronin
1
Nvz
1
Muhammad Yudha - DJ
1
James Paremain
1
Endang Alfarisi
1
hongdo
1
xwii
1
longnv719
1
Webbernaut
1
anhcd05
1
Namdn
1
blue0x1
1
Abi Wiranata
1
siyuan shao
1
sequence_X0
1
CHOIGYEONGMIN
1
Ryan Kozak
1
Mohamed Wajih Hichri (Assaults)
1
Kyokito
1
Khanh Nguyen
1
Aliefis
1
Vincent Sevkli
1
Mitchell
1
Ilay Striechman
1
Md. Moniruzzaman Prodhan (NomanProdhan)
1
Yat
1
she11f
1
Anirudh Makkar
1
Tiago Ventura (perses)
1
afnaan
1
Nguyen Duong
1
Kitch
1
UKO
1
Jamshed Yergashvoyev (CVE Guy)
1
PeterPatter
1
Pablo Santiago
1
Peleg Nagli (ultrared.ai)
1
RyuuKhagetsu
1
Tran Nguyen Bao Khanh
1
stealthcopter
1
Kirasec
1
Jonah Burgess (CryptoCat)
1
Dmitrii Ignatyev
1
NAKLEH ZEIDAN
1
Sudhanshu Chauhan
1
Prickly Cactus
1
Muhammad Nur Ibnu Hubab
1
Jack Pas (Dark.)
1
fayespiegel
1
ParkHyunWoo
1
Teerachai Somprasong
1
Rafie Muhammad
1
Shane
1
Niv Kochan
1
adhikara13
1
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name
Software Slug
10WebAdManager
ad-manager-wd
Active Products Tables for WooCommerce. Use constructor to create tables
profit-products-tables-for-woocommerce
Ad Inserter – Ad Manager & AdSense Ads
ad-inserter
Admin Columns
codepress-admin-columns
Advanced Google reCAPTCHA
advanced-google-recaptcha
AI Chatbot & Workflow Automation by AIWU
ai-copilot-content-generator
Alba Board
alba-board
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup
armember
Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO)
auto-image-attributes-from-filename-with-bulk-updater
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress
automatorwp
Backup, Restore and Migrate your sites with XCloner
xcloner-backup-and-restore
BirdSeed
birdseed
Booking for Appointments and Events Calendar – Amelia
ameliabooking
Booking Package
booking-package
Booknetic
booknetic
cformsII
cforms2
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
charitable
Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons
chatway-live-chat
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
Content Visibility for Divi Builder
content-visibility-for-divi-builder
Cornerstone
cornerstone
Debug Log Manager – Conveniently Monitor and Inspect Errors
debug-log-manager
DeMomentSomTres Shortcodes
demomentsomtres-shortcodes
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy
dokan-lite
Drag and Drop Multiple File Upload for Contact Form 7
drag-and-drop-multiple-file-upload-contact-form-7
Easy Cart
easy-cart
Easy Invoice – Invoice Generator, PDF Quotes & Payments
easy-invoice
Elementor Website Builder – more than just a page builder
elementor
ELEX WordPress HelpDesk & Customer Ticketing System
elex-helpdesk-customer-support-ticket-system
Email Address Encoder
email-address-encoder
email-encoder-premium
email-encoder-premium
EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more
embedpress
EmergencyWP – Dead Man's switch & legacy deliverance
emergencywp
Employee, Leave and Recruitment Management System – Crew HRM
hr-management
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Event Monster – Event Manager, Ticket Booking & Registration
event-monster
Express Payment For Stripe
wp-stripe-express
FPW Category Thumbnails
fpw-category-thumbnails
Frontend User Notes
frontend-user-notes
FunnelKit – Funnel Builder for WooCommerce Checkout
funnel-builder
FV Flowplayer Video Player
fv-wordpress-flowplayer
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress
gamipress
Geo Mashup
geo-mashup
Google Plus One Bottom
google-plus-one-bottom
GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites
gptranslate
Gravity Forms
gravityforms
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
essential-blocks
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms
happyforms
Hippoo Mobile App for WooCommerce
hippoo
hiWeb Migration Simple
hiweb-migration-simple
HollerBox — Fast & Effective Popups & Lead-Generation
holler-box
Hybrid Composer
hybrid-composer
Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms
cf7-active-campaign
Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms
cf7-constant-contact
Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More
crm-integration-freshworks-any-form
Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms
cf7-hubspot
Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms
cf7-infusionsoft
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms
cf7-mailchimp
Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms
cf7-salesforce
JetSearch
jet-search
JetSmartFilters
jet-smart-filters
JobSearch WP Job Board
wp-jobsearch
JS Help Desk – AI-Powered Support & Ticketing System
js-support-ticket
JTL-Connector for WooCommerce
woo-jtl-connector
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder
king-addons
Kirki – Freeform Page Builder, Website Builder & Customizer
kirki
Klamra Paycal for Aspaclaria
klamra-paycal-for-aspaclaria
Laiser Tag
laiser-tag
LatePoint – Calendar Booking Plugin for Appointments and Events
latepoint
LearnPress – Backup & Migration Tool
learnpress-import-export
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
learnpress
MapPress Maps for WordPress
mappress-google-maps-for-wordpress
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits
master-addons
MasterStudy LMS Pro
masterstudy-lms-learning-management-system-pro
MDJM Event Management
mobile-dj-manager
Media folder Addon
wp-media-folder-addon
Montonio for WooCommerce
montonio-for-woocommerce
MW WP Form
mw-wp-form
OptinCraft – Drag & Drop Optins & Popup Builder for WordPress
optincraft
OttoKit: All-in-One Automation Platform
suretriggers
Page-list
page-list
Passeum Ticketing
passeum-ticketing
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
photo-gallery
Product Filter Widget for Elementor
product-filter-widget-for-elementor
Product Slider Pro for WooCommerce
woo-product-slider-pro
Progress Planner
progress-planner
Quick Playground
quick-playground
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker
quiz-master-next
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings
seo-by-rank-math
RD Station
integracao-rd-station
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
really-simple-ssl
Recipe Card Blocks Lite
recipe-card-blocks-by-wpzoom
RegistrationMagic – User Registration Forms Plugin
custom-registration-form-builder-with-submission-manager
Remove meta boxes per user role
remove-meta-boxes-per-user-role
Remove NoFollow Commenter URL
remove-nofollow-commenter-link
rognone
rognone
