Wordfence Intelligence Weekly WordPress Vulnerability Report (June 29, 2026 to July 5, 2026)
Autor: Chloe Chamberland
⚠️ CVE-Referenzen:
CVE-2026-12923
CVE-2026-57355
CVE-2026-12135
CVE-2026-57802
CVE-2026-9145
CVE-2026-57778
CVE-2026-57736
CVE-2026-12920
CVE-2026-12731
CVE-2026-57338
CVE-2026-57334
CVE-2026-8351
CVE-2026-57685
CVE-2026-57773
CVE-2026-57763
CVE-2026-57783
CVE-2026-27419
CVE-2026-27414
CVE-2026-57751
CVE-2026-12133
CVE-2026-12560
CVE-2026-12734
CVE-2026-5821
CVE-2026-57793
CVE-2026-13468
CVE-2026-57341
CVE-2026-12113
CVE-2026-57623
CVE-2026-57342
CVE-2026-57353
CVE-2026-27436
CVE-2026-10089
CVE-2026-5348
CVE-2026-57678
CVE-2026-11380
CVE-2026-57352
CVE-2026-57339
CVE-2026-57753
CVE-2026-9756
CVE-2025-69156
CVE-2026-9834
CVE-2026-57737
CVE-2026-12224
CVE-2026-11397
CVE-2026-57330
CVE-2026-57731
CVE-2026-57759
CVE-2026-57801
CVE-2026-57677
CVE-2026-57346
CVE-2026-57358
CVE-2026-27409
CVE-2026-12073
CVE-2026-57791
CVE-2026-57790
CVE-2026-57683
CVE-2026-13040
CVE-2026-12408
CVE-2026-11398
CVE-2026-27060
CVE-2026-57800
CVE-2026-57351
CVE-2026-57343
CVE-2026-9188
CVE-2026-27435
CVE-2026-57672
CVE-2026-57776
CVE-2026-57796
CVE-2026-57676
CVE-2026-7517
CVE-2026-57789
CVE-2026-13357
CVE-2026-57805
CVE-2026-6070
CVE-2026-11896
CVE-2026-12435
CVE-2025-69155
CVE-2026-57758
CVE-2026-57803
CVE-2026-57356
CVE-2026-11981
CVE-2026-57723
CVE-2026-57794
CVE-2026-57752
CVE-2026-59511
CVE-2026-57760
CVE-2026-57335
CVE-2026-12754
CVE-2026-8489
CVE-2026-57340
CVE-2026-57792
CVE-2025-69153
CVE-2025-58902
CVE-2026-57679
CVE-2026-12557
CVE-2026-57687
CVE-2026-13459
CVE-2026-13251
CVE-2026-57625
CVE-2026-57689
CVE-2026-57682
CVE-2026-57328
CVE-2026-57345
CVE-2026-13252
CVE-2025-69133
CVE-2026-57670
CVE-2026-9180
CVE-2026-57327
CVE-2026-1239
CVE-2026-57781
CVE-2026-57720
CVE-2026-4804
CVE-2026-27408
CVE-2026-57674
CVE-2026-57675
CVE-2026-57426
CVE-2026-57362
CVE-2026-57754
CVE-2026-57765
CVE-2025-69152
CVE-2026-57747
CVE-2026-5137
CVE-2026-57779
CVE-2026-57344
CVE-2026-57692
CVE-2026-57669
CVE-2026-13369
CVE-2026-57673
CVE-2026-57764
CVE-2026-12729
CVE-2026-13443
CVE-2026-12657
CVE-2026-57804
CVE-2026-9107
CVE-2026-57333
CVE-2026-57748
CVE-2026-57684
CVE-2026-9230
CVE-2026-12110
CVE-2025-69132
CVE-2026-57337
CVE-2026-57681
CVE-2026-57348
CVE-2026-57347
CVE-2026-8141
CVE-2026-9148
CVE-2026-49779
CVE-2026-57721
CVE-2026-57757
CVE-2026-12472
CVE-2026-13704
CVE-2026-57686
CVE-2026-57326
CVE-2026-11367
CVE-2026-57772
CVE-2026-57671
CVE-2026-57755
CVE-2026-13015
CVE-2026-13454
CVE-2026-57798
CVE-2026-27404
CVE-2026-57730
CVE-2026-12158
CVE-2026-27426
CVE-2026-57690
CVE-2026-9711
CVE-2026-57361
CVE-2026-12154
CVE-2026-12732
CVE-2026-12902
CVE-2026-11600
CVE-2026-12127
CVE-2026-59520
CVE-2026-57799
CVE-2026-57762
CVE-2026-57366
CVE-2026-15158
CVE-2026-14352
CVE-2026-57788
CVE-2026-11387
CVE-2026-13733
CVE-2026-8944
CVE-2026-39448
CVE-2026-8892
CVE-2026-57766
CVE-2026-57331
CVE-2025-69134
CVE-2026-27412
CVE-2026-12090
CVE-2026-42382
CVE-2026-14029
CVE-2026-57749
CVE-2026-10104
CVE-2026-57782
CVE-2026-57359
CVE-2026-2387
CVE-2026-11592
CVE-2026-27425
CVE-2026-12134
CVE-2026-12142
CVE-2026-59519
CVE-2026-57787
CVE-2026-12349
CVE-2026-10096
CVE-2026-8441
CVE-2026-57795
CVE-2026-12114
CVE-2026-57797
CVE-2026-57722
CVE-2026-13228
CVE-2026-13731
CVE-2026-5524
CVE-2026-57624
CVE-2026-9626
CVE-2026-11823
CVE-2026-11988
CVE-2026-10095
CVE-2026-11778
CVE-2026-57688
CVE-2026-9725
CVE-2026-57780
CVE-2026-27402
CVE-2026-13246
CVE-2025-69094
CVE-2026-11900
CVE-2026-27433
CVE-2026-12240
CVE-2026-57332
