Wordfence Intelligence Weekly WordPress Vulnerability Report (June 29, 2026 to July 5, 2026)

⚠️ CVE-Referenzen: CVE-2026-12923 CVE-2026-57355 CVE-2026-12135 CVE-2026-57802 CVE-2026-9145 CVE-2026-57778 CVE-2026-57736 CVE-2026-12920 CVE-2026-12731 CVE-2026-57338 CVE-2026-57334 CVE-2026-8351 CVE-2026-57685 CVE-2026-57773 CVE-2026-57763 CVE-2026-57783 CVE-2026-27419 CVE-2026-27414 CVE-2026-57751 CVE-2026-12133 CVE-2026-12560 CVE-2026-12734 CVE-2026-5821 CVE-2026-57793 CVE-2026-13468 CVE-2026-57341 CVE-2026-12113 CVE-2026-57623 CVE-2026-57342 CVE-2026-57353 CVE-2026-27436 CVE-2026-10089 CVE-2026-5348 CVE-2026-57678 CVE-2026-11380 CVE-2026-57352 CVE-2026-57339 CVE-2026-57753 CVE-2026-9756 CVE-2025-69156 CVE-2026-9834 CVE-2026-57737 CVE-2026-12224 CVE-2026-11397 CVE-2026-57330 CVE-2026-57731 CVE-2026-57759 CVE-2026-57801 CVE-2026-57677 CVE-2026-57346 CVE-2026-57358 CVE-2026-27409 CVE-2026-12073 CVE-2026-57791 CVE-2026-57790 CVE-2026-57683 CVE-2026-13040 CVE-2026-12408 CVE-2026-11398 CVE-2026-27060 CVE-2026-57800 CVE-2026-57351 CVE-2026-57343 CVE-2026-9188 CVE-2026-27435 CVE-2026-57672 CVE-2026-57776 CVE-2026-57796 CVE-2026-57676 CVE-2026-7517 CVE-2026-57789 CVE-2026-13357 CVE-2026-57805 CVE-2026-6070 CVE-2026-11896 CVE-2026-12435 CVE-2025-69155 CVE-2026-57758 CVE-2026-57803 CVE-2026-57356 CVE-2026-11981 CVE-2026-57723 CVE-2026-57794 CVE-2026-57752 CVE-2026-59511 CVE-2026-57760 CVE-2026-57335 CVE-2026-12754 CVE-2026-8489 CVE-2026-57340 CVE-2026-57792 CVE-2025-69153 CVE-2025-58902 CVE-2026-57679 CVE-2026-12557 CVE-2026-57687 CVE-2026-13459 CVE-2026-13251 CVE-2026-57625 CVE-2026-57689 CVE-2026-57682 CVE-2026-57328 CVE-2026-57345 CVE-2026-13252 CVE-2025-69133 CVE-2026-57670 CVE-2026-9180 CVE-2026-57327 CVE-2026-1239 CVE-2026-57781 CVE-2026-57720 CVE-2026-4804 CVE-2026-27408 CVE-2026-57674 CVE-2026-57675 CVE-2026-57426 CVE-2026-57362 CVE-2026-57754 CVE-2026-57765 CVE-2025-69152 CVE-2026-57747 CVE-2026-5137 CVE-2026-57779 CVE-2026-57344 CVE-2026-57692 CVE-2026-57669 CVE-2026-13369 CVE-2026-57673 CVE-2026-57764 CVE-2026-12729 CVE-2026-13443 CVE-2026-12657 CVE-2026-57804 CVE-2026-9107 CVE-2026-57333 CVE-2026-57748 CVE-2026-57684 CVE-2026-9230 CVE-2026-12110 CVE-2025-69132 CVE-2026-57337 CVE-2026-57681 CVE-2026-57348 CVE-2026-57347 CVE-2026-8141 CVE-2026-9148 CVE-2026-49779 CVE-2026-57721 CVE-2026-57757 CVE-2026-12472 CVE-2026-13704 CVE-2026-57686 CVE-2026-57326 CVE-2026-11367 CVE-2026-57772 CVE-2026-57671 CVE-2026-57755 CVE-2026-13015 CVE-2026-13454 CVE-2026-57798 CVE-2026-27404 CVE-2026-57730 CVE-2026-12158 CVE-2026-27426 CVE-2026-57690 CVE-2026-9711 CVE-2026-57361 CVE-2026-12154 CVE-2026-12732 CVE-2026-12902 CVE-2026-11600 CVE-2026-12127 CVE-2026-59520 CVE-2026-57799 CVE-2026-57762 CVE-2026-57366 CVE-2026-15158 CVE-2026-14352 CVE-2026-57788 CVE-2026-11387 CVE-2026-13733 CVE-2026-8944 CVE-2026-39448 CVE-2026-8892 CVE-2026-57766 CVE-2026-57331 CVE-2025-69134 CVE-2026-27412 CVE-2026-12090 CVE-2026-42382 CVE-2026-14029 CVE-2026-57749 CVE-2026-10104 CVE-2026-57782 CVE-2026-57359 CVE-2026-2387 CVE-2026-11592 CVE-2026-27425 CVE-2026-12134 CVE-2026-12142 CVE-2026-59519 CVE-2026-57787 CVE-2026-12349 CVE-2026-10096 CVE-2026-8441 CVE-2026-57795 CVE-2026-12114 CVE-2026-57797 CVE-2026-57722 CVE-2026-13228 CVE-2026-13731 CVE-2026-5524 CVE-2026-57624 CVE-2026-9626 CVE-2026-11823 CVE-2026-11988 CVE-2026-10095 CVE-2026-11778 CVE-2026-57688 CVE-2026-9725 CVE-2026-57780 CVE-2026-27402 CVE-2026-13246 CVE-2025-69094 CVE-2026-11900 CVE-2026-27433 CVE-2026-12240 CVE-2026-57332 CVE-2026-57350 CVE-2026-57320 CVE-2026-7311 CVE-2025-69154 CVE-2026-12904 CVE-2026-57774 CVE-2026-57357 CVE-2026-57771 CVE-2025-66076 CVE-2026-57746 CVE-2026-57360 CVE-2026-12122 CVE-2026-14249 CVE-2026-57349 CVE-2026-14327 CVE-2026-57750 CVE-2026-57329 CVE-2026-10513
Last week, there were 246 vulnerabilities disclosed in 179 WordPress Plugins and 40 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 100 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back. Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 35,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free. Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. New Firewall Rules Deployed Last Week The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection. The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week: Ninja Forms – File Uploads <= 3.3.29 – Unauthenticated Arbitrary File Read via File Upload Field ‘files[].data.file_path’ Parameter WAF-RULE-923 – Data redacted while we work with the vendor on a patch. WAF-RULE-924 – Data redacted while we work with the vendor on a patch. Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay. Total Unpatched & Patched Vulnerabilities Last Week Patch Status Number of Vulnerabilities Patched 158 Unpatched 88 Total Vulnerabilities by CVSS Severity Last Week Severity Rating Number of Vulnerabilities Medium Severity 150 High Severity 87 Critical Severity 9 Total Vulnerabilities by CWE Type Last Week Vulnerability Type by CWE Number of Vulnerabilities Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 87 Missing Authorization 50 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 25 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 19 Authorization Bypass Through User-Controlled Key 12 Cross-Site Request Forgery (CSRF) 12 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 11 Exposure of Sensitive Information to an Unauthorized Actor 7 Deserialization of Untrusted Data 4 Improper Control of Generation of Code ('Code Injection') 4 Improper Privilege Management 3 Server-Side Request Forgery (SSRF) 3 Unrestricted Upload of File with Dangerous Type 3 External Control of File Name or Path 2 Improper Authentication 1 Improper Neutralization of CRLF Sequences ('CRLF Injection') 1 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1 Improper Neutralization of Special Elements used in a Command ('Command Injection') 1 Researchers That Contributed to WordPress Security Last Week Researcher Name Number of Vulnerabilities João Pedro S Alcântara (Kinorth) 34 PRISM 18 Ananda Dhakal 14 Nguyen Ba Khanh 13 daroo 12 dodoh4t 7 Nabil Irawan 5 Bonds 5 Nguyen Dinh Hai (HaiND) 5 Phat RiO 5 Athiwat Tiprasaharn (Jitlada) 5 Chloe Chamberland 4 zaim 4 Muhammad Yudha - DJ 4 dutafi 4 Legion Hunter 4 Evan NR 4 Tran Nguyen Bao Khanh 3 Niv Kochan 3 Jakub Herman 3 0xd4rk5id3 3 Dmitrii Ignatyev 3 timomangcut 3 w41bu1 2 h0xilo 2 CHOIGYEONGMIN 2 se1en 2 Osvaldo Noe Gonzalez Del Rio (Os) 2 endy 2 javitoia 2 Kirasec 2 Rafie Muhammad 2 d.v4n_s3c 2 Denver Jackson 2 b4shu206 1 davidfdzmorilla 1 AmonRa 1 gidget smith 1 Irwan Kusuma 1 afnaan 1 Ad4m5 1 Nguyen Ngoc Duc (duc193) 1 Azril Fathoni (kiseki) 1 nightward 1 wesley (wcraft) 1 Alessandro Greco (Aleff) 1 Giovanbattista Ianni 1 Supoj Polsawas (sp0x5ec) 1 Austin Ginder 1 Jonah Burgess (CryptoCat) 1 ParkHyunWoo 1 Ivan Kuzymchak 1 VDsec 1 Webbernaut 1 theviper17y 1 Taichi Kashimura 1 she11f 1 Eason 1 Michael Perla (vizen5) 1 sterva 1 Mitchell 1 Volodymyr Kolesnykov 1 hivesec 1 tjoffe 1 MatilJ 1 Abu Hurayra (HurayraIIT) 1 jonathan dunn 1 John Umoru 1 skyv3il 1 Saad Malik 1 Ilkeggs 1 HieuPenguinnn 1 Jagadesh Achanta 1 밥김국 1 suyoung kim(AhnLab) 1 yangsori 1 sleeper 1 Sakimi 1 Tharadol Suksamran (d3kc4rt_1) 1 Matan Bahar 1 Md. Moniruzzaman Prodhan (NomanProdhan) 1 R2D2 1 Yat 1 qdtad 1 devploit 1 Averon Averenkov (Averon Averenkov) 1 VanTastic 1 Catalin Oancea (0x4D5A) 1 Saleh Elsayed (0xManticore) 1 Manopakorn Kooharueangrong (manop55555) 1 Jack Pas (Dark.) 1 Anthony Cihan (Hann1bl3L3ct3r) 1 hhhai 1 Psalms Christopher Matovu (ByteOverride) 1 g0wthr 1 lhking 1 Chirita Catalin-Andrei (CC99IE) 1 Septio Noerdiansyah 1 mickeyjoe 1 Ravindu Lakmina Munaweera 1 Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report. WordPress Plugins with Reported Vulnerabilities Last Week Software Name Software Slug Academy LMS academy Ad Inserter – Ad Manager & AdSense Ads ad-inserter Admin and Site Enhancements (ASE) Pro admin-site-enhancements-pro Advanced Booking & Appointment System – Webba Booking Calendar webba-booking-lite Advanced Contact form 7 DB advanced-cf7-db Advanced Shipment Tracking for WooCommerce woo-advanced-shipment-tracking Ajax Load More - Filters ajax-load-more-filters ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce woo-alidropship ApplyOnline – Application Form Builder and Manager apply-online Appointment Booking Calendar appointment-booking-calendar Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress latepoint Appointment Bookings for Zoom GoogleMeet and more – Wappointment wappointment AR for WooCommerce ar-for-woocommerce AR for WordPress ar-for-wordpress ARforms arforms ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup armember Automotive Listings automotive BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net woo-bulk-editor Blocksy Companion blocksy-companion Blocksy Companion Pro blocksy-companion-pro Booked - Appointment Booking for WordPress booked Booking calendar, Appointment Booking System booking-calendar BookingPress Appointment Booking Pro bookingpress-appointment-booking-pro Business Directory Plugin – Easy Listing Directories for WordPress business-directory-plugin Classified Listing – AI-Powered Classified ads & Business Directory classified-listing CM Business Directory – Optimise and showcase local business cm-business-directory CodePeople Post Map for Google Maps codepeople-post-map Colissimo shipping methods for WooCommerce colissimo-shipping-methods-for-woocommerce Comments – wpDiscuz wpdiscuz Cookie Banner for GDPR / CCPA – WPLP Cookie Consent gdpr-cookie-consent CrawlWP SEO – Instant Search Engine Indexing & SEO Performance Monitor mihdan-index-now CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x woo-multi-currency Custom Field Template custom-field-template Custom Payment Gateways for WooCommerce custom-payment-gateways-woocommerce cws-svgicons cws-svgicons Database for Contact Form 7, WPforms, Elementor forms contact-form-entries Divi Form Builder divi-form-builder Dokan Pro dokan-pro Download Manager download-manager eCommerce Product Catalog Plugin for WordPress ecommerce-product-catalog Editorial Rating – Product Review & Rating System editorial-rating Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress email-subscribers Embed Privacy embed-privacy Enable Media Replace enable-media-replace Envision Page Builder – A collection of WordPress Gutenberg blocks & templates envision-page-builder Envo's Templates & Widgets for Elementor and WooCommerce envo-elementor-for-woocommerce Event Organiser event-organiser EventON (Pro) - WordPress Virtual Event Calendar Plugin eventON Exclusive Addons for Elementor exclusive-addons-for-elementor Export User Data export-user-data ez Form Calculator Premium ez-form-calculator-premium Five Star Business Profile and Schema business-profile FormLayer formlayer FV Flowplayer Video Player fv-wordpress-flowplayer GD Rating System gd-rating-system GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content geeky-bot GenerateBlocks generateblocks GeoDirectory – WP Business Directory Plugin and Classified Listings Directory geodirectory GiveWP – Donation Plugin and Fundraising Platform give Golo Framework golo-framework Groundhogg — CRM, Newsletters, and Marketing Automation groundhogg HandL