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator
feedzy-rss-feeds
SEO Plugin by Squirrly SEO
squirrly-seo
Shared Files – Frontend File Upload Form & Secure File Sharing
shared-files
Simple Custom Login Page
simple-custom-login-page
Simple SEO Slideshow
simple-seo-slideshow
Simple Shopping Cart
wordpress-simple-paypal-shopping-cart
Slider Revolution
revslider
SlimStat Analytics
wp-slimstat
Smart Slider 3
smart-slider-3
SP Project & Document Manager
sp-client-document-manager
Stop Spammers Classic
stop-spammer-registrations-plugin
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions
wp-full-stripe-free
Support Board
supportboard
Tectite Forms
tectite-forms
Thrive Apprentice
thrive-apprentice
Tiled Gallery Carousel Without JetPack
tiled-gallery-carousel-without-jetpack
Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Solution
tour-booking-manager
TrueBooker – Appointment Booking and Scheduler System
truebooker-appointment-booking
Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups.
upsell-order-bump-offer-for-woocommerce
User Registration Stripe
user-registration-stripe
VikBooking Hotel Booking Engine & PMS
vikbooking
Visual Link Preview
visual-link-preview
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels
print-invoices-packing-slip-labels-for-woocommerce
Welcart e-Commerce
usc-e-shop
Word Replacer
word-replacer
Wp EMember
wp-eMember
WP Go Maps – Google Maps, OpenStreetMap, Leaflet Map
wp-google-maps
WP Google Review Slider
wp-google-places-review-slider
WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
cf7-insightly
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website
wp-job-portal
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters
wp-google-map-plugin
WP Nano AD
wp-nano-ad
WP Statistics – Simple, privacy-friendly Google Analytics alternative
wp-statistics
WP Time Slots Booking Form
wp-time-slots-booking-form
WP Travel Engine – Tour Booking Plugin – Tour Operator Software
wp-travel-engine
WP User Manager – User Profile Builder & Membership
wp-user-manager
WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
cf7-zendesk
WPC Product Bundles for WooCommerce
woo-product-bundle
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
wpForo Forum
wpforo
WPFunnels Pro
wpfunnels-pro
WPvivid — Backup, Migration & Staging
wpvivid-backuprestore
ZeM STL
zem-stl-viewer
WordPress Themes with Reported Vulnerabilities Last Week
Software Name
Software Slug
enfold
enfold
Moderno – Fashion & Clothing, Furniture
moderno
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
AI Chatbot & Workflow Automation by AIWU <= 1.4.17 - Unauthenticated Privilege Escalation
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-48879
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
AI Chatbot & Workflow Automation by AIWU [ai-copilot-content-generator]
Researcher
daroo
More Details >
ARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-5076
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup [armember]
Researcher
h0xilo
More Details >
Easy Invoice – Invoice Generator, PDF Quotes & Payments <= 2.1.19 - Unauthenticated Remote Code Execution
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-48836
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
Easy Invoice – Invoice Generator, PDF Quotes & Payments [easy-invoice]
Researcher
Nguyen Dinh Hai (HaiND)
More Details >
Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-10580
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Hippoo Mobile App for WooCommerce [hippoo]
Researcher
Mitchell
More Details >
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-8206
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
Kirki – Freeform Page Builder, Website Builder & Customizer [kirki]
Researcher
CHOIGYEONGMIN
More Details >
Product Slider Pro for WooCommerce < 3.5.4 - Backdoored Software
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-49777
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
Product Slider Pro for WooCommerce [woo-product-slider-pro]
Researcher
Shane
More Details >
Support Board < 3.8.9 - Unauthenticated Privilege Escalation
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-27395
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
Support Board [supportboard]
Researcher
Phat RiO
More Details >
Gravity Forms <= 2.10.0.1 - Unauthenticated Arbitrary File Deletion
9.1
CVSS Rating
9.1 (Critical)
CVE-ID
CVE-2026-48866
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
Gravity Forms [gravityforms]
Researcher
daroo
More Details >
Media folder Addon <= 4.0.1 - Unauthenticated Arbitrary File Download
9.1
CVSS Rating
9.1 (Critical)
CVE-ID
CVE-2026-9690
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
Media folder Addon [wp-media-folder-addon]
Researcher
0xd4rk5id3
More Details >
Admin Columns <= 7.0.18 - Authenticated (Contributor+) PHP Object Injection to Remote Code Execution via Custom Field Meta Value
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-7654
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Admin Columns [codepress-admin-columns]
Researcher
Osvaldo Noe Gonzalez Del Rio (Os)
More Details >
Booking for Appointments and Events Calendar – Amelia <= 2.3 - Authenticated (Subscriber+) Privilege Escalation
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-48889
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
Booking for Appointments and Events Calendar – Amelia [ameliabooking]
Researcher
dodoh4t
More Details >
Content Visibility for Divi Builder <= 4.02 - Authenticated (Contributor+) Remote Code Execution
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-1829
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
Content Visibility for Divi Builder [content-visibility-for-divi-builder]
Researcher
ZAST.AI
More Details >
Content Visibility for Divi Builder <= 4.02 - Authenticated (Contributor+) Remote Code Execution
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-1829
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
Content Visibility for Divi Builder [content-visibility-for-divi-builder]
Researcher
ZAST.AI
More Details >
Cornerstone < 7.8.8 - Authenticated (Subscriber+) Arbitrary Code Execution
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-49113
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
Cornerstone [cornerstone]
Researcher
Nguyen Ba Khanh
More Details >
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.2 - Authenticated (Customer+) Privilege Escalation