CVE-2026-57350
CVE-2026-57320
CVE-2026-7311
CVE-2025-69154
CVE-2026-12904
CVE-2026-57774
CVE-2026-57357
CVE-2026-57771
CVE-2025-66076
CVE-2026-57746
CVE-2026-57360
CVE-2026-12122
CVE-2026-14249
CVE-2026-57349
CVE-2026-14327
CVE-2026-57750
CVE-2026-57329
CVE-2026-10513
Last week, there were 246 vulnerabilities disclosed in 179 WordPress Plugins and 40 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 100 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 35,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
Ninja Forms – File Uploads <= 3.3.29 – Unauthenticated Arbitrary File Read via File Upload Field ‘files[].data.file_path’ Parameter
WAF-RULE-923 – Data redacted while we work with the vendor on a patch.
WAF-RULE-924 – Data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status
Number of Vulnerabilities
Patched
158
Unpatched
88
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating
Number of Vulnerabilities
Medium Severity
150
High Severity
87
Critical Severity
9
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE
Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
87
Missing Authorization
50
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
25
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
19
Authorization Bypass Through User-Controlled Key
12
Cross-Site Request Forgery (CSRF)
12
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
11
Exposure of Sensitive Information to an Unauthorized Actor
7
Deserialization of Untrusted Data
4
Improper Control of Generation of Code ('Code Injection')
4
Improper Privilege Management
3
Server-Side Request Forgery (SSRF)
3
Unrestricted Upload of File with Dangerous Type
3
External Control of File Name or Path
2
Improper Authentication
1
Improper Neutralization of CRLF Sequences ('CRLF Injection')
1
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
1
Improper Neutralization of Special Elements used in a Command ('Command Injection')
1
Researchers That Contributed to WordPress Security Last Week
Researcher Name
Number of Vulnerabilities
João Pedro S Alcântara (Kinorth)
34
PRISM
18
Ananda Dhakal
14
Nguyen Ba Khanh
13
daroo
12
dodoh4t
7
Nabil Irawan
5
Bonds
5
Nguyen Dinh Hai (HaiND)
5
Phat RiO
5
Athiwat Tiprasaharn (Jitlada)
5
Chloe Chamberland
4
zaim
4
Muhammad Yudha - DJ
4
dutafi
4
Legion Hunter
4
Evan NR
4
Tran Nguyen Bao Khanh
3
Niv Kochan
3
Jakub Herman
3
0xd4rk5id3
3
Dmitrii Ignatyev
3
timomangcut
3
w41bu1
2
h0xilo
2
CHOIGYEONGMIN
2
se1en
2
Osvaldo Noe Gonzalez Del Rio (Os)
2
endy
2
javitoia
2
Kirasec
2
Rafie Muhammad
2
d.v4n_s3c
2
Denver Jackson
2
b4shu206
1
davidfdzmorilla
1
AmonRa
1
gidget smith
1
Irwan Kusuma
1
afnaan
1
Ad4m5
1
Nguyen Ngoc Duc (duc193)
1
Azril Fathoni (kiseki)
1
nightward
1
wesley (wcraft)
1
Alessandro Greco (Aleff)
1
Giovanbattista Ianni
1
Supoj Polsawas (sp0x5ec)
1
Austin Ginder
1
Jonah Burgess (CryptoCat)
1
ParkHyunWoo
1
Ivan Kuzymchak
1
VDsec
1
Webbernaut
1
theviper17y
1
Taichi Kashimura
1
she11f
1
Eason
1
Michael Perla (vizen5)
1
sterva
1
Mitchell
1
Volodymyr Kolesnykov
1
hivesec
1
tjoffe
1
MatilJ
1
Abu Hurayra (HurayraIIT)
1
jonathan dunn
1
John Umoru
1
skyv3il
1
Saad Malik
1
Ilkeggs
1
HieuPenguinnn
1
Jagadesh Achanta
1
밥김국
1
suyoung kim(AhnLab)
1
yangsori
1
sleeper
1
Sakimi
1
Tharadol Suksamran (d3kc4rt_1)
1
Matan Bahar
1
Md. Moniruzzaman Prodhan (NomanProdhan)
1
R2D2
1
Yat
1
qdtad
1
devploit
1
Averon Averenkov (Averon Averenkov)
1
VanTastic
1
Catalin Oancea (0x4D5A)
1
Saleh Elsayed (0xManticore)
1
Manopakorn Kooharueangrong (manop55555)
1
Jack Pas (Dark.)