UTM Grabber / Tracker handl-utm-grabber Heateor Social Login WordPress heateor-social-login Houzez Property Feed houzez-property-feed HubSpot All-In-One Marketing – Forms, Popups, Live Chat leadin Image Optimization – Compress Images and Convert to WebP or AVIF image-optimization iNET Webkit inet-webkit Insert Pages insert-pages Internal Links Manager seo-automated-link-building Japanized for WooCommerce woocommerce-for-japan JetFormBuilder — Dynamic Blocks Form Builder jetformbuilder JetWidgets For Elementor jetwidgets-for-elementor JoomSport – for Sports: Team & League, Football, Hockey & more joomsport-sports-league-results-management JSON API User json-api-user Kadence Blocks — Page Builder Toolkit for Gutenberg Editor kadence-blocks Kali Forms — Contact Form & Drag-and-Drop Builder kali-forms Kirki – Freeform Page Builder, Website Builder & Customizer kirki Kit (formerly ConvertKit) for WooCommerce convertkit-for-woocommerce Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages page-builder-add LearnPress – WordPress LMS Plugin for Create and Sell Online Courses learnpress Link Whisper Free link-whisper Link Whisper Premium link-whisper-premium MainWP Dashboard: Self-hosted WordPress Management for Agencies mainwp MasterStudy LMS WordPress Plugin – for Online Courses and Education masterstudy-lms-learning-management-system MeetingHub – Webinar & Meeting Plugin for Zoom, Google Meet, Webex, Microsoft Teams, & Jitsi Meet meetinghub Module PRO modula MoreConvert Wishlist for WooCommerce smart-wishlist-for-more-convert Mosaic Gallery – Advanced Gallery mosaic-gallery-advanced-gallery MotoPress Appointment Booking motopress-appointment-lite MotoPress Hotel Booking motopress-hotel-booking-lite Motors – Car Dealership & Classified Listings Plugin motors-car-dealership-classified-listings My Calendar – Accessible Event Manager my-calendar NewsPlus Shortcodes newsplus-shortcodes NEX-Forms – Ultimate Forms Plugin for WordPress nex-forms-express-wp-form-builder Ninja Forms - File Uploads ninja-forms-uploads Ninja Forms – The Contact Form Builder That Grows With You ninja-forms Novalnet Payment Gateway for WooCommerce woocommerce-novalnet-gateway NOWPayments for WooCommerce – Crypto Payment Gateway nowpayments-for-woocommerce OpenAI Chatbot for WordPress – Helper helper Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization optimole-wp Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction paid-member-subscriptions Paid Videochat Turnkey Site – HTML5 PPV Live Webcams ppv-live-webcams pCloud WP Backup pcloud-wp-backup Perfmatters perfmatters Permalink Manager for WooCommerce permalink-manager-for-woocommerce PixMagix – WordPress Image Editor pixmagix Plugin for Google Analytics by IO technologies io-engagement-analytics POS Entegratör – Gurmehub Ödeme Eklentisi pos-entegrator Premium Addons for KingComposer premium-addons-for-kingcomposer Printcart Web to Print Product Designer for WooCommerce printcart-integration Private Content private-content Product Addons and Product Options With Custom Fields – WowAddons product-addons Product Video Gallery for Woocommerce product-video-gallery-slider-for-woocommerce ProfileGrid – User Profiles, Groups and Communities profilegrid-user-profiles-groups-and-communities Qi Blocks qi-blocks Quads Ads Manager for Google AdSense quick-adsense-reloaded Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker quiz-master-next RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login custom-registration-form-builder-with-submission-manager Request a Quote – Quote Forms for Any WordPress Site request-a-quote Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations fb-reviews-widget ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema reviewx RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator feedzy-rss-feeds RTMKit rometheme-for-elementor Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization metasync Sendcloud Shipping sendcloud-connected-shipping Shopify shopify-plugin Shopping Cart & eCommerce Store wp-easycart Shortcodes and extra features for Phlox theme auxin-elements ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization shortpixel-adaptive-images Simple Link Directory Pro qc-simple-link-directory Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management simple-urls Simple User Avatar simple-user-avatar Slider Revolution revslider Slim SEO – A Fast & Automated SEO Plugin For WordPress slim-seo SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery sms-alert Speaker speaker SportsPress Pro sportspress-pro Structured Content (JSON-LD) #wpsc structured-content Struktur Core struktur-core Surbma | Yoast SEO Breadcrumb Shortcode surbma-yoast-breadcrumb-shortcode Survey Maker by AYS survey-maker SysBasics Customize My Account for WooCommerce – Live My Account Customizer customize-my-account-for-woocommerce Taskbuilder – Project Management & Task Management Tool With Kanban Board taskbuilder Tax Exempt for WooCommerce woocommerce-tax-exempt-plugin Team Members – Multi Language Supported Team Plugin team-showcase-supreme TheGem Theme Elements thegem-elements-elementor ThumbPress – Compress Images, Manage Thumbnails, Detect Image Issues, WebP/AVIF, Lazy Loading, Hotlinking & More image-sizes Timetics – Appointment Booking Calendar & Scheduling System timetics TinyPNG – JPEG, PNG & WebP image compression tiny-compress-images Tour Master - Tour Booking, Travel, Hotel tourmaster Tutor LMS – eLearning and online course solution tutor Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin ultimate-member Universal Clocks universal-clocks User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration wp-user-frontend Video Gallery – YouTube Gallery, Playlist & Video Grid youtube-showcase VikBooking Hotel Booking Engine & PMS vikbooking Visualizer – Tables & Charts Manager with Built-in AI Generator visualizer W3 Total Cache w3-total-cache Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments wallet-system-for-woocommerce Webmention webmention weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot wedocs WooCommerce Designer Pro wc-designer-pro Woostify Sites Library woostify-sites-library WP Database Backup – Unlimited Database & Files Backup by Backup for WP wp-database-backup WP Debugging wp-debugging WP Fast Total Search – The Power of Indexed Search fulltext-search WP Google Review Slider wp-google-places-review-slider WP Import Export Lite wp-import-export-lite WP Inventory Manager wp-inventory-manager WP Photo Album Plus wp-photo-album-plus WP Review Slider Pro wp-review-slider-pro WP-BusinessDirectory – Business directory plugin for WordPress wp-businessdirectory WPAdverts – Classifieds Plugin wpadverts WPBakery Page Builder Addons by Livemesh addons-for-visual-composer WPBot – AI ChatBot for Live Support, Lead Generation, AI Services chatbot wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin wpdatatables WPeMatico RSS Feed Fetcher wpematico WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More wpforms-lite WPIDE – File Manager & Code Editor wpide WordPress Themes with Reported Vulnerabilities Last Week Software Name Software Slug Aalto - Architecture and Interior Design WordPress Theme aalto aqua aqua Artale | Wedding Photography WordPress artale Audrey - Fashion WordPress Theme audrey Automotive Car Dealership Business WordPress Theme automotive Billey - Creative Portfolio & Agency Elementor WordPress Theme billey Brook - Agency Business Creative WordPress Theme brook Corpkit - Business Consulting WordPress Theme corpkit Dør - Modern Architecture and Interior Design Theme dor EduMall - Professional LMS Education Center WordPress Theme edumall Fascinate fascinate Fitness Zone WordPress Theme fitnesszone Flatsome flatsome Flow flow Kids Life | Children School WordPress kidslife Kids Zone - Children WordPress Theme kidszone Kitchor - Interior Design WordPress Theme kitchor Leedo – Modern, Colorful & Creative Portfolio WordPress Theme leedo Lighthouse | School for Kids with Disabilities & Special Needs WordPress Theme lighthouseschool LMS - Education WordPress Theme lms Martfury - Marketplace Mobile App Figma Template martfury Motors - Car Dealer, Rental & Listing WordPress theme motors NativeChurch NativeChurch Nuss - Hotel Booking WordPress nuss Overworld - eSports and Gaming WordPress Theme overworld pearl pearl Real Estate 7 WordPress realestate-7 SetSail - Travel Agency WordPress Theme setsail SpaLab | Beauty Salon WordPress Theme spalab Struktur - Creative Agency WordPress Theme struktur TheFox | Responsive Multi-Purpose WordPress Theme thefox Tonda - Elegant Shop WordPress Theme tonda Trendy Travel WordPress trendytravel unicamp unicamp VW Food Corner vw-food-corner VW Wedding vw-wedding Werkstatt - Creative Portfolio WordPress Theme werkstatt Woffice CRM woffice Zakra zakra Zegen - Church WordPress Theme zegen Vulnerability Details Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize. Blocksy Companion <= 2.1.46 - Unauthenticated Arbitrary File Upload via 'blc-review-images[]' Parameter 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-15158 Patch Status Patched Published Jul 1, 2026 Affected Software Blocksy Companion [blocksy-companion] Researcher Nguyen Ba Khanh More Details > Blocksy Companion Pro <= 2.1.46 - Unauthenticated Remote Code Execution 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-57624 Patch Status Patched Published Jun 29, 2026 Affected Software Blocksy Companion Pro [blocksy-companion-pro] Researcher Nguyen Ba Khanh More Details > Divi Form Builder <= 5.1.8 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-5524 Patch Status Patched Published Jul 1, 2026 Affected Software Divi Form Builder [divi-form-builder] Researcher 0xd4rk5id3 More Details > EventON - WordPress Virtual Event Calendar Plugin <= 5.0.11 - Unauthenticated Blind SQL Injection via Search Parameter 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-9711 Patch Status Unpatched Published Jun 29, 2026 Affected Software EventON (Pro) - WordPress Virtual Event Calendar Plugin [eventON] Researcher Nguyen Ngoc Duc (duc193) More Details > Private Content <= 9.9.2 - Unauthenticated Privilege Escalation 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-57692 Patch Status Unpatched Published Jul 1, 2026 Affected Software Private Content [private-content] Researcher 0xd4rk5id3 More Details > ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthenticated Privilege Escalation via Email Overwrite 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-12073 Patch Status Patched Published Jun 29, 2026 Affected Software ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] Researcher Ivan Kuzymchak More Details > SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-11387 Patch Status Patched Published Jun 30, 2026 Affected Software SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery [sms-alert] Researchers Chloe ChamberlandPRISM More Details > Printcart Web to Print Product Designer for WooCommerce <= 2.5.2 - Unauthenticated Arbitrary File Deletion 9.1 CVSS Rating 9.1 (Critical) CVE-ID CVE-2026-9725 Patch Status Patched Published Jul 2, 2026 Affected Software Printcart Web to Print Product Designer for WooCommerce [printcart-integration] Researcher tjoffe More Details > WP-BusinessDirectory <= 4.0.1 - Unauthenticated Arbitrary File Deletion via Path Traversal via '_filename' Parameter 9.1 CVSS Rating 9.1 (Critical) CVE-ID CVE-2026-6070 Patch Status Patched Published Jun 30, 2026 Affected Software WP-BusinessDirectory – Business directory plugin for WordPress [wp-businessdirectory] Researcher Nabil Irawan More Details > Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-12224 Patch Status Patched Published Jun 30, 2026 Affected Software Dokan Pro [dokan-pro] Researcher 0xd4rk5id3 More Details > LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-13228 Patch Status Patched Published Jun 30, 2026 Affected Software Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] Researcher d.v4n_s3c More Details > RegistrationMagic <= 6.0.9.1 - Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-12158 Patch Status Patched Published Jun 30, 2026 Affected Software RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login [custom-registration-form-builder-with-submission-manager] Researchers Chloe ChamberlandPRISM More Details > Zegen - Church WordPress Theme <= 1.1.9 - Authenticated (Subscriber+) Arbitrary File Upload 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-27419 Patch Status Unpatched Published Jun 29, 2026 Affected Software Zegen - Church WordPress Theme [zegen] Researcher Tran Nguyen Bao Khanh More Details > Audrey <= 1.5 - Unauthenticated Local File Inclusion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-42382 Patch Status Unpatched Published Jun 29, 2026 Affected Software Audrey - Fashion WordPress Theme [audrey] Researcher Tran Nguyen Bao Khanh More Details > Embed Privacy <= 1.12.3 - Authenticated (Contributor+) Arbitrary File Deletion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-57346 Patch Status Patched Published Jun 29, 2026 Affected Software Embed Privacy [embed-privacy] Researcher daroo More Details > Image Optimizer <= 1.7.4 - Authenticated (Author+) Arbitrary File Deletion via Post Meta Field Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-5821 Patch Status Patched Published Jul 1, 2026 Affected Software Image Optimization – Compress Images and Convert to WebP or AVIF [image-optimization] Researcher Dmitrii Ignatyev More Details > Lighthouse <= 1.2.12 - Unauthenticated Local File Inclusion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2025-58902 Patch Status Unpatched Published Jun 29, 2026 Affected Software Lighthouse | School for Kids with Disabilities & Special Needs WordPress Theme [lighthouseschool] Researcher Tran Nguyen Bao Khanh More Details > Novalnet Payment Gateway for WooCommerce <= 12.10.3 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-57677 Patch Status Patched Published Jun 29, 2026 Affected Software Novalnet Payment Gateway for WooCommerce [woocommerce-novalnet-gateway] Researcher qdtad More Details > Paid Videochat Turnkey Site – HTML5 PPV Live Webcams <= 7.4.8 - Authenticated (Performer+) Arbitrary File Deletion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-57331 Patch Status Patched Published Jun 29, 2026 Affected Software Paid Videochat Turnkey Site – HTML5 PPV Live Webcams [ppv-live-webcams] Researcher endy More Details > Pearl - Corporate Business <= 3.4.10 - Unauthenticated Local File Inclusion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-27412 Patch Status Unpatched Published Jun 29, 2026 Affected Software pearl [pearl] Researcher João Pedro S Alcântara (Kinorth) More Details > TinyPNG <= 3.6.13 - Authenticated (Author+) Arbitrary File Deletion via 'convert.path' in 'tiny_compress_images' Post Meta 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-7311 Patch Status Patched Published Jul 2, 2026 Affected Software TinyPNG – JPEG, PNG & WebP image compression [tiny-compress-images] Researcher lhking More Details > W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary Code Execution 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-57623 Patch Status Patched Published Jun 29, 2026 Affected Software W3 Total Cache [w3-total-cache] Researcher Ananda Dhakal More Details > Export User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion via display_name Field 8.0 CVSS Rating 8.0 (High) CVE-ID CVE-2026-12240 Patch Status Unpatched Published Jun 29, 2026 Affected Software Export User Data [export-user-data] Researcher Webbernaut More Details > Aalto <= 1.8 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57788 Patch Status Unpatched Published Jul 2, 2026 Affected Software Aalto - Architecture and Interior Design WordPress Theme [aalto] Researcher João Pedro S Alcântara (Kinorth) More Details > Aqua <= 5.1.2 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57789 Patch Status Unpatched Published Jul 2, 2026 Affected Software aqua [aqua] Researcher João Pedro S Alcântara (Kinorth) More Details > AR for WooCommerce <= 8.40 - Unauthenticated Path Traversal to Arbitrary File Read via 'file' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-14352 Patch Status Patched Published Jul 2, 2026 Affected Software AR for WooCommerce [ar-for-woocommerce] Researcher CHOIGYEONGMIN More Details > AR for WordPress <= 8.40 - Unauthenticated Arbitrary File Read via 'file' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-14327 Patch Status Patched Published Jul 2, 2026 Affected Software AR for WordPress [ar-for-wordpress] Researcher CHOIGYEONGMIN More Details > ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup <= 7.0 - Authenticated (Contributor+) PHP Object Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-27060 Patch Status Unpatched Published Jun 30, 2026 Affected Software ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup [armember] Researcher Phat RiO More Details > Billey <= 2.1.8 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57790 Patch Status Unpatched Published Jul 2, 2026 Affected Software Billey - Creative Portfolio & Agency Elementor WordPress Theme [billey] Researcher João Pedro S Alcântara (Kinorth) More Details > BookingPress Appointment Booking Pro <= 5.7.1 - Unauthenticated SQL Injection via 'store_service_date' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-11823 Patch Status Patched Published Jun 30, 2026 Affected Software BookingPress Appointment Booking Pro [bookingpress-appointment-booking-pro] Researcher h0xilo More Details > Brook - Agency Business Creative WordPress Theme <= 2.9.0 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57791 Patch Status Unpatched Published Jul 2, 2026 Affected Software Brook - Agency Business Creative WordPress Theme [brook] Researcher João Pedro S Alcântara (Kinorth) More Details > Dør - Modern Architecture and Interior Design Theme <= 2.4.1 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57792 Patch Status Unpatched Published Jul 2, 2026 Affected Software Dør - Modern Architecture and Interior Design Theme [dor] Researcher João Pedro S Alcântara (Kinorth) More Details > Flow <= 1.8 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57793 Patch Status Unpatched Published Jul 2, 2026 Affected Software Flow [flow] Researcher João Pedro S Alcântara (Kinorth) More Details > GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content <= 1.2.5 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57679 Patch Status Patched Published Jun 29, 2026 Affected Software GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content [geeky-bot] Researcher daroo More Details > Golo Framework <= 1.7.3 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57794 Patch Status Unpatched Published Jul 2, 2026 Affected Software Golo Framework [golo-framework] Researcher João Pedro S Alcântara (Kinorth) More Details > Kitchor <= 1.4.3 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57795 Patch Status Unpatched Published Jul 2, 2026 Affected Software Kitchor - Interior Design WordPress Theme [kitchor] Researcher João Pedro S Alcântara (Kinorth) More Details > Leedo <= 3.0.0 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57796 Patch Status Unpatched Published Jul 2, 2026 Affected Software Leedo – Modern, Colorful & Creative Portfolio WordPress Theme [leedo] Researcher João Pedro S Alcântara (Kinorth) More Details > NewsPlus Shortcodes <= 4.2.0 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57798 Patch Status Unpatched Published Jul 2, 2026 Affected Software NewsPlus Shortcodes [newsplus-shortcodes] Researcher João Pedro S Alcântara (Kinorth) More Details > Ninja Forms - File Uploads <= 3.3.29 - Unauthenticated Arbitrary File Read via File Upload Field 'files[].data.file_path' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-13369 Patch Status Patched Published Jul 1, 2026 Affected Software Ninja Forms - File Uploads [ninja-forms-uploads] Researcher daroo More Details > Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-1239 Patch Status Patched Published Jun 30, 2026 Affected Software Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] Researcher suyoung kim(AhnLab) More Details > Nuss - Hotel Booking WordPress <= 1.3.6 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57799 Patch Status Unpatched Published Jul 2, 2026 Affected Software Nuss - Hotel Booking WordPress [nuss] Researcher João Pedro S Alcântara (Kinorth) More Details > Overworld - eSports and Gaming WordPress Theme <= 1.5 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57800 Patch Status Unpatched Published Jul 2, 2026 Affected Software Overworld - eSports and Gaming WordPress Theme [overworld] Researcher João Pedro S Alcântara (Kinorth) More Details > Perfmatters <= 2.6.4 - Unauthenticated Arbitrary File Read via 's' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-13251 Patch Status Patched Published Jul 1, 2026 Affected Software Perfmatters [perfmatters] Researcher daroo More Details > Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'path' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-14249 Patch Status Patched Published Jul 1, 2026 Affected Software Request a Quote – Quote Forms for Any WordPress Site [request-a-quote] Researcher Mitchell More Details > SetSail - Travel Agency WordPress Theme <= 2.1 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57801 Patch Status Unpatched Published Jul 2, 2026 Affected Software SetSail - Travel Agency WordPress Theme [setsail] Researcher João Pedro S Alcântara (Kinorth) More Details > Shopify <= 1.0.0 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57748 Patch Status Unpatched Published Jul 2, 2026 Affected Software Shopify [shopify-plugin] Researcher Rafie Muhammad More Details > SportsPress Pro <= 2.7.29 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57749 Patch Status Unpatched Published Jul 2, 2026 Affected Software SportsPress Pro [sportspress-pro] Researcher w41bu1 More Details > Struktur - Creative Agency WordPress Theme <= 2.5.1 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57802 Patch Status Unpatched Published Jul 2, 2026 Affected Software Struktur - Creative Agency WordPress Theme [struktur] Researcher João Pedro S Alcântara (Kinorth) More Details > Struktur Core <= 2.5.1 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57803 Patch Status Unpatched Published Jul 2, 2026 Affected Software Struktur Core [struktur-core] Researcher João Pedro S Alcântara (Kinorth) More Details > TheGem Theme Elements <= 5.11.1 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57804 Patch Status Unpatched Published Jul 2, 2026 Affected Software TheGem Theme Elements [thegem-elements-elementor] Researcher João Pedro S Alcântara (Kinorth) More Details > Tonda <= 2.5 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57805 Patch Status Unpatched Published Jul 2, 2026 Affected Software Tonda - Elegant Shop WordPress Theme [tonda] Researcher João Pedro S Alcântara (Kinorth) More Details > Tour Master - Tour Booking, Travel, Hotel <= 5.4.5 - Authenticated (Subscriber+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2025-69133 Patch Status Unpatched Published Jun 29, 2026 Affected Software Tour Master - Tour Booking, Travel, Hotel [tourmaster] Researcher João Pedro S Alcântara (Kinorth) More Details > Video Gallery <= 4.0.3 - Authenticated (Subscriber+) Arbitrary Function Call via 'path' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-12923 Patch Status Patched Published Jun 30, 2026 Affected Software Video Gallery – YouTube Gallery, Playlist & Video Grid [youtube-showcase] Researcher PRISM More Details > Visualizer <= 4.0.