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-49780
Patch Status
Patched
Published
Jun 3, 2026
Affected Software
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite]
Researcher
Nguyen Ba Khanh
More Details >
LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.5.1 - Authenticated (Contributor+) Privilege Escalation
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-49083
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
LatePoint – Calendar Booking Plugin for Appointments and Events [latepoint]
Researcher
VanTastic
More Details >
RD Station <= 5.6.0 - Authenticated (Contributor+) Remote Code Execution
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-49774
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
RD Station [integracao-rd-station]
Researcher
ParkHyunWoo
More Details >
WP Captcha PRO <= 5.38 - Authenticated (Subscriber+) Authentication Bypass via Temporary Login Link
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-5415
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Advanced Google reCAPTCHA [advanced-google-recaptcha]
Researcher
Nguyen Ngoc Duc (duc193)
More Details >
WP Captcha PRO <= 5.38 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-5411
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Advanced Google reCAPTCHA [advanced-google-recaptcha]
Researcher
h0xilo
More Details >
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms <= 1.26.13 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-49768
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms [happyforms]
Researcher
longnv719
More Details >
Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-9691
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms [cf7-active-campaign]
Researcher
Frissi0n
More Details >
Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.6 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-49106
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms [cf7-constant-contact]
Researcher
Frissi0n
More Details >
Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.3.7 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-49763
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms [cf7-hubspot]
Researcher
Frissi0n
More Details >
Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-49104
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms [cf7-infusionsoft]
Researcher
Frissi0n
More Details >
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-49765
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms [cf7-mailchimp]
Researcher
Frissi0n
More Details >
Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-49109
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms [cf7-salesforce]
Researcher
Frissi0n
More Details >
Moderno < 1.43 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-49108
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
Moderno – Fashion & Clothing, Furniture [moderno]
Researcher
João Pedro Soares de Alcântara
More Details >
OttoKit: All-in-One Automation Platform <= 1.1.27 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-49781
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
OttoKit: All-in-One Automation Platform [suretriggers]
Researcher
daroo
More Details >
SlimStat Analytics < 5.4.0 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-27410
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
SlimStat Analytics [wp-slimstat]
Researcher
Drew Webber (mcdruid)
More Details >
Thrive Apprentice < 10.8.10.2 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-49107
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
Thrive Apprentice [thrive-apprentice]
Researcher
dutafi
More Details >
WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-49085
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms [cf7-insightly]
Researcher
Frissi0n
More Details >
WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.7.12 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-49770
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
WP Travel Engine – Tour Booking Plugin – Tour Operator Software [wp-travel-engine]
Researcher
daroo
More Details >
WP User Manager – User Profile Builder & Membership <= 2.9.16 - Authenticated (Subscriber+) Arbitrary File Deletion
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-49766
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
WP User Manager – User Profile Builder & Membership [wp-user-manager]
Researcher
endy
More Details >
WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-49105
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms [cf7-zendesk]
Researcher
Frissi0n
More Details >
wpForo Forum <= 3.1.0 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-49769
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
wpForo Forum [wpforo]
Researcher
daroo
More Details >
Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.9 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-42761
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
Active Products Tables for WooCommerce. Use constructor to create tables [profit-products-tables-for-woocommerce]
Researcher
hhhai
More Details >
ARMember Premium <= 7.3.1 - Unauthenticated SQL Injection via 'order' Parameter
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-5073
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup [armember]
Researcher
h0xilo
More Details >
GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-49776
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites [gptranslate]
Researcher
Nguyen Dinh Hai (HaiND)
More Details >
JetSearch <= 3.5.17 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-49079
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
JetSearch [jet-search]
Researcher
Bonds
More Details >
JetSmartFilters <= 3.8.1 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-48875
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
JetSmartFilters [jet-smart-filters]
Researcher
Austin Ginder
More Details >
JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.9 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-48886
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
JS Help Desk – AI-Powered Support & Ticketing System [js-support-ticket]
Researcher
sequence_X0
More Details >
SP Project & Document Manager <= 4.71 - Missing Authorization to Unauthenticated Arbitrary File Information Disclosure via view_file() Function