1
Anthony Cihan (Hann1bl3L3ct3r)
1
hhhai
1
Psalms Christopher Matovu (ByteOverride)
1
g0wthr
1
lhking
1
Chirita Catalin-Andrei (CC99IE)
1
Septio Noerdiansyah
1
mickeyjoe
1
Ravindu Lakmina Munaweera
1
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name
Software Slug
Academy LMS
academy
Ad Inserter – Ad Manager & AdSense Ads
ad-inserter
Admin and Site Enhancements (ASE) Pro
admin-site-enhancements-pro
Advanced Booking & Appointment System – Webba Booking Calendar
webba-booking-lite
Advanced Contact form 7 DB
advanced-cf7-db
Advanced Shipment Tracking for WooCommerce
woo-advanced-shipment-tracking
Ajax Load More - Filters
ajax-load-more-filters
ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce
woo-alidropship
ApplyOnline – Application Form Builder and Manager
apply-online
Appointment Booking Calendar
appointment-booking-calendar
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
latepoint
Appointment Bookings for Zoom GoogleMeet and more – Wappointment
wappointment
AR for WooCommerce
ar-for-woocommerce
AR for WordPress
ar-for-wordpress
ARforms
arforms
ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup
armember
Automotive Listings
automotive
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net
woo-bulk-editor
Blocksy Companion
blocksy-companion
Blocksy Companion Pro
blocksy-companion-pro
Booked - Appointment Booking for WordPress
booked
Booking calendar, Appointment Booking System
booking-calendar
BookingPress Appointment Booking Pro
bookingpress-appointment-booking-pro
Business Directory Plugin – Easy Listing Directories for WordPress
business-directory-plugin
Classified Listing – AI-Powered Classified ads & Business Directory
classified-listing
CM Business Directory – Optimise and showcase local business
cm-business-directory
CodePeople Post Map for Google Maps
codepeople-post-map
Colissimo shipping methods for WooCommerce
colissimo-shipping-methods-for-woocommerce
Comments – wpDiscuz
wpdiscuz
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent
gdpr-cookie-consent
CrawlWP SEO – Instant Search Engine Indexing & SEO Performance Monitor
mihdan-index-now
CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x
woo-multi-currency
Custom Field Template
custom-field-template
Custom Payment Gateways for WooCommerce
custom-payment-gateways-woocommerce
cws-svgicons
cws-svgicons
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Divi Form Builder
divi-form-builder
Dokan Pro
dokan-pro
Download Manager
download-manager
eCommerce Product Catalog Plugin for WordPress
ecommerce-product-catalog
Editorial Rating – Product Review & Rating System
editorial-rating
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
email-subscribers
Embed Privacy
embed-privacy
Enable Media Replace
enable-media-replace
Envision Page Builder – A collection of WordPress Gutenberg blocks & templates
envision-page-builder
Envo's Templates & Widgets for Elementor and WooCommerce
envo-elementor-for-woocommerce
Event Organiser
event-organiser
EventON (Pro) - WordPress Virtual Event Calendar Plugin
eventON
Exclusive Addons for Elementor
exclusive-addons-for-elementor
Export User Data
export-user-data
ez Form Calculator Premium
ez-form-calculator-premium
Five Star Business Profile and Schema
business-profile
FormLayer
formlayer
FV Flowplayer Video Player
fv-wordpress-flowplayer
GD Rating System
gd-rating-system
GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content
geeky-bot
GenerateBlocks
generateblocks
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
geodirectory
GiveWP – Donation Plugin and Fundraising Platform
give
Golo Framework
golo-framework
Groundhogg — CRM, Newsletters, and Marketing Automation
groundhogg
HandL UTM Grabber / Tracker
handl-utm-grabber
Heateor Social Login WordPress
heateor-social-login
Houzez Property Feed
houzez-property-feed
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
Image Optimization – Compress Images and Convert to WebP or AVIF
image-optimization
iNET Webkit
inet-webkit
Insert Pages
insert-pages
Internal Links Manager
seo-automated-link-building
Japanized for WooCommerce
woocommerce-for-japan
JetFormBuilder — Dynamic Blocks Form Builder
jetformbuilder
JetWidgets For Elementor
jetwidgets-for-elementor
JoomSport – for Sports: Team & League, Football, Hockey & more
joomsport-sports-league-results-management
JSON API User
json-api-user
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
Kali Forms — Contact Form & Drag-and-Drop Builder
kali-forms
Kirki – Freeform Page Builder, Website Builder & Customizer
kirki
Kit (formerly ConvertKit) for WooCommerce
convertkit-for-woocommerce
Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages
page-builder-add
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
learnpress
Link Whisper Free
link-whisper
Link Whisper Premium
link-whisper-premium
MainWP Dashboard: Self-hosted WordPress Management for Agencies
mainwp
MasterStudy LMS WordPress Plugin – for Online Courses and Education
masterstudy-lms-learning-management-system
MeetingHub – Webinar & Meeting Plugin for Zoom, Google Meet, Webex, Microsoft Teams, & Jitsi Meet
meetinghub
Module PRO
modula
MoreConvert Wishlist for WooCommerce
smart-wishlist-for-more-convert
Mosaic Gallery – Advanced Gallery
mosaic-gallery-advanced-gallery
MotoPress Appointment Booking
motopress-appointment-lite
MotoPress Hotel Booking
motopress-hotel-booking-lite
Motors – Car Dealership & Classified Listings Plugin
motors-car-dealership-classified-listings
My Calendar – Accessible Event Manager
my-calendar
NewsPlus Shortcodes
newsplus-shortcodes
NEX-Forms – Ultimate Forms Plugin for WordPress
nex-forms-express-wp-form-builder
Ninja Forms - File Uploads
ninja-forms-uploads
Ninja Forms – The Contact Form Builder That Grows With You
ninja-forms
Novalnet Payment Gateway for WooCommerce
woocommerce-novalnet-gateway
NOWPayments for WooCommerce – Crypto Payment Gateway
nowpayments-for-woocommerce
OpenAI Chatbot for WordPress – Helper
helper
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization
optimole-wp
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
paid-member-subscriptions
Paid Videochat Turnkey Site – HTML5 PPV Live Webcams
ppv-live-webcams
pCloud WP Backup
pcloud-wp-backup
Perfmatters
perfmatters