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via /visualizer/v1/action/{chart}/{type}/ REST Endpoint 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-13468 Patch Status Patched Published Jun 30, 2026 Affected Software Visualizer – Tables & Charts Manager with Built-in AI Generator [visualizer] Researcher Niv Kochan More Details > Werkstatt - Creative Portfolio WordPress Theme <= 4.8.3 - Authenticated (Contributor+) PHP Object Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-27414 Patch Status Unpatched Published Jun 30, 2026 Affected Software Werkstatt - Creative Portfolio WordPress Theme [werkstatt] Researcher João Pedro S Alcântara (Kinorth) More Details > WP Fast Total Search – The Power of Indexed Search <= 1.80.280 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57683 Patch Status Patched Published Jun 29, 2026 Affected Software WP Fast Total Search – The Power of Indexed Search [fulltext-search] Researcher Nguyen Dinh Hai (HaiND) More Details > WP Review Slider Pro <= 12.7.2 - Unauthenticated SQL Injection via 'notinstring' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-8441 Patch Status Patched Published Jul 1, 2026 Affected Software WP Review Slider Pro [wp-review-slider-pro] Researcher h0xilo More Details > Admin and Site Enhancements (ASE) Pro <= 8.8.5 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57625 Patch Status Patched Published Jun 29, 2026 Affected Software Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro] Researcher Nguyen Ba Khanh More Details > Ajax Load More - Filters <= 3.4.1 - Unauthenticated Stored Cross-Site Scripting via 'taxonomy_include_children' Field 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-8141 Patch Status Patched Published Jun 29, 2026 Affected Software Ajax Load More - Filters [ajax-load-more-filters] Researcher jonathan dunn More Details > Artale | Wedding Photography WordPress <= 2.2.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2025-69152 Patch Status Unpatched Published Jun 30, 2026 Affected Software Artale | Wedding Photography WordPress [artale] Researcher João Pedro S Alcântara (Kinorth) More Details > BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.8 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57320 Patch Status Patched Published Jun 29, 2026 Affected Software BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] Researcher Bonds More Details > Business Directory Plugin – Easy Listing Directories for WordPress <= 6.4.22 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57326 Patch Status Patched Published Jun 29, 2026 Affected Software Business Directory Plugin – Easy Listing Directories for WordPress [business-directory-plugin] Researcher Saleh Elsayed (0xManticore) More Details > Classified Listing – AI-Powered Classified ads & Business Directory <= 5.4.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57344 Patch Status Patched Published Jun 29, 2026 Affected Software Classified Listing – AI-Powered Classified ads & Business Directory [classified-listing] Researcher daroo More Details > CodePeople Post Map for Google Maps <= 1.2.5 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57670 Patch Status Patched Published Jun 30, 2026 Affected Software CodePeople Post Map for Google Maps [codepeople-post-map] Researcher dutafi More Details > Comments <= 7.6.56 - Unauthenticated Stored Cross-Site Scripting via 'Website' Field 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-9148 Patch Status Patched Published Jul 2, 2026 Affected Software Comments – wpDiscuz [wpdiscuz] Researcher mickeyjoe More Details > Custom Payment Gateways for WooCommerce <= 2.1.0 - Unauthenticated Stored Cross-Site Scripting via 'alg_wc_cpg_input_fields' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-7517 Patch Status Patched Published Jun 30, 2026 Affected Software Custom Payment Gateways for WooCommerce [custom-payment-gateways-woocommerce] Researcher Azril Fathoni (kiseki) More Details > eCommerce Product Catalog Plugin for WordPress <= 3.5.4 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57360 Patch Status Patched Published Jul 1, 2026 Affected Software eCommerce Product Catalog Plugin for WordPress [ecommerce-product-catalog] Researcher Jakub Herman More Details > Fitness Zone WordPress <= 5.7 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2025-69155 Patch Status Unpatched Published Jun 30, 2026 Affected Software Fitness Zone WordPress Theme [fitnesszone] Researcher João Pedro S Alcântara (Kinorth) More Details > Five Star Business Profile and Schema <= 2.3.19 - Authenticated (Editor+) Arbitrary Code Execution 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-27436 Patch Status Unpatched Published Jun 30, 2026 Affected Software Five Star Business Profile and Schema [business-profile] Researcher daroo More Details > HandL UTM Grabber / Tracker <= 2.9.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57351 Patch Status Patched Published Jul 1, 2026 Affected Software HandL UTM Grabber / Tracker [handl-utm-grabber] Researcher Ananda Dhakal More Details > Internal Links Manager <= 3.0.3 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57345 Patch Status Patched Published Jun 29, 2026 Affected Software Internal Links Manager [seo-automated-link-building] Researcher dodoh4t More Details > Kids Life | Children School WordPress <= 5.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-27402 Patch Status Unpatched Published Jun 30, 2026 Affected Software Kids Life | Children School WordPress [kidslife] Researcher João Pedro S Alcântara (Kinorth) More Details > Kids Zone - Children WordPress <= 5.4 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2025-69156 Patch Status Unpatched Published Jun 30, 2026 Affected Software Kids Zone - Children WordPress Theme [kidszone] Researcher João Pedro S Alcântara (Kinorth) More Details > Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages <= 1.5.3.5 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57337 Patch Status Patched Published Jun 29, 2026 Affected Software Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages [page-builder-add] Researcher Nguyen Dinh Hai (HaiND) More Details > Modula - PRO <= 2.10.8 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57426 Patch Status Patched Published Jul 1, 2026 Affected Software Module PRO [modula] Researcher Nguyen Ba Khanh More Details > MoreConvert Wishlist for WooCommerce <= 1.9.19 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57356 Patch Status Patched Published Jul 1, 2026 Affected Software MoreConvert Wishlist for WooCommerce [smart-wishlist-for-more-convert] Researcher Manopakorn Kooharueangrong (manop55555) More Details > NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-12142 Patch Status Patched Published Jun 30, 2026 Affected Software NEX-Forms – Ultimate Forms Plugin for WordPress [nex-forms-express-wp-form-builder] Researcher Anthony Cihan (Hann1bl3L3ct3r) More Details > NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-13040 Patch Status Patched Published Jul 2, 2026 Affected Software NEX-Forms – Ultimate Forms Plugin for WordPress [nex-forms-express-wp-form-builder] Researcher Taichi Kashimura More Details > Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.7 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57673 Patch Status Patched Published Jun 30, 2026 Affected Software Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization [optimole-wp] Researcher daroo More Details > Perfmatters <= 2.6.4 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57671 Patch Status Patched Published Jun 30, 2026 Affected Software Perfmatters [perfmatters] Researcher daroo More Details > Product Addons and Product Options With Custom Fields – WowAddons <= 1.6.14 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57686 Patch Status Patched Published Jun 30, 2026 Affected Software Product Addons and Product Options With Custom Fields – WowAddons [product-addons] Researcher Nguyen Ba Khanh More Details > Real Estate 7 WordPress <= 3.5.9 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57343 Patch Status Patched Published Jun 29, 2026 Affected Software Real Estate 7 WordPress [realestate-7] Researcher João Pedro S Alcântara (Kinorth) More Details > ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema <= 2.3.10 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57359 Patch Status Patched Published Jul 1, 2026 Affected Software ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema [reviewx] Researcher Psalms Christopher Matovu (ByteOverride) More Details > Simple Link Directory Pro <= 15.0.5 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57682 Patch Status Patched Published Jun 30, 2026 Affected Software Simple Link Directory Pro [qc-simple-link-directory] Researcher dutafi More Details > Slider Revolution 7.0.0-7.0.16 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57678 Patch Status Patched Published Jun 30, 2026 Affected Software Slider Revolution [revslider] Researcher daroo More Details > SpaLab | Beauty Salon WordPress <= 6.7 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2025-69154 Patch Status Unpatched Published Jun 30, 2026 Affected Software SpaLab | Beauty Salon WordPress Theme [spalab] Researcher João Pedro S Alcântara (Kinorth) More Details > Survey Maker by AYS <= 5.2.2.5 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57361 Patch Status Patched Published Jul 1, 2026 Affected Software Survey Maker by AYS [survey-maker] Researcher Nguyen Ba Khanh More Details > Timetics – Appointment Booking Calendar & Scheduling System <= 1.0.58 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57674 Patch Status Patched Published Jun 30, 2026 Affected Software Timetics – Appointment Booking Calendar & Scheduling System [timetics] Researcher daroo More Details > Webmention <= 5.8.0 - Unauthenticated Stored Cross-Site Scripting via MF2 'photo'/'url' Author Properties 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-10513 Patch Status Patched Published Jun 30, 2026 Affected Software Webmention [webmention] Researcher Volodymyr Kolesnykov More Details > WP Database Backup <= 7.11 - Authenticated (Administrator+) OS Command Injection via 'wp_db_exclude_table' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-9834 Patch Status Patched Published Jul 1, 2026 Affected Software WP Database Backup – Unlimited Database & Files Backup by Backup for WP [wp-database-backup] Researcher Irwan Kusuma More Details > WP Debugging <= 2.12.