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-10737
Patch Status
Unpatched
Published
Jun 3, 2026
Affected Software
SP Project & Document Manager [sp-client-document-manager]
Researcher
Namdn
More Details >
WP User Manager <= 2.9.17 - Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-9290
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
WP User Manager – User Profile Builder & Membership [wp-user-manager]
Researcher
Yat
More Details >
All-In-One Security (AIOS) <= 5.4.7 - Unauthenticated Stored Cross-Site Scripting via REST API Request Path
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-8438
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
All-In-One Security (AIOS) – Security and Firewall [all-in-one-wp-security-and-firewall]
Researcher
Dmitrii Ignatyev
More Details >
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.7.2 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-42775
Patch Status
Patched
Published
Jun 3, 2026
Affected Software
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress [automatorwp]
Researcher
daroo
More Details >
Booking Package <= 1.7.16 - Authenticated (Editor+) Privilege Escalation via Account Takeover to updateUser AJAX Action
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-9851
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Booking Package [booking-package]
Researcher
Md. Moniruzzaman Prodhan (NomanProdhan)
More Details >
cformsII <= 15.1.3 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-39435
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
cformsII [cforms2]
Researcher
Ilay Striechman
More Details >
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-49055
Patch Status
Patched
Published
Jun 3, 2026
Affected Software
Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7]
Researcher
fayespiegel
More Details >
Email Encoder < 0.3.12 (premium) < 1.0.25 (free) - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-5305
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
Email Address Encoder [email-address-encoder]email-encoder-premium [email-encoder-premium]
Researcher
stealthcopter
More Details >
FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.15.0.2 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-48966
Patch Status
Patched
Published
Jun 3, 2026
Affected Software
FunnelKit – Funnel Builder for WooCommerce Checkout [funnel-builder]
Researcher
Tiago Ventura (perses)
More Details >
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-10586
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks]
Researcher
Shambles
More Details >
HollerBox — Fast & Effective Popups & Lead-Generation <= 2.3.10.1 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-48885
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
HollerBox — Fast & Effective Popups & Lead-Generation [holler-box]
Researcher
she11f
More Details >
Integration for Freshsales <= 1.0.15 - Unauthenticated Stored Cross-Site Scripting via Form Submission Data
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-8901
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More [crm-integration-freshworks-any-form]
Researcher
PeterPatter
More Details >
MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-7537
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
MDJM Event Management [mobile-dj-manager]
Researcher
Ryan Kozak
More Details >
MW WP Form <= 5.1.3 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-48871
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
MW WP Form [mw-wp-form]
Researcher
VanTastic
More Details >
Product Filter Widget for Elementor <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-45437
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
Product Filter Widget for Elementor [product-filter-widget-for-elementor]
Researcher
Evan NR
More Details >
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 11.1.2 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-48867
Patch Status
Patched
Published
Jun 3, 2026
Affected Software
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker [quiz-master-next]
Researcher
endy
More Details >
Stop Spammers Classic <= 2026.3 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-48876
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
Stop Spammers Classic [stop-spammer-registrations-plugin]
Researcher
Peleg Nagli (ultrared.ai)
More Details >
VikBooking Hotel Booking Engine & PMS <= 1.8.9 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-42762
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
VikBooking Hotel Booking Engine & PMS [vikbooking]
Researcher
anhcd05
More Details >
WP Google Review Slider <= 17.9 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-39451
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
WP Google Review Slider [wp-google-places-review-slider]
Researcher
hhhai
More Details >
WP Statistics – Simple, privacy-friendly Google Analytics alternative <= 14.16.6 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-48839
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics]
Researcher
daroo
More Details >
WPFunnels Pro <= 2.9.4 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-49778
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
WPFunnels Pro [wpfunnels-pro]
Researcher
dutafi
More Details >
LearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File Upload
6.6
CVSS Rating
6.6 (Medium)
CVE-ID
CVE-2026-7566
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
LearnPress – Backup & Migration Tool [learnpress-import-export]
Researcher
Wannes Verwimp
More Details >
ARMember Premium <= 7.3.1 - Authenticated (Subscriber+) SQL Injection via 'sSortDir_0' Parameter
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-5074
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup [armember]
Researcher
h0xilo
More Details >
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 - Authenticated (Subscriber+) SQL Injection
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-48964
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
ELEX WordPress HelpDesk & Customer Ticketing System [elex-helpdesk-customer-support-ticket-system]
Researcher
Mukhlis Amien
More Details >
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.8.7 - Authenticated (Subscriber+) SQL Injection
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-48874
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress [gamipress]
Researcher
kai63001
More Details >