Permalink Manager for WooCommerce
permalink-manager-for-woocommerce
PixMagix – WordPress Image Editor
pixmagix
Plugin for Google Analytics by IO technologies
io-engagement-analytics
POS Entegratör – Gurmehub Ödeme Eklentisi
pos-entegrator
Premium Addons for KingComposer
premium-addons-for-kingcomposer
Printcart Web to Print Product Designer for WooCommerce
printcart-integration
Private Content
private-content
Product Addons and Product Options With Custom Fields – WowAddons
product-addons
Product Video Gallery for Woocommerce
product-video-gallery-slider-for-woocommerce
ProfileGrid – User Profiles, Groups and Communities
profilegrid-user-profiles-groups-and-communities
Qi Blocks
qi-blocks
Quads Ads Manager for Google AdSense
quick-adsense-reloaded
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker
quiz-master-next
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
custom-registration-form-builder-with-submission-manager
Request a Quote – Quote Forms for Any WordPress Site
request-a-quote
Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations
fb-reviews-widget
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator
feedzy-rss-feeds
RTMKit
rometheme-for-elementor
Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization
metasync
Sendcloud Shipping
sendcloud-connected-shipping
Shopify
shopify-plugin
Shopping Cart & eCommerce Store
wp-easycart
Shortcodes and extra features for Phlox theme
auxin-elements
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization
shortpixel-adaptive-images
Simple Link Directory Pro
qc-simple-link-directory
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
simple-urls
Simple User Avatar
simple-user-avatar
Slider Revolution
revslider
Slim SEO – A Fast & Automated SEO Plugin For WordPress
slim-seo
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
sms-alert
Speaker
speaker
SportsPress Pro
sportspress-pro
Structured Content (JSON-LD) #wpsc
structured-content
Struktur Core
struktur-core
Surbma | Yoast SEO Breadcrumb Shortcode
surbma-yoast-breadcrumb-shortcode
Survey Maker by AYS
survey-maker
SysBasics Customize My Account for WooCommerce – Live My Account Customizer
customize-my-account-for-woocommerce
Taskbuilder – Project Management & Task Management Tool With Kanban Board
taskbuilder
Tax Exempt for WooCommerce
woocommerce-tax-exempt-plugin
Team Members – Multi Language Supported Team Plugin
team-showcase-supreme
TheGem Theme Elements
thegem-elements-elementor
ThumbPress – Compress Images, Manage Thumbnails, Detect Image Issues, WebP/AVIF, Lazy Loading, Hotlinking & More
image-sizes
Timetics – Appointment Booking Calendar & Scheduling System
timetics
TinyPNG – JPEG, PNG & WebP image compression
tiny-compress-images
Tour Master - Tour Booking, Travel, Hotel
tourmaster
Tutor LMS – eLearning and online course solution
tutor
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
ultimate-member
Universal Clocks
universal-clocks
User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration
wp-user-frontend
Video Gallery – YouTube Gallery, Playlist & Video Grid
youtube-showcase
VikBooking Hotel Booking Engine & PMS
vikbooking
Visualizer – Tables & Charts Manager with Built-in AI Generator
visualizer
W3 Total Cache
w3-total-cache
Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments
wallet-system-for-woocommerce
Webmention
webmention
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot
wedocs
WooCommerce Designer Pro
wc-designer-pro
Woostify Sites Library
woostify-sites-library
WP Database Backup – Unlimited Database & Files Backup by Backup for WP
wp-database-backup
WP Debugging
wp-debugging
WP Fast Total Search – The Power of Indexed Search
fulltext-search
WP Google Review Slider
wp-google-places-review-slider
WP Import Export Lite
wp-import-export-lite
WP Inventory Manager
wp-inventory-manager
WP Photo Album Plus
wp-photo-album-plus
WP Review Slider Pro
wp-review-slider-pro
WP-BusinessDirectory – Business directory plugin for WordPress
wp-businessdirectory
WPAdverts – Classifieds Plugin
wpadverts
WPBakery Page Builder Addons by Livemesh
addons-for-visual-composer
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services
chatbot
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin
wpdatatables
WPeMatico RSS Feed Fetcher
wpematico
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More
wpforms-lite
WPIDE – File Manager & Code Editor
wpide
WordPress Themes with Reported Vulnerabilities Last Week
Software Name
Software Slug
Aalto - Architecture and Interior Design WordPress Theme
aalto
aqua
aqua
Artale | Wedding Photography WordPress
artale
Audrey - Fashion WordPress Theme
audrey
Automotive Car Dealership Business WordPress Theme
automotive
Billey - Creative Portfolio & Agency Elementor WordPress Theme
billey
Brook - Agency Business Creative WordPress Theme
brook
Corpkit - Business Consulting WordPress Theme
corpkit
Dør - Modern Architecture and Interior Design Theme
dor
EduMall - Professional LMS Education Center WordPress Theme
edumall
Fascinate
fascinate
Fitness Zone WordPress Theme
fitnesszone
Flatsome
flatsome
Flow
flow
Kids Life | Children School WordPress
kidslife
Kids Zone - Children WordPress Theme
kidszone
Kitchor - Interior Design WordPress Theme
kitchor
Leedo – Modern, Colorful & Creative Portfolio WordPress Theme
leedo
Lighthouse | School for Kids with Disabilities & Special Needs WordPress Theme
lighthouseschool
LMS - Education WordPress Theme
lms
Martfury - Marketplace Mobile App Figma Template
martfury
Motors - Car Dealer, Rental & Listing WordPress theme
motors
NativeChurch
NativeChurch
Nuss - Hotel Booking WordPress
nuss
Overworld - eSports and Gaming WordPress Theme
overworld
pearl
pearl
Real Estate 7 WordPress
realestate-7
SetSail - Travel Agency WordPress Theme
setsail
SpaLab | Beauty Salon WordPress Theme
spalab
Struktur - Creative Agency WordPress Theme
struktur
TheFox | Responsive Multi-Purpose WordPress Theme
thefox
Tonda - Elegant Shop WordPress Theme
tonda
Trendy Travel WordPress
trendytravel
unicamp
unicamp
VW Food Corner
vw-food-corner
VW Wedding
vw-wedding
Werkstatt - Creative Portfolio WordPress Theme
werkstatt
Woffice CRM
woffice
Zakra
zakra
Zegen - Church WordPress Theme
zegen