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57350 Patch Status Patched Published Jul 1, 2026 Affected Software WP Debugging [wp-debugging] Researcher Ananda Dhakal More Details > WP Photo Album Plus <= 9.2.02.004 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57675 Patch Status Patched Published Jun 30, 2026 Affected Software WP Photo Album Plus [wp-photo-album-plus] Researcher Nguyen Ba Khanh More Details > WPAdverts – Classifieds Plugin <= 2.3.1 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57366 Patch Status Patched Published Jul 1, 2026 Affected Software WPAdverts – Classifieds Plugin [wpadverts] Researcher Evan NR More Details > WPBot <= 8.4.9 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-13731 Patch Status Patched Published Jun 30, 2026 Affected Software WPBot – AI ChatBot for Live Support, Lead Generation, AI Services [chatbot] Researcher PRISM More Details > wpDataTables (Premium) <= 6.5.1.1 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57672 Patch Status Patched Published Jun 30, 2026 Affected Software wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables] Researcher Nguyen Ba Khanh More Details > WPeMatico RSS Feed Fetcher <= 2.8.17 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57349 Patch Status Patched Published Jul 1, 2026 Affected Software WPeMatico RSS Feed Fetcher [wpematico] Researcher João Pedro S Alcântara (Kinorth) More Details > Corpkit - Business Consulting WordPress Theme <= 1.0.5 - Authenticated (Subscriber+) Sensitive Information Exopsure 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2025-69132 Patch Status Unpatched Published Jun 30, 2026 Affected Software Corpkit - Business Consulting WordPress Theme [corpkit] Researcher Bonds More Details > Custom Field Template <= 2.7.8 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-57687 Patch Status Patched Published Jun 29, 2026 Affected Software Custom Field Template [custom-field-template] Researcher daroo More Details > CWS SVGicons <= 1.5.5 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-57787 Patch Status Unpatched Published Jul 2, 2026 Affected Software cws-svgicons [cws-svgicons] Researcher Phat RiO More Details > Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value' 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-9145 Patch Status Patched Published Jul 1, 2026 Affected Software Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] Researcher Jonah Burgess (CryptoCat) More Details > GD Rating System <= 3.7 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-57771 Patch Status Unpatched Published Jul 2, 2026 Affected Software GD Rating System [gd-rating-system] Researcher VanTastic More Details > Groundhogg <= 4.5.8 - Authenticated (Custom+) SQL Injection via 'select' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-14029 Patch Status Patched Published Jul 1, 2026 Affected Software Groundhogg — CRM, Newsletters, and Marketing Automation [groundhogg] Researcher PRISM More Details > iNET Webkit 1.2.4 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-57752 Patch Status Unpatched Published Jul 2, 2026 Affected Software iNET Webkit [inet-webkit] Researcher Evan NR More Details > LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'userId' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-11988 Patch Status Patched Published Jun 30, 2026 Affected Software LearnPress – WordPress LMS Plugin for Create and Sell Online Courses [learnpress] Researcher javitoia More Details > MotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection via 's' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-13454 Patch Status Patched Published Jun 30, 2026 Affected Software MotoPress Appointment Booking [motopress-appointment-lite] Researcher MatilJ More Details > PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-11367 Patch Status Unpatched Published Jun 29, 2026 Affected Software PixMagix – WordPress Image Editor [pixmagix] Researcher devploit More Details > Shopping Cart & eCommerce Store <= 5.9.1 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-57765 Patch Status Unpatched Published Jul 2, 2026 Affected Software Shopping Cart & eCommerce Store [wp-easycart] Researcher Nguyen Dinh Hai (HaiND) More Details > Taskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'task_search' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-12110 Patch Status Patched Published Jun 30, 2026 Affected Software Taskbuilder – Project Management & Task Management Tool With Kanban Board [taskbuilder] Researcher d.v4n_s3c More Details > Taskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'wppm_proj_filter' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-12090 Patch Status Patched Published Jun 30, 2026 Affected Software Taskbuilder – Project Management & Task Management Tool With Kanban Board [taskbuilder] Researcher Catalin Oancea (0x4D5A) More Details > Unicamp - University and College WordPress Theme <= 2.2.2 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2025-69094 Patch Status Unpatched Published Jun 29, 2026 Affected Software unicamp [unicamp] Researcher Bonds More Details > WP Inventory Manager <= 2.4.0 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-57772 Patch Status Unpatched Published Jul 2, 2026 Affected Software WP Inventory Manager [wp-inventory-manager] Researcher dodoh4t More Details > Business Directory Plugin – Easy Listing Directories for WordPress <= 6.4.22 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57328 Patch Status Patched Published Jun 29, 2026 Affected Software Business Directory Plugin – Easy Listing Directories for WordPress [business-directory-plugin] Researcher she11f More Details > CM Business Directory <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Business Address Meta Fields 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-8892 Patch Status Patched Published Jul 2, 2026 Affected Software CM Business Directory – Optimise and showcase local business [cm-business-directory] Researcher Muhammad Yudha - DJ More Details > Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-13733 Patch Status Patched Published Jun 30, 2026 Affected Software Download Manager [download-manager] Researcher PRISM More Details > Envision Page Builder – A collection of WordPress Gutenberg blocks & templates <= 0.22 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57780 Patch Status Unpatched Published Jul 2, 2026 Affected Software Envision Page Builder – A collection of WordPress Gutenberg blocks & templates [envision-page-builder] Researcher Athiwat Tiprasaharn (Jitlada) More Details > Event Organiser <= 3.12.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via eo_events Shortcode 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-2387 Patch Status Patched Published Jun 30, 2026 Affected Software Event Organiser [event-organiser] Researcher Muhammad Yudha - DJ More Details > FV Flowplayer Video Player <= 7.5.51.7212 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'video_player' Shortcode 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-12135 Patch Status Patched Published Jun 30, 2026 Affected Software FV Flowplayer Video Player [fv-wordpress-flowplayer] Researcher Muhammad Yudha - DJ More Details > GenerateBlocks <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-9756 Patch Status Patched Published Jul 2, 2026 Affected Software GenerateBlocks [generateblocks] Researcher Kirasec More Details > GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.161 - Authenticated (Subscriber+) Server-Side Request Forgery 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57681 Patch Status Patched Published Jun 30, 2026 Affected Software GeoDirectory – WP Business Directory Plugin and Classified Listings Directory [geodirectory] Researcher dodoh4t More Details > GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-13246 Patch Status Patched Published Jun 30, 2026 Affected Software GiveWP – Donation Plugin and Fundraising Platform [give] Researcher AmonRa More Details > GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-13704 Patch Status Patched Published Jul 1, 2026 Affected Software GiveWP – Donation Plugin and Fundraising Platform [give] Researcher Chirita Catalin-Andrei (CC99IE) More Details > Insert Pages <= 3.11.4 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Field Keys (Meta Key Names) 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-10089 Patch Status Patched Published Jul 1, 2026 Affected Software Insert Pages [insert-pages] Researcher Athiwat Tiprasaharn (Jitlada) More Details > JetWidgets For Elementor <= 1.0.21 - Authenticated (Author+) Stored Cross-Site Scripting via Animated Box 'animation_effect' Setting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-11380 Patch Status Patched Published Jun 30, 2026 Affected Software JetWidgets For Elementor [jetwidgets-for-elementor] Researcher Athiwat Tiprasaharn (Jitlada) More Details > JSON API User <= 4.1.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'content' Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-9626 Patch Status Patched Published Jul 2, 2026 Affected Software JSON API User [json-api-user] Researcher Yat More Details > Kali Forms <= 2.4.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'kaliforms_field_components' Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-9107 Patch Status Patched Published Jun 30, 2026 Affected Software Kali Forms — Contact Form & Drag-and-Drop Builder [kali-forms] Researcher Osvaldo Noe Gonzalez Del Rio (Os) More Details > LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-12732 Patch Status Patched Published Jun 30, 2026 Affected Software LearnPress – WordPress LMS Plugin for Create and Sell Online Courses [learnpress] Researchers zaimPRISM More Details > MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.27 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57330 Patch Status Patched Published Jun 29, 2026 Affected Software MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] Researcher endy More Details > Mosaic Gallery – Advanced Gallery <= 1.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57755 Patch Status Unpatched Published Jul 2, 2026 Affected Software Mosaic Gallery – Advanced Gallery [mosaic-gallery-advanced-gallery] Researcher zaim More Details > Reviews Widgets for Google, Yelp & TripAdvisor <= 2.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'page_id' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-12154 Patch Status Patched Published Jul 2, 2026 Affected Software Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations [fb-reviews-widget] Researcher Ilkeggs More Details > RSS Aggregator by Feedzy <= 5.