Geo Mashup <= 1.13.19 - Authenticated (Subscriber+) SQL Injection
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-48967
Patch Status
Patched
Published
Jun 3, 2026
Affected Software
Geo Mashup [geo-mashup]
Researcher
Jonathan Dersch
More Details >
MasterStudy LMS Pro Plus <= 4.8.20 - Authenticated (Instructor+) SQL Injection via 'columns' Parameter
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-8653
Patch Status
Patched
Published
Jun 3, 2026
Affected Software
MasterStudy LMS Pro [masterstudy-lms-learning-management-system-pro]
Researcher
Rafie Muhammad
More Details >
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.41 - Authenticated (Contributor+) SQL Injection
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-49771
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery]
Researcher
daroo
More Details >
Photo Gallery by 10Web <= 1.8.41 - Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-9829
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery]
Researcher
Jonah Burgess (CryptoCat)
More Details >
WP Time Slots Booking Form <= 1.2.50 - Authenticated (Subscriber+) SQL Injection
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-48882
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
WP Time Slots Booking Form [wp-time-slots-booking-form]
Researcher
xwii
More Details >
Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) <= 4.9 - Authenticated (Author+) Stored Cross-Site Scripting via Image Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-3722
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) [auto-image-attributes-from-filename-with-bulk-updater]
Researcher
kai63001
More Details >
Click to Chat <= 4.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'num' Shortcode Parameter
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-7795
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Click to Chat – HoliThemes [click-to-chat-for-whatsapp]
Researcher
Valatty
More Details >
DeMomentSomTres Shortcodes <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-8885
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
DeMomentSomTres Shortcodes [demomentsomtres-shortcodes]
Researcher
zakaria
More Details >
Easy Cart <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-4080
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
Easy Cart [easy-cart]
Researcher
zakaria
More Details >
EmbedPress <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block 'url' Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-7796
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more [embedpress]
Researcher
UKO
More Details >
Express Payment For Stripe <= 1.28.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-8893
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Express Payment For Stripe [wp-stripe-express]
Researcher
Muhammad Yudha - DJ
More Details >
FPW Category Thumbnails <= 1.9.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'id' Parameter
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-2382
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
FPW Category Thumbnails [fpw-category-thumbnails]
Researcher
Nabil Irawan
More Details >
FV Flowplayer Video Player < 7.5.51.7212 - Authenticated (Subscriber+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-49773
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
FV Flowplayer Video Player [fv-wordpress-flowplayer]
Researcher
Jakub Herman
More Details >
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder <= 51.1.62 - Authenticated (Subscriber+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-48870
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder [king-addons]
Researcher
thevietronin
More Details >
Master Addons For Elementor <= 3.1.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'jtlma_custom_js' Page Setting (Custom JS Extension)
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-9281
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits [master-addons]
Researchers
KyokitoAthiwat Tiprasaharn (Jitlada)Itthidej Aramsri (Boeing777)
More Details >
Recipe Card Blocks Lite <= 3.4.13 - Authenticated (Author+) Stored Cross-Site Scripting via 'summary' and 'notes'
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-3011
Patch Status
Patched
Published
Jun 7, 2026
Affected Software
Recipe Card Blocks Lite [recipe-card-blocks-by-wpzoom]
Researchers
Athiwat Tiprasaharn (Jitlada)Itthidej Aramsri (Boeing777)
More Details >
Simple SEO Slideshow <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-8900
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Simple SEO Slideshow [simple-seo-slideshow]
Researcher
Gilang - DJ
More Details >
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website <= 2.5.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-48880
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal]
Researcher
Jonathan Dersch
More Details >
ZeM STL <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-4081
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
ZeM STL [zem-stl-viewer]
Researcher
Gilang - DJ
More Details >
Ad Inserter <= 2.8.15 - Reflected Cross-Site Scripting via URL Parameters in iframe Mode
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-9280
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Ad Inserter – Ad Manager & AdSense Ads [ad-inserter]
Researcher
darkmode
More Details >
Enfold - Responsive Multi-Purpose Theme <= 7.1.4 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-48869
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
enfold [enfold]
Researcher
João Pedro Soares de Alcântara
More Details >
hiWeb Migration Simple <= 2.0.0.1 - Reflected Cross-Site Scripting via 'new_domain' Parameter
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-2425
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
hiWeb Migration Simple [hiweb-migration-simple]
Researcher
san6051
More Details >
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.6 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-48865
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses [learnpress]
Researcher
VanTastic
More Details >
rognone <= 0.6.2 - Reflected Cross-Site Scripting via 'a' Parameter
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-1451
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
rognone [rognone]
Researcher
san6051
More Details >
rognone <= 0.6.2 - Reflected Cross-Site Scripting via 'mode' Parameter