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Blocksy Companion <= 2.1.46 - Unauthenticated Arbitrary File Upload via 'blc-review-images[]' Parameter
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-15158
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Blocksy Companion [blocksy-companion]
Researcher
Nguyen Ba Khanh
More Details >
Blocksy Companion Pro <= 2.1.46 - Unauthenticated Remote Code Execution
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-57624
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Blocksy Companion Pro [blocksy-companion-pro]
Researcher
Nguyen Ba Khanh
More Details >
Divi Form Builder <= 5.1.8 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-5524
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Divi Form Builder [divi-form-builder]
Researcher
0xd4rk5id3
More Details >
EventON - WordPress Virtual Event Calendar Plugin <= 5.0.11 - Unauthenticated Blind SQL Injection via Search Parameter
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-9711
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
EventON (Pro) - WordPress Virtual Event Calendar Plugin [eventON]
Researcher
Nguyen Ngoc Duc (duc193)
More Details >
Private Content <= 9.9.2 - Unauthenticated Privilege Escalation
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-57692
Patch Status
Unpatched
Published
Jul 1, 2026
Affected Software
Private Content [private-content]
Researcher
0xd4rk5id3
More Details >
ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthenticated Privilege Escalation via Email Overwrite
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-12073
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities]
Researcher
Ivan Kuzymchak
More Details >
SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
9.8
CVSS Rating
9.8 (Critical)
CVE-ID
CVE-2026-11387
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery [sms-alert]
Researchers
Chloe ChamberlandPRISM
More Details >
Printcart Web to Print Product Designer for WooCommerce <= 2.5.2 - Unauthenticated Arbitrary File Deletion
9.1
CVSS Rating
9.1 (Critical)
CVE-ID
CVE-2026-9725
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
Printcart Web to Print Product Designer for WooCommerce [printcart-integration]
Researcher
tjoffe
More Details >
WP-BusinessDirectory <= 4.0.1 - Unauthenticated Arbitrary File Deletion via Path Traversal via '_filename' Parameter
9.1
CVSS Rating
9.1 (Critical)
CVE-ID
CVE-2026-6070
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
WP-BusinessDirectory – Business directory plugin for WordPress [wp-businessdirectory]
Researcher
Nabil Irawan
More Details >
Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-12224
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Dokan Pro [dokan-pro]
Researcher
0xd4rk5id3
More Details >
LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-13228
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint]
Researcher
d.v4n_s3c
More Details >
RegistrationMagic <= 6.0.9.1 - Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-12158
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login [custom-registration-form-builder-with-submission-manager]
Researchers
Chloe ChamberlandPRISM
More Details >
Zegen - Church WordPress Theme <= 1.1.9 - Authenticated (Subscriber+) Arbitrary File Upload
8.8
CVSS Rating
8.8 (High)
CVE-ID
CVE-2026-27419
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
Zegen - Church WordPress Theme [zegen]
Researcher
Tran Nguyen Bao Khanh
More Details >
Audrey <= 1.5 - Unauthenticated Local File Inclusion
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-42382
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
Audrey - Fashion WordPress Theme [audrey]
Researcher
Tran Nguyen Bao Khanh
More Details >
Embed Privacy <= 1.12.3 - Authenticated (Contributor+) Arbitrary File Deletion
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-57346
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Embed Privacy [embed-privacy]
Researcher
daroo
More Details >
Image Optimizer <= 1.7.4 - Authenticated (Author+) Arbitrary File Deletion via Post Meta Field Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-5821
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Image Optimization – Compress Images and Convert to WebP or AVIF [image-optimization]
Researcher
Dmitrii Ignatyev
More Details >
Lighthouse <= 1.2.12 - Unauthenticated Local File Inclusion
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2025-58902
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
Lighthouse | School for Kids with Disabilities & Special Needs WordPress Theme [lighthouseschool]
Researcher
Tran Nguyen Bao Khanh
More Details >
Novalnet Payment Gateway for WooCommerce <= 12.10.3 - Unauthenticated PHP Object Injection
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-57677
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Novalnet Payment Gateway for WooCommerce [woocommerce-novalnet-gateway]
Researcher
qdtad
More Details >
Paid Videochat Turnkey Site – HTML5 PPV Live Webcams <= 7.4.8 - Authenticated (Performer+) Arbitrary File Deletion
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-57331
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Paid Videochat Turnkey Site – HTML5 PPV Live Webcams [ppv-live-webcams]
Researcher
endy
More Details >
Pearl - Corporate Business <= 3.4.10 - Unauthenticated Local File Inclusion
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-27412
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
pearl [pearl]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
TinyPNG <= 3.6.13 - Authenticated (Author+) Arbitrary File Deletion via 'convert.path' in 'tiny_compress_images' Post Meta
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-7311
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
TinyPNG – JPEG, PNG & WebP image compression [tiny-compress-images]
Researcher
lhking
More Details >
W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary Code Execution
8.1
CVSS Rating
8.1 (High)
CVE-ID
CVE-2026-57623
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
W3 Total Cache [w3-total-cache]
Researcher
Ananda Dhakal
More Details >
Export User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion via display_name Field
8.0
CVSS Rating
8.0 (High)
CVE-ID
CVE-2026-12240
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