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aspectRatio' Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-13252 Patch Status Patched Published Jul 1, 2026 Affected Software RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] Researcher PRISM More Details > RTMKit <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Heading Widget 'Background Text' Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-8351 Patch Status Patched Published Jul 2, 2026 Affected Software RTMKit [rometheme-for-elementor] Researcher theviper17y More Details > Shortcodes and extra features for Phlox theme <= 2.17.21 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57737 Patch Status Unpatched Published Jul 1, 2026 Affected Software Shortcodes and extra features for Phlox theme [auxin-elements] Researcher timomangcut More Details > ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization <= 3.11.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57342 Patch Status Patched Published Jun 29, 2026 Affected Software ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images] Researcher dodoh4t More Details > Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management <= 151 - Authenticated (Author+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57762 Patch Status Unpatched Published Jul 2, 2026 Affected Software Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management [simple-urls] Researcher Athiwat Tiprasaharn (Jitlada) More Details > Speaker <= 4.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57783 Patch Status Unpatched Published Jul 2, 2026 Affected Software Speaker [speaker] Researcher w41bu1 More Details > Structured Content (JSON-LD) #wpsc <= 1.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57763 Patch Status Unpatched Published Jul 2, 2026 Affected Software Structured Content (JSON-LD) #wpsc [structured-content] Researcher zaim More Details > Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57764 Patch Status Unpatched Published Jul 2, 2026 Affected Software Surbma | Yoast SEO Breadcrumb Shortcode [surbma-yoast-breadcrumb-shortcode] Researcher zaim More Details > TheFox <= 3.9.70 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57684 Patch Status Unpatched Published Jun 29, 2026 Affected Software TheFox | Responsive Multi-Purpose WordPress Theme [thefox] Researcher Ananda Dhakal More Details > Tutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment Title 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-13443 Patch Status Patched Published Jun 30, 2026 Affected Software Tutor LMS – eLearning and online course solution [tutor] Researcher skyv3il More Details > Ultimate Member <= 2.11.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Non-HTML Custom Textarea Profile Field 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-8489 Patch Status Patched Published Jul 2, 2026 Affected Software Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] Researcher daroo More Details > weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'connectorWidth' Block Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-12734 Patch Status Patched Published Jul 2, 2026 Affected Software weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot [wedocs] Researcher PRISM More Details > weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-12731 Patch Status Patched Published Jul 2, 2026 Affected Software weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot [wedocs] Researcher PRISM More Details > WooCommerce Designer Pro <= 1.9.34 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57329 Patch Status Patched Published Jun 29, 2026 Affected Software WooCommerce Designer Pro [wc-designer-pro] Researcher Nguyen Ba Khanh More Details > WP Photo Album Plus <= 9.1.13.005 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'subtext' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-10095 Patch Status Patched Published Jun 30, 2026 Affected Software WP Photo Album Plus [wp-photo-album-plus] Researcher Muhammad Yudha - DJ More Details > WPBakery Page Builder Addons by Livemesh <= 3.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57754 Patch Status Unpatched Published Jul 2, 2026 Affected Software WPBakery Page Builder Addons by Livemesh [addons-for-visual-composer] Researcher timomangcut More Details > Zakra <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta REST API 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4804 Patch Status Patched Published Jul 2, 2026 Affected Software Zakra [zakra] Researcher Osvaldo Noe Gonzalez Del Rio (Os) More Details > ARforms <= 7.1.2 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-57338 Patch Status Patched Published Jun 29, 2026 Affected Software ARforms [arforms] Researcher dutafi More Details > Automotive Car Dealership Business WordPress Theme <= 13.3.3 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-27426 Patch Status Unpatched Published Jun 30, 2026 Affected Software Automotive Car Dealership Business WordPress Theme [automotive] Researcher João Pedro S Alcântara (Kinorth) More Details > Automotive Listings <= 18.6 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-27425 Patch Status Unpatched Published Jun 29, 2026 Affected Software Automotive Listings [automotive] Researcher João Pedro S Alcântara (Kinorth) More Details > Link Whisper Free <= 0.9.4 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-57333 Patch Status Patched Published Jun 29, 2026 Affected Software Link Whisper Free [link-whisper] Researcher João Pedro S Alcântara (Kinorth) More Details > LMS <= 9.7 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-27404 Patch Status Unpatched Published Jun 30, 2026 Affected Software LMS - Education WordPress Theme [lms] Researcher João Pedro S Alcântara (Kinorth) More Details > NativeChurch <= 4.8.8.2 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-27408 Patch Status Unpatched Published Jun 30, 2026 Affected Software NativeChurch [NativeChurch] Researcher João Pedro S Alcântara (Kinorth) More Details > Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 3.0.4 - Unauthenticated Server-Side Request Forgery 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-57348 Patch Status Patched Published Jul 1, 2026 Affected Software Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction [paid-member-subscriptions] Researcher yangsori More Details > Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization <= 2.6.6 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-57357 Patch Status Patched Published Jul 1, 2026 Affected Software Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization [metasync] Researcher Evan NR More Details > SysBasics Customize My Account for WooCommerce – Live My Account Customizer <= 4.3.9 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-57358 Patch Status Patched Published Jul 1, 2026 Affected Software SysBasics Customize My Account for WooCommerce – Live My Account Customizer [customize-my-account-for-woocommerce] Researcher dutafi More Details > Trendy Travel <= 6.7 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2025-69153 Patch Status Unpatched Published Jun 30, 2026 Affected Software Trendy Travel WordPress [trendytravel] Researcher João Pedro S Alcântara (Kinorth) More Details > VikBooking Hotel Booking Engine & PMS <= 1.8.12 - Reflected Cross-Site Scripting via 'layoutstyle' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-12754 Patch Status Patched Published Jun 30, 2026 Affected Software VikBooking Hotel Booking Engine & PMS [vikbooking] Researcher PRISM More Details > WP Google Review Slider <= 18.1 - Reflected Cross-Site Scripting via 'place' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-13015 Patch Status Patched Published Jun 30, 2026 Affected Software WP Google Review Slider [wp-google-places-review-slider] Researcher PRISM More Details > WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 8.3.2 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-57362 Patch Status Patched Published Jul 1, 2026 Affected Software WPBot – AI ChatBot for Live Support, Lead Generation, AI Services [chatbot] Researcher Nguyen Dinh Hai (HaiND) More Details > WP Import Export Lite <= 3.9.30 - Authenticated (Administrator+) Server-Side Request Forgery via 'file_url' Parameter 5.5 CVSS Rating 5.5 (Medium) CVE-ID CVE-2026-11397 Patch Status Patched Published Jul 2, 2026 Affected Software WP Import Export Lite [wp-import-export-lite] Researcher 밥김국 More Details > CURCY <= 2.2.14 - Unauthenticated Arbitrary Shortcode Execution via 'exchange' Parameter 5.4 CVSS Rating 5.4 (Medium) CVE-ID CVE-2026-11778 Patch Status Patched Published Jul 2, 2026 Affected Software CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x [woo-multi-currency] Researcher sterva More Details > Academy LMS <= 3.8.1 - Unauthenticated Insecure Direct Object Reference to Private Topic Disclosure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-5348 Patch Status Patched Published Jul 1, 2026 Affected Software Academy LMS [academy] Researcher Md. Moniruzzaman Prodhan (NomanProdhan) More Details > Advanced Booking & Appointment System – Webba Booking Calendar <= 6.4.13 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-27409 Patch Status Patched Published Jul 1, 2026 Affected Software Advanced Booking & Appointment System – Webba Booking Calendar [webba-booking-lite] Researcher Legion Hunter More Details > ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57352 Patch Status Patched Published Jul 1, 2026 Affected Software ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce [woo-alidropship] Researcher Ananda Dhakal More Details > ApplyOnline – Application Form Builder and Manager <= 2.6.7.6 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57721 Patch Status Patched Published Jul 1, 2026 Affected Software ApplyOnline – Application Form Builder and Manager [apply-online] Researcher Jakub Herman More Details > Appointment Bookings for Zoom GoogleMeet and more – Wappointment <= 2.7.6 - Unauthenticated Insecure Direct Object Reference via Predictable 'edit_key' / 'appointmentkey' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-9188 Patch Status Patched Published Jul 1, 2026 Affected Software Appointment Bookings for Zoom GoogleMeet and more – Wappointment [wappointment] Researcher davidfdzmorilla More Details > Booking calendar, Appointment Booking System <= 3.2.36 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57778 Patch Status Unpatched Published Jul 2, 2026 Affected Software Booking calendar, Appointment Booking System [booking-calendar] Researcher Nabil Irawan More Details > Business Directory Plugin – Easy Listing Directories for WordPress <= 6.4.23 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57339 Patch Status Patched Published Jun 29, 2026 Affected Software Business Directory Plugin – Easy Listing Directories for WordPress [business-directory-plugin] Researcher John Umoru More Details > Colissimo shipping methods for WooCommerce <= 2.9.0 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57341 Patch Status Patched Published Jun 29, 2026 Affected Software Colissimo shipping methods for WooCommerce [colissimo-shipping-methods-for-woocommerce] Researcher HieuPenguinnn More Details > Exclusive Addons for Elementor <= 2.7.9.9 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-59511 Patch Status Patched Published Jul 5, 2026 Affected Software Exclusive Addons for Elementor [exclusive-addons-for-elementor] Researcher Ananda Dhakal More Details > ez Form Calculator Premium <= 2.14.1.2 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57750 Patch Status Unpatched Published Jul 2, 2026 Affected Software ez Form Calculator Premium [ez-form-calculator-premium] Researcher Phat RiO More Details > Fascinate <= 1.1.5 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57779 Patch Status Unpatched Published Jul 2, 2026 Affected Software Fascinate [fascinate] Researcher Legion Hunter More Details > FormLayer <= 1.0.6 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-59519 Patch Status Patched Published Jul 5, 2026 Affected Software FormLayer [formlayer] Researcher Ananda Dhakal More Details > Japanized for WooCommerce <= 2.9.12 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57340 Patch Status Patched Published Jun 29, 2026 Affected Software Japanized for WooCommerce [woocommerce-for-japan] Researcher Nguyen Dinh Hai (HaiND) More Details > JetFormBuilder <= 3.6.