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-1450
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
rognone [rognone]
Researcher
san6051
More Details >
wp-nano-ad <= 1.31 - Authenticated (Administrator+) Stored Cross-Site Scripting via blogrole_link Parameter
5.5
CVSS Rating
5.5 (Medium)
CVE-ID
CVE-2025-5085
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
WP Nano AD [wp-nano-ad]
Researcher
siyuan shao
More Details >
Tiled Gallery Carousel Without JetPack <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-image-title'
5.4
CVSS Rating
5.4 (Medium)
CVE-ID
CVE-2026-5191
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
Tiled Gallery Carousel Without JetPack [tiled-gallery-carousel-without-jetpack]
Researcher
Webbernaut
More Details >
10WebAdManager <= 1.0.11 - Unauthenticated Arbitrary File Download
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2019-25727
Patch Status
Unpatched
Published
Jun 5, 2026
Affected Software
10WebAdManager [ad-manager-wd]
Researcher(s): Unknown
More Details >
Booknetic <= 4.8.5 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-25439
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
Booknetic [booknetic]
Researcher
Phat RiO
More Details >
Debug Log Manager <= 2.5.0 - Unauthenticated Improper Output Neutralization for Logs via log_js_errors AJAX Action
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-9016
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Debug Log Manager – Conveniently Monitor and Inspect Errors [debug-log-manager]
Researcher
Endang Alfarisi
More Details >
EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more <= 4.5.2 - Unauthenticated Information Exposure
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-48872
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more [embedpress]
Researcher
Mukhlis Amien
More Details >
Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-7665
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite]
Researcher
Anirudh Makkar
More Details >
Event Monster <= 2.1.0 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via em_capture_payment AJAX Action
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-8608
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Event Monster – Event Manager, Ticket Booking & Registration [event-monster]
Researcher
NAKLEH ZEIDAN
More Details >
Hybrid Composer <= 1.4.6 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2019-25738
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Hybrid Composer [hybrid-composer]
Researcher(s): Unknown
More Details >
JobSearch WP Job Board <= 3.2.7 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-49057
Patch Status
Patched
Published
Jun 3, 2026
Affected Software
JobSearch WP Job Board [wp-jobsearch]
Researcher
adhikara13
More Details >
JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.9 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-48887
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
JS Help Desk – AI-Powered Support & Ticketing System [js-support-ticket]
Researcher
Nvz
More Details >
LearnPress <= 4.3.6 - Unauthenticated Sensitive Information Exposure via 'c_status' and 'return_type' Parameters
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-8502
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses [learnpress]
Researcher
Jamshed Yergashvoyev (CVE Guy)
More Details >
MapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Reference via REST API Endpoints
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-8839
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
MapPress Maps for WordPress [mappress-google-maps-for-wordpress]
Researcher
Kitch
More Details >
Montonio for WooCommerce <= 10.1.2 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-48873
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
Montonio for WooCommerce [montonio-for-woocommerce]
Researcher
Niv Kochan
More Details >
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) <= 9.5.10 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-48970
Patch Status
Patched
Published
Jun 3, 2026
Affected Software
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl]
Researcher
RyuuKhagetsu
More Details >
RegistrationMagic – User Registration Forms Plugin <= 6.0.8.6 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-49764
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
RegistrationMagic – User Registration Forms Plugin [custom-registration-form-builder-with-submission-manager]
Researcher
James Paremain
More Details >
Shared Files – Frontend File Upload Form & Secure File Sharing <= 1.7.64 - Unauthenticated Path Traversal
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-49112
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Shared Files – Frontend File Upload Form & Secure File Sharing [shared-files]
Researcher
kai63001
More Details >
Simple Shopping Cart <= 5.2.9 - Unauthenticated Insecure Direct Object Reference
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-48868
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
Simple Shopping Cart [wordpress-simple-paypal-shopping-cart]
Researcher
Austin Ginder
More Details >
Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Solution <= 2.1.7 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-27089
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Solution [tour-booking-manager]
Researcher
benzdeus
More Details >
TrueBooker – Appointment Booking and Scheduler System <= 1.1.9 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-48881
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
TrueBooker – Appointment Booking and Scheduler System [truebooker-appointment-booking]
Researcher
Vincent Sevkli
More Details >
Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups. <= 3.1.4 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-49110
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups. [upsell-order-bump-offer-for-woocommerce]
Researcher
Jakub Herman
More Details >
User Registration Stripe <= 1.3.12 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-49081
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
User Registration Stripe [user-registration-stripe]
Researcher
0xd4rk5id3
More Details >
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 4.9.4 - Unauthenticated Information Exposure
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-49056
Patch Status
Patched
Published
Jun 3, 2026