Export User Data [export-user-data]
Researcher
Webbernaut
More Details >
Aalto <= 1.8 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57788
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Aalto - Architecture and Interior Design WordPress Theme [aalto]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Aqua <= 5.1.2 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57789
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
aqua [aqua]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
AR for WooCommerce <= 8.40 - Unauthenticated Path Traversal to Arbitrary File Read via 'file' Parameter
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-14352
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
AR for WooCommerce [ar-for-woocommerce]
Researcher
CHOIGYEONGMIN
More Details >
AR for WordPress <= 8.40 - Unauthenticated Arbitrary File Read via 'file' Parameter
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-14327
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
AR for WordPress [ar-for-wordpress]
Researcher
CHOIGYEONGMIN
More Details >
ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup <= 7.0 - Authenticated (Contributor+) PHP Object Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-27060
Patch Status
Unpatched
Published
Jun 30, 2026
Affected Software
ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup [armember]
Researcher
Phat RiO
More Details >
Billey <= 2.1.8 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57790
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Billey - Creative Portfolio & Agency Elementor WordPress Theme [billey]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
BookingPress Appointment Booking Pro <= 5.7.1 - Unauthenticated SQL Injection via 'store_service_date' Parameter
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-11823
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
BookingPress Appointment Booking Pro [bookingpress-appointment-booking-pro]
Researcher
h0xilo
More Details >
Brook - Agency Business Creative WordPress Theme <= 2.9.0 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57791
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Brook - Agency Business Creative WordPress Theme [brook]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Dør - Modern Architecture and Interior Design Theme <= 2.4.1 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57792
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Dør - Modern Architecture and Interior Design Theme [dor]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Flow <= 1.8 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57793
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Flow [flow]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content <= 1.2.5 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57679
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content [geeky-bot]
Researcher
daroo
More Details >
Golo Framework <= 1.7.3 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57794
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Golo Framework [golo-framework]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Kitchor <= 1.4.3 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57795
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Kitchor - Interior Design WordPress Theme [kitchor]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Leedo <= 3.0.0 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57796
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Leedo – Modern, Colorful & Creative Portfolio WordPress Theme [leedo]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
NewsPlus Shortcodes <= 4.2.0 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57798
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
NewsPlus Shortcodes [newsplus-shortcodes]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Ninja Forms - File Uploads <= 3.3.29 - Unauthenticated Arbitrary File Read via File Upload Field 'files[].data.file_path' Parameter
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-13369
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Ninja Forms - File Uploads [ninja-forms-uploads]
Researcher
daroo
More Details >
Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-1239
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms]
Researcher
suyoung kim(AhnLab)
More Details >
Nuss - Hotel Booking WordPress <= 1.3.6 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57799
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Nuss - Hotel Booking WordPress [nuss]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Overworld - eSports and Gaming WordPress Theme <= 1.5 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57800
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Overworld - eSports and Gaming WordPress Theme [overworld]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Perfmatters <= 2.6.4 - Unauthenticated Arbitrary File Read via 's' Parameter
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-13251
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Perfmatters [perfmatters]
Researcher
daroo
More Details >
Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'path' Parameter
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-14249
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Request a Quote – Quote Forms for Any WordPress Site [request-a-quote]
Researcher
Mitchell
More Details >
SetSail - Travel Agency WordPress Theme <= 2.1 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57801
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
SetSail - Travel Agency WordPress Theme [setsail]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Shopify <= 1.0.0 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57748
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Shopify [shopify-plugin]
Researcher
Rafie Muhammad
More Details >
SportsPress Pro <= 2.7.29 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57749
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
SportsPress Pro [sportspress-pro]
Researcher
w41bu1
More Details >
Struktur - Creative Agency WordPress Theme <= 2.5.1 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57802