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'context' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-13459 Patch Status Patched Published Jul 1, 2026 Affected Software JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] Researcher Niv Kochan More Details > Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Arbitrary Email Content Injection (Mail Relay / Phishing) via 'emailBody' and 'emailSubject' Parameters 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-12472 Patch Status Patched Published Jul 1, 2026 Affected Software Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] Researchers Niv KochanMatan Bahar More Details > Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX Action 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-12122 Patch Status Patched Published Jul 1, 2026 Affected Software Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] Researcher Jagadesh Achanta More Details > Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57753 Patch Status Unpatched Published Jul 2, 2026 Affected Software Kit (formerly ConvertKit) for WooCommerce [convertkit-for-woocommerce] Researcher Nguyen Ba Khanh More Details > LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-11398 Patch Status Patched Published Jul 2, 2026 Affected Software Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] Researcher hhhai More Details > LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-12657 Patch Status Patched Published Jul 1, 2026 Affected Software Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] Researcher gidget smith More Details > MeetingHub – Webinar & Meeting Plugin for Zoom, Google Meet, Webex, Microsoft Teams, & Jitsi Meet <= 1.25.10 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57781 Patch Status Unpatched Published Jul 2, 2026 Affected Software MeetingHub – Webinar & Meeting Plugin for Zoom, Google Meet, Webex, Microsoft Teams, & Jitsi Meet [meetinghub] Researcher Nabil Irawan More Details > MotoPress Appointment Booking <= 2.4.4 - Unauthenticated Insecure Direct Object Reference to 'payment_details.booking_id' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-9180 Patch Status Patched Published Jul 2, 2026 Affected Software MotoPress Appointment Booking [motopress-appointment-lite] Researcher g0wthr More Details > Motors - Car Dealer, Rental & Listing WordPress theme <= 5.6.80 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-27433 Patch Status Unpatched Published Jun 30, 2026 Affected Software Motors - Car Dealer, Rental & Listing WordPress theme [motors] Researcher Rafie Muhammad More Details > My Calendar <= 3.7.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'vcal' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-11896 Patch Status Patched Published Jul 1, 2026 Affected Software My Calendar – Accessible Event Manager [my-calendar] Researchers Athiwat Tiprasaharn (Jitlada)Tharadol Suksamran (d3kc4rt_1) More Details > Ninja Forms - File Uploads <= 3.3.29 - Missing Authorization to Unauthenticated Log Disclosure and Deletion via debug-log/delete-all and debug-log/get-all REST Endpoints 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-12557 Patch Status Patched Published Jul 2, 2026 Affected Software Ninja Forms - File Uploads [ninja-forms-uploads] Researcher Ad4m5 More Details > NOWPayments for WooCommerce – Crypto Payment Gateway <= 1.4.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-39448 Patch Status Unpatched Published Jun 29, 2026 Affected Software NOWPayments for WooCommerce – Crypto Payment Gateway [nowpayments-for-woocommerce] Researcher b4shu206 More Details > OpenAI Chatbot for WordPress – Helper <= 1.1.4 - Missing Authorization to Unauthenticated Arbitrary Content Deletion 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2025-69134 Patch Status Unpatched Published Jun 29, 2026 Affected Software OpenAI Chatbot for WordPress – Helper [helper] Researcher Denver Jackson More Details > POS Entegratör – Gurmehub Ödeme Eklentisi <= 3.7.103 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57688 Patch Status Patched Published Jun 29, 2026 Affected Software POS Entegratör – Gurmehub Ödeme Eklentisi [pos-entegrator] Researcher hivesec More Details > Premium Addons for KingComposer <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Custom Sidebar Creation and Deletion via 'add_custom_sidebar' and 'remove_custom_sidebar' AJAX actions 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-12349 Patch Status Unpatched Published Jun 29, 2026 Affected Software Premium Addons for KingComposer [premium-addons-for-kingcomposer] Researcher Eason More Details > Sendcloud Shipping <= 1.0.31 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57760 Patch Status Unpatched Published Jul 2, 2026 Affected Software Sendcloud Shipping [sendcloud-connected-shipping] Researcher Nguyen Ba Khanh More Details > Universal Clocks <= 1.2.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57782 Patch Status Unpatched Published Jul 2, 2026 Affected Software Universal Clocks [universal-clocks] Researcher Legion Hunter More Details > User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration <= 4.3.7 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57334 Patch Status Patched Published Jun 29, 2026 Affected Software User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration [wp-user-frontend] Researcher(s): Unknown More Details > VW Food Corner <= 1.1.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57774 Patch Status Unpatched Published Jul 2, 2026 Affected Software VW Food Corner [vw-food-corner] Researcher Nabil Irawan More Details > VW Wedding <= 1.3.7 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57776 Patch Status Unpatched Published Jul 2, 2026 Affected Software VW Wedding [vw-wedding] Researcher Nabil Irawan More Details > Woffice CRM <= 5.4.31 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-27435 Patch Status Unpatched Published Jun 29, 2026 Affected Software Woffice CRM [woffice] Researcher João Pedro S Alcântara (Kinorth) More Details > Woostify Sites Library <= 1.6.2 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2025-66076 Patch Status Unpatched Published Jun 29, 2026 Affected Software Woostify Sites Library [woostify-sites-library] Researcher Legion Hunter More Details > WPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display Name 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-12127 Patch Status Patched Published Jun 30, 2026 Affected Software WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] Researcher Jack Pas (Dark.) More Details > Advanced Shipment Tracking for WooCommerce <= 4.0 - Authenticated (Shop manager+) SQL Injection 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-57773 Patch Status Patched Published Jul 2, 2026 Affected Software Advanced Shipment Tracking for WooCommerce [woo-advanced-shipment-tracking] Researcher Nguyen Ba Khanh More Details > Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Administrator+) SQL Injection via 's' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-12920 Patch Status Patched Published Jul 2, 2026 Affected Software Cookie Banner for GDPR / CCPA – WPLP Cookie Consent [gdpr-cookie-consent] Researcher PRISM More Details > Houzez Property Feed <= 2.5.46 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-13357 Patch Status Patched Published Jul 1, 2026 Affected Software Houzez Property Feed [houzez-property-feed] Researcher PRISM More Details > Editorial Rating <= 4.0.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Link URL' Field 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-12560 Patch Status Unpatched Published Jun 29, 2026 Affected Software Editorial Rating – Product Review & Rating System [editorial-rating] Researcher Supoj Polsawas (sp0x5ec) More Details > Enable Media Replace <= 4.2.1 - Authenticated (Editor+) Stored Cross-Site Scripting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-57722 Patch Status Patched Published Jul 1, 2026 Affected Software Enable Media Replace [enable-media-replace] Researcher Ananda Dhakal More Details > Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via custom_thumbnail Parameter 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-10104 Patch Status Patched Published Jul 1, 2026 Affected Software Product Video Gallery for Woocommerce [product-video-gallery-slider-for-woocommerce] Researcher Ravindu Lakmina Munaweera More Details > Team Members <= 8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'custom_css' Parameter 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-12114 Patch Status Patched Published Jun 29, 2026 Affected Software Team Members – Multi Language Supported Team Plugin [team-showcase-supreme] Researcher Averon Averenkov (Averon Averenkov) More Details > Ad Inserter <= 2.8.