Affected Software
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels [print-invoices-packing-slip-labels-for-woocommerce]
Researcher
Jakub Herman
More Details >
Welcart e-Commerce <= 2.11.28 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-49775
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
Welcart e-Commerce [usc-e-shop]
Researcher
dodoh4t
More Details >
Wp EMember <= v10.2.2 - Unauthenticated Information Exposure
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-49077
Patch Status
Unpatched
Published
Jun 4, 2026
Affected Software
Wp EMember [wp-eMember]
Researcher
Tran Nguyen Bao Khanh
More Details >
WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-8385
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
WP Go Maps – Google Maps, OpenStreetMap, Leaflet Map [wp-google-maps]
Researcher
Sudhanshu Chauhan
More Details >
WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.7.10 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-49078
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
WP Travel Engine – Tour Booking Plugin – Tour Operator Software [wp-travel-engine]
Researcher
dodoh4t
More Details >
WPC Product Bundles for WooCommerce <= 8.5.3 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-48883
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
WPC Product Bundles for WooCommerce [woo-product-bundle]
Researcher
Jakub Herman
More Details >
WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-7792
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite]
Researcher
Valatty
More Details >
wpForo Forum <= 3.1.0 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-49767
Patch Status
Patched
Published
Jun 4, 2026
Affected Software
wpForo Forum [wpforo]
Researcher
Jakub Herman
More Details >
LearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file' Parameter
4.9
CVSS Rating
4.9 (Medium)
CVE-ID
CVE-2026-7565
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
LearnPress – Backup & Migration Tool [learnpress-import-export]
Researcher
Wannes Verwimp
More Details >
OptinCraft <= 1.2.0 - Authenticated (Administrator+) SQL Injection via 'order_by' Parameter
4.9
CVSS Rating
4.9 (Medium)
CVE-ID
CVE-2026-8978
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
OptinCraft – Drag & Drop Optins & Popup Builder for WordPress [optincraft]
Researcher
Yousef Alraddadi
More Details >
Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters
4.9
CVSS Rating
4.9 (Medium)
CVE-ID
CVE-2026-6448
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker [quiz-master-next]
Researcher
Drew Webber (mcdruid)
More Details >
Smart Slider 3 <= 3.5.1.36 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'src'/'srcset' Attribute in HTML Export
4.9
CVSS Rating
4.9 (Medium)
CVE-ID
CVE-2026-9197
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Smart Slider 3 [smart-slider-3]
Researcher
Nguyen Khanh Hao
More Details >
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-8991
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Drag and Drop Multiple File Upload for Contact Form 7 [drag-and-drop-multiple-file-upload-contact-form-7]
Researcher
Bao Luu Gia Nguyen
More Details >
Passeum Ticketing <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'shop_name' Setting
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-7421
Patch Status
Unpatched
Published
Jun 2, 2026
Affected Software
Passeum Ticketing [passeum-ticketing]
Researcher
KEVIN LEE (crattack)
More Details >
Progress Planner <= 1.9.0 - Authenticated (Editor+) Stored Cross-Site Scripting
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-28116
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
Progress Planner [progress-planner]
Researcher
hongdo
More Details >
Quick Playground <= 1.3.4 - Authenticated (Administrator+) Arbitrary File Read via 'filename' Parameter
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-2500
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Quick Playground [quick-playground]
Researcher
Pablo Santiago
More Details >
Simple Custom Login Page <= 1.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-10100
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
Simple Custom Login Page [simple-custom-login-page]
Researcher
Nguyen Duong
More Details >
Word Replacer <= 0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Replacement' Parameter
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-3620
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
Word Replacer [word-replacer]
Researcher
san6051
More Details >
WP Maps <= 4.9.4 - Authenticated (Admin+) Stored Cross-Site Scripting via 'location_messages' Parameter
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-9594
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin]
Researcher
Yousef Alraddadi
More Details >
Alba Board <= 2.1.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'card_id' Parameter
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-7523
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Alba Board [alba-board]
Researcher
Teerachai Somprasong
More Details >
Backup, Restore and Migrate your sites with XCloner <= 4.8.6 - Authenticated (Subscriber+) Information Exposure
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-48965
Patch Status
Patched
Published
Jun 3, 2026
Affected Software
Backup, Restore and Migrate your sites with XCloner [xcloner-backup-and-restore]
Researcher
kai63001
More Details >
BirdSeed <= 2.2.0 - Cross-Site Request Forgery via BirdSeed Token Change
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-4071
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
BirdSeed [birdseed]
Researcher
Nabil Irawan
More Details >
Charitable <= 1.8.11.1 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Attachment Deletion via 'avatar' Parameter
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-10038
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable]
Researcher
Khanh Nguyen
More Details >
Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons <= 1.4.8 - Authenticated (Subscriber+) Information Exposure
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-49082
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons [chatway-live-chat]
Researcher
dodoh4t
More Details >
Elementor Website Builder – more than just a page builder <= 4.1.0 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-49782
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