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Struktur - Creative Agency WordPress Theme [struktur]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Struktur Core <= 2.5.1 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57803
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Struktur Core [struktur-core]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
TheGem Theme Elements <= 5.11.1 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57804
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
TheGem Theme Elements [thegem-elements-elementor]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Tonda <= 2.5 - Authenticated (Contributor+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57805
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Tonda - Elegant Shop WordPress Theme [tonda]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Tour Master - Tour Booking, Travel, Hotel <= 5.4.5 - Authenticated (Subscriber+) Local File Inclusion
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2025-69133
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
Tour Master - Tour Booking, Travel, Hotel [tourmaster]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Video Gallery <= 4.0.3 - Authenticated (Subscriber+) Arbitrary Function Call via 'path' Parameter
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-12923
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Video Gallery – YouTube Gallery, Playlist & Video Grid [youtube-showcase]
Researcher
PRISM
More Details >
Visualizer <= 4.0.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via /visualizer/v1/action/{chart}/{type}/ REST Endpoint
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-13468
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Visualizer – Tables & Charts Manager with Built-in AI Generator [visualizer]
Researcher
Niv Kochan
More Details >
Werkstatt - Creative Portfolio WordPress Theme <= 4.8.3 - Authenticated (Contributor+) PHP Object Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-27414
Patch Status
Unpatched
Published
Jun 30, 2026
Affected Software
Werkstatt - Creative Portfolio WordPress Theme [werkstatt]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
WP Fast Total Search – The Power of Indexed Search <= 1.80.280 - Unauthenticated SQL Injection
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-57683
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
WP Fast Total Search – The Power of Indexed Search [fulltext-search]
Researcher
Nguyen Dinh Hai (HaiND)
More Details >
WP Review Slider Pro <= 12.7.2 - Unauthenticated SQL Injection via 'notinstring' Parameter
7.5
CVSS Rating
7.5 (High)
CVE-ID
CVE-2026-8441
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
WP Review Slider Pro [wp-review-slider-pro]
Researcher
h0xilo
More Details >
Admin and Site Enhancements (ASE) Pro <= 8.8.5 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57625
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Admin and Site Enhancements (ASE) Pro [admin-site-enhancements-pro]
Researcher
Nguyen Ba Khanh
More Details >
Ajax Load More - Filters <= 3.4.1 - Unauthenticated Stored Cross-Site Scripting via 'taxonomy_include_children' Field
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-8141
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Ajax Load More - Filters [ajax-load-more-filters]
Researcher
jonathan dunn
More Details >
Artale | Wedding Photography WordPress <= 2.2.2 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2025-69152
Patch Status
Unpatched
Published
Jun 30, 2026
Affected Software
Artale | Wedding Photography WordPress [artale]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.8 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57320
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor]
Researcher
Bonds
More Details >
Business Directory Plugin – Easy Listing Directories for WordPress <= 6.4.22 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57326
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Business Directory Plugin – Easy Listing Directories for WordPress [business-directory-plugin]
Researcher
Saleh Elsayed (0xManticore)
More Details >
Classified Listing – AI-Powered Classified ads & Business Directory <= 5.4.2 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57344
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Classified Listing – AI-Powered Classified ads & Business Directory [classified-listing]
Researcher
daroo
More Details >
CodePeople Post Map for Google Maps <= 1.2.5 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57670
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
CodePeople Post Map for Google Maps [codepeople-post-map]
Researcher
dutafi
More Details >
Comments <= 7.6.56 - Unauthenticated Stored Cross-Site Scripting via 'Website' Field
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-9148
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
Comments – wpDiscuz [wpdiscuz]
Researcher
mickeyjoe
More Details >
Custom Payment Gateways for WooCommerce <= 2.1.0 - Unauthenticated Stored Cross-Site Scripting via 'alg_wc_cpg_input_fields' Parameter
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-7517
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Custom Payment Gateways for WooCommerce [custom-payment-gateways-woocommerce]
Researcher
Azril Fathoni (kiseki)
More Details >
eCommerce Product Catalog Plugin for WordPress <= 3.5.4 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57360
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
eCommerce Product Catalog Plugin for WordPress [ecommerce-product-catalog]
Researcher
Jakub Herman
More Details >
Fitness Zone WordPress <= 5.7 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2025-69155
Patch Status
Unpatched
Published
Jun 30, 2026
Affected Software
Fitness Zone WordPress Theme [fitnesszone]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Five Star Business Profile and Schema <= 2.3.19 - Authenticated (Editor+) Arbitrary Code Execution
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-27436
Patch Status
Unpatched
Published
Jun 30, 2026
Affected Software
Five Star Business Profile and Schema [business-profile]
Researcher
daroo
More Details >
HandL UTM Grabber / Tracker <= 2.9.2 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57351
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
HandL UTM Grabber / Tracker [handl-utm-grabber]
Researcher
Ananda Dhakal
More Details >
Internal Links Manager <= 3.0.3 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57345
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Internal Links Manager [seo-automated-link-building]
Researcher
dodoh4t
More Details >
Kids Life | Children School WordPress <= 5.2 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-27402
Patch Status
Unpatched
Published
Jun 30, 2026
Affected Software
Kids Life | Children School WordPress [kidslife]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Kids Zone - Children WordPress <= 5.4 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2025-69156
Patch Status
Unpatched
Published
Jun 30, 2026
Affected Software
Kids Zone - Children WordPress Theme [kidszone]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages <= 1.5.3.5 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57337
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages [page-builder-add]
Researcher
Nguyen Dinh Hai (HaiND)
More Details >
Modula - PRO <= 2.10.8 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57426
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Module PRO [modula]
Researcher
Nguyen Ba Khanh
More Details >
MoreConvert Wishlist for WooCommerce <= 1.9.19 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57356
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
MoreConvert Wishlist for WooCommerce [smart-wishlist-for-more-convert]
Researcher
Manopakorn Kooharueangrong (manop55555)
More Details >
NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-12142
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
NEX-Forms – Ultimate Forms Plugin for WordPress [nex-forms-express-wp-form-builder]
Researcher
Anthony Cihan (Hann1bl3L3ct3r)
More Details >
NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameter
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-13040
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
NEX-Forms – Ultimate Forms Plugin for WordPress [nex-forms-express-wp-form-builder]
Researcher
Taichi Kashimura
More Details >
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.7 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57673
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization [optimole-wp]
Researcher
daroo
More Details >
Perfmatters <= 2.6.4 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57671
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Perfmatters [perfmatters]
Researcher
daroo
More Details >
Product Addons and Product Options With Custom Fields – WowAddons <= 1.6.14 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57686
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Product Addons and Product Options With Custom Fields – WowAddons [product-addons]
Researcher
Nguyen Ba Khanh
More Details >
Real Estate 7 WordPress <= 3.5.9 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57343
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Real Estate 7 WordPress [realestate-7]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema <= 2.3.10 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57359
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema [reviewx]
Researcher
Psalms Christopher Matovu (ByteOverride)
More Details >
Simple Link Directory Pro <= 15.0.5 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57682
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Simple Link Directory Pro [qc-simple-link-directory]
Researcher
dutafi
More Details >
Slider Revolution 7.0.0-7.0.16 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57678
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Slider Revolution [revslider]
Researcher
daroo
More Details >
SpaLab | Beauty Salon WordPress <= 6.7 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2025-69154
Patch Status
Unpatched
Published
Jun 30, 2026
Affected Software
SpaLab | Beauty Salon WordPress Theme [spalab]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Survey Maker by AYS <= 5.2.2.5 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57361
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Survey Maker by AYS [survey-maker]
Researcher
Nguyen Ba Khanh
More Details >
Timetics – Appointment Booking Calendar & Scheduling System <= 1.0.58 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57674
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Timetics – Appointment Booking Calendar & Scheduling System [timetics]
Researcher
daroo
More Details >
Webmention <= 5.8.0 - Unauthenticated Stored Cross-Site Scripting via MF2 'photo'/'url' Author Properties
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-10513
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Webmention [webmention]
Researcher
Volodymyr Kolesnykov
More Details >
WP Database Backup <= 7.11 - Authenticated (Administrator+) OS Command Injection via 'wp_db_exclude_table' Parameter
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-9834
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
WP Database Backup – Unlimited Database & Files Backup by Backup for WP [wp-database-backup]
Researcher
Irwan Kusuma
More Details >
WP Debugging <= 2.12.2 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57350
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
WP Debugging [wp-debugging]
Researcher
Ananda Dhakal
More Details >
WP Photo Album Plus <= 9.2.02.004 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57675
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
WP Photo Album Plus [wp-photo-album-plus]
Researcher
Nguyen Ba Khanh
More Details >
WPAdverts – Classifieds Plugin <= 2.3.1 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57366
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
WPAdverts – Classifieds Plugin [wpadverts]
Researcher
Evan NR
More Details >
WPBot <= 8.4.9 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-13731
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services [chatbot]
Researcher
PRISM
More Details >
wpDataTables (Premium) <= 6.5.1.1 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57672
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables]
Researcher
Nguyen Ba Khanh
More Details >