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via 'data' Shortcode Attribute 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-11900 Patch Status Patched Published Jul 2, 2026 Affected Software Ad Inserter – Ad Manager & AdSense Ads [ad-inserter] Researcher nightward More Details > Advanced Contact form 7 DB <= 2.0.9 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57669 Patch Status Patched Published Jun 30, 2026 Affected Software Advanced Contact form 7 DB [advanced-cf7-db] Researcher timomangcut More Details > Appointment Booking Calendar <= 1.4.02 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-12113 Patch Status Patched Published Jun 30, 2026 Affected Software Appointment Booking Calendar [appointment-booking-calendar] Researcher PRISM More Details > Booked - Appointment Booking for WordPress <= 3.0.0 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57747 Patch Status Unpatched Published Jul 2, 2026 Affected Software Booked - Appointment Booking for WordPress [booked] Researcher Phat RiO More Details > Booked - Appointment Booking for WordPress <= 3.0.0 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57746 Patch Status Unpatched Published Jul 2, 2026 Affected Software Booked - Appointment Booking for WordPress [booked] Researcher Phat RiO More Details > Classified Listing – AI-Powered Classified ads & Business Directory <= 5.4.2 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57355 Patch Status Patched Published Jul 1, 2026 Affected Software Classified Listing – AI-Powered Classified ads & Business Directory [classified-listing] Researcher Septio Noerdiansyah More Details > CrawlWP SEO – Instant Search Engine Indexing & SEO Performance Monitor <= 3.0.16 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-59520 Patch Status Patched Published Jul 5, 2026 Affected Software CrawlWP SEO – Instant Search Engine Indexing & SEO Performance Monitor [mihdan-index-now] Researcher Ananda Dhakal More Details > EduMall - Professional LMS Education Center WordPress Theme <= 4.5.1 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57797 Patch Status Patched Published Jul 2, 2026 Affected Software EduMall - Professional LMS Education Center WordPress Theme [edumall] Researcher Nguyen Ba Khanh More Details > Email Subscribers & Newsletters <= 5.9.27 - Missing Authorization to Authenticated (Contributor+) Settings Modification via ig_es_handle_request AJAX Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-11592 Patch Status Patched Published Jul 1, 2026 Affected Software Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress [email-subscribers] Researcher Dmitrii Ignatyev More Details > Envo's Templates & Widgets for Elementor and WooCommerce <= 1.4.26 - Missing Authorization to Authenticated (Author+) Private Content Disclosure via Envo Tabs Widget 'templates' Setting 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-11600 Patch Status Patched Published Jul 1, 2026 Affected Software Envo's Templates & Widgets for Elementor and WooCommerce [envo-elementor-for-woocommerce] Researchers Alessandro Greco (Aleff)Giovanbattista Ianni More Details > Flatsome <= 3.20.5 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57730 Patch Status Unpatched Published Jul 1, 2026 Affected Software Flatsome [flatsome] Researcher Bonds More Details > Flatsome <= 3.20.5 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57731 Patch Status Unpatched Published Jul 1, 2026 Affected Software Flatsome [flatsome] Researcher Bonds More Details > GiveWP <= 4.15.3 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-11981 Patch Status Patched Published Jun 30, 2026 Affected Software GiveWP – Donation Plugin and Fundraising Platform [give] Researcher javitoia More Details > Heateor Social Login WordPress <= 1.1.39 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57751 Patch Status Unpatched Published Jul 1, 2026 Affected Software Heateor Social Login WordPress [heateor-social-login] Researcher ParkHyunWoo More Details > HubSpot All-In-One Marketing – Forms, Popups, Live Chat <= 11.3.56 - Authenticated (Contributor+) Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57736 Patch Status Unpatched Published Jul 1, 2026 Affected Software HubSpot All-In-One Marketing – Forms, Popups, Live Chat [leadin] Researcher Jakub Herman More Details > JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Creation/Modification via season_groupedit AJAX action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-12134 Patch Status Patched Published Jul 1, 2026 Affected Software JoomSport – for Sports: Team & League, Football, Hockey & more [joomsport-sports-league-results-management] Researchers PRISMChloe Chamberland More Details > JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Deletion via season_groupdel AJAX action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-12133 Patch Status Patched Published Jun 30, 2026 Affected Software JoomSport – for Sports: Team & League, Football, Hockey & more [joomsport-sports-league-results-management] Researchers Chloe ChamberlandPRISM More Details > Kadence Blocks <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Optimizer Data Deletion/Read/Modification via 'post_path' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-12904 Patch Status Patched Published Jun 30, 2026 Affected Software Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] Researcher se1en More Details > Kadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Attachment Creation via kadence_import_process_pattern/kadence_import_process_data AJAX Actions 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-12902 Patch Status Patched Published Jun 30, 2026 Affected Software Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] Researcher se1en More Details > Link Whisper Premium <= 2.9.0 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57353 Patch Status Patched Published Jul 1, 2026 Affected Software Link Whisper Premium [link-whisper-premium] Researcher Austin Ginder More Details > MainWP Dashboard: Self-hosted WordPress Management for Agencies <= 6.1.1 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57327 Patch Status Patched Published Jun 29, 2026 Affected Software MainWP Dashboard: Self-hosted WordPress Management for Agencies [mainwp] Researcher sleeper More Details > Martfury - WooCommerce Marketplace WordPress <= 3.2.8 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57685 Patch Status Unpatched Published Jun 29, 2026 Affected Software Martfury - Marketplace Mobile App Figma Template [martfury] Researcher Ananda Dhakal More Details > MotoPress Hotel Booking <= 6.0.3 - Authenticated (Subscriber+) Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57347 Patch Status Patched Published Jul 1, 2026 Affected Software MotoPress Hotel Booking [motopress-hotel-booking-lite] Researcher Sakimi More Details > Motors <= 1.4.111 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'stm_mark_as_sold_car' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-12435 Patch Status Patched Published Jun 30, 2026 Affected Software Motors – Car Dealership & Classified Listings Plugin [motors-car-dealership-classified-listings] Researcher Michael Perla (vizen5) More Details > pCloud WP Backup <= 2.0.4 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57757 Patch Status Unpatched Published Jul 2, 2026 Affected Software pCloud WP Backup [pcloud-wp-backup] Researcher R2D2 More Details > Permalink Manager for WooCommerce <= 1.0.8.2 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57758 Patch Status Unpatched Published Jul 2, 2026 Affected Software Permalink Manager for WooCommerce [permalink-manager-for-woocommerce] Researcher dodoh4t More Details > Plugin for Google Analytics by IO technologies <= 1.1 - Cross-Site Request Forgery via 'ga_id' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-8944 Patch Status Unpatched Published Jun 29, 2026 Affected Software Plugin for Google Analytics by IO technologies [io-engagement-analytics] Researcher afnaan More Details > ProfileGrid – User Profiles, Groups and Communities <= 5.9.9.8 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57759 Patch Status Unpatched Published Jul 2, 2026 Affected Software ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] Researcher dodoh4t More Details > Qi Blocks <= 1.4.9 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Style Modification via 'page_id' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-10096 Patch Status Patched Published Jun 30, 2026 Affected Software Qi Blocks [qi-blocks] Researcher Dmitrii Ignatyev More Details > Quads Ads Manager for Google AdSense <= 3.0.3 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57335 Patch Status Patched Published Jun 29, 2026 Affected Software Quads Ads Manager for Google AdSense [quick-adsense-reloaded] Researcher Ananda Dhakal More Details > Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9230 Patch Status Patched Published Jul 2, 2026 Affected Software Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker [quiz-master-next] Researcher Kirasec More Details > RTMKit <= 2.0.7 - Authenticated (Contributor+) Limited Local File Inclusion via 'template' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-5137 Patch Status Patched Published Jul 2, 2026 Affected Software RTMKit [rometheme-for-elementor] Researcher wesley (wcraft) More Details > Simple User Avatar <= 4.9 - Authenticated (Subscriber+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57676 Patch Status Patched Published Jun 29, 2026 Affected Software Simple User Avatar [simple-user-avatar] Researcher Ananda Dhakal More Details > Slim SEO <= 4.9.8 - Authenticated (Contributor+) Insufficient Authorization to Private Content Disclosure via 'object.ID' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-12408 Patch Status Patched Published Jun 30, 2026 Affected Software Slim SEO – A Fast & Automated SEO Plugin For WordPress [slim-seo] Researcher Abu Hurayra (HurayraIIT) More Details > Tax Exempt for WooCommerce <= 1.9.3 - Authenticated (Customer+) Path Traversal 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-49779 Patch Status Unpatched Published Jun 29, 2026 Affected Software Tax Exempt for WooCommerce [woocommerce-tax-exempt-plugin] Researcher Saad Malik More Details > ThumbPress – Compress Images, Manage Thumbnails, Detect Image Issues, WebP/AVIF, Lazy Loading, Hotlinking & More <= 6.3.2 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57720 Patch Status Patched Published Jul 1, 2026 Affected Software ThumbPress – Compress Images, Manage Thumbnails, Detect Image Issues, WebP/AVIF, Lazy Loading, Hotlinking & More [image-sizes] Researcher Denver Jackson More Details > VikBooking Hotel Booking Engine & PMS <= 1.8.12 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57723 Patch Status Patched Published Jul 1, 2026 Affected Software VikBooking Hotel Booking Engine & PMS [vikbooking] Researcher VDsec More Details > Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments <= 2.7.6 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57332 Patch Status Patched Published Jun 29, 2026 Affected Software Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments [wallet-system-for-woocommerce] Researcher Evan NR More Details > weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Missing Authorization to Authenticated (Subscriber+) Data Migration via wedocs_migrate_betterdocs_to_wedocs AJAX Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-12729 Patch Status Patched Published Jul 2, 2026 Affected Software weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot [wedocs] Researcher PRISM More Details > Werkstatt - Creative Portfolio WordPress Theme <= 4.7.2 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57690 Patch Status Unpatched Published Jun 29, 2026 Affected Software Werkstatt - Creative Portfolio WordPress Theme [werkstatt] Researcher Ananda Dhakal More Details > Werkstatt - Creative Portfolio WordPress Theme <= 4.7.2 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57689 Patch Status Unpatched Published Jun 29, 2026 Affected Software Werkstatt - Creative Portfolio WordPress Theme [werkstatt] Researcher Ananda Dhakal More Details > WPIDE – File Manager & Code Editor <= 3.5.6 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57766 Patch Status Unpatched Published Jul 2, 2026 Affected Software WPIDE – File Manager & Code Editor [wpide] Researcher dodoh4t More Details > As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence. This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can. Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. The post Wordfence Intelligence Weekly WordPress Vulnerability Report (June 29, 2026 to July 5, 2026) appeared first on Wordfence.
Quelle: www.wordfence.com