Elementor Website Builder – more than just a page builder [elementor]
Researcher
Bonds
More Details >
EmergencyWP <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Update
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-9732
Patch Status
Unpatched
Published
Jun 2, 2026
Affected Software
EmergencyWP – Dead Man's switch & legacy deliverance [emergencywp]
Researcher
swat
More Details >
Employee, Leave and Recruitment Management System – Crew HRM <= 1.2.2 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-27351
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
Employee, Leave and Recruitment Management System – Crew HRM [hr-management]
Researcher
benzdeus
More Details >
Frontend User Notes <= 2.1.1 - Cross-Site Request Forgery to Note Content Modification via 'confirmEdit' Action
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-7047
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Frontend User Notes [frontend-user-notes]
Researcher
Mohamed Wajih Hichri (Assaults)
More Details >
Google Plus One Bottom <= 0.0.2 - Cross-Site Request Forgery to Plugin Settings Update via Settings Page
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-9723
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
Google Plus One Bottom [google-plus-one-bottom]
Researcher
swat
More Details >
JTL-Connector for WooCommerce <= 2.4.1 - Missing Authorization to Authenticated (Subscriber+) Settings Modification via Multiple Functions
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-9234
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
JTL-Connector for WooCommerce [woo-jtl-connector]
Researcher
Muhan Luo
More Details >
Klamra Paycal for Aspaclaria <= 1.1.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'invoice_id' Parameter
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-8611
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Klamra Paycal for Aspaclaria [klamra-paycal-for-aspaclaria]
Researcher
KEVIN LEE (crattack)
More Details >
Laiser Tag <= 1.2.5 - Cross-Site Request Forgery to Plugin Settings Update via Settings Form
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-9722
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
Laiser Tag [laiser-tag]
Researcher
swat
More Details >
LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-9719
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
LatePoint – Calendar Booking Plugin for Appointments and Events [latepoint]
Researcher
Kirasec
More Details >
Page-list <= 6.2 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure via Shortcode Attributes
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-9008
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
Page-list [page-list]
Researcher
darkmode
More Details >
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.271 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-34892
Patch Status
Patched
Published
Jun 3, 2026
Affected Software
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math]
Researcher
Jakub Herman
More Details >
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) <= 9.5.9 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-48969
Patch Status
Patched
Published
Jun 3, 2026
Affected Software
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl]
Researcher
Evan NR
More Details >
Remove meta boxes per user role <= 1.01 - Cross-Site Request Forgery to Settings Update
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-8422
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
Remove meta boxes per user role [remove-meta-boxes-per-user-role]
Researcher
Muhammad Nur Ibnu Hubab
More Details >
Remove NoFollow Commenter URL <= 1.0 - Cross-Site Request Forgery to Settings Update
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-9730
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
Remove NoFollow Commenter URL [remove-nofollow-commenter-link]
Researcher
swat
More Details >
RSS Aggregator by Feedzy <= 5.1.7 - Missing Authorization to Authenticated (Contributor+) Import Job Creation, Execution, Purge, Log Clearing, and Information Disclosure via Multiple AJAX Sub-Actions
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-8976
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds]
Researcher
Jack Pas (Dark.)
More Details >
SEO Plugin by Squirrly SEO <= 12.4.16 - Missing Authorization to Authenticated (Contributor+) Privileged Cloud API Operations
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-7624
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
SEO Plugin by Squirrly SEO [squirrly-seo]
Researcher
Abi Wiranata
More Details >
Slider Revolution 6.0.0-6.7.55 and 7.0.0-7.0.14 - Missing Authorization to Authenticated (Contributor+) Arbitrary Plugin Deactivation
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-9050
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
Slider Revolution [revslider]
Researcher
Nguyen Ngoc Duc (duc193)
More Details >
Slider Revolution 7.0.0 - 7.0.14 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-9048
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
Slider Revolution [revslider]
Researcher
Prickly Cactus
More Details >
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions <= 8.4.1 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-42378
Patch Status
Patched
Published
Jun 1, 2026
Affected Software
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions [wp-full-stripe-free]
Researcher
hhhai
More Details >
Tectite Forms <= 1.3 - Cross-Site Request Forgery to Settings Update
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-9599
Patch Status
Unpatched
Published
Jun 1, 2026
Affected Software
Tectite Forms [tectite-forms]
Researcher
afnaan
More Details >
Visual Link Preview <= 2.4.1 - Authenticated (Subscriber+) Information Exposure
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-48878
Patch Status
Patched
Published
Jun 2, 2026
Affected Software
Visual Link Preview [visual-link-preview]
Researcher
Aliefis
More Details >
Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.128 - Authenticated (Admin+) Arbitrary Directory Deletion
3.8
CVSS Rating
3.8 (Low)
CVE-ID
CVE-2025-12656
Patch Status
Patched
Published
Jun 5, 2026
Affected Software
WPvivid — Backup, Migration & Staging [wpvivid-backuprestore]
Researcher
blue0x1
More Details >
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (June 1, 2026 to June 7, 2026) appeared first on Wordfence.
Quelle: www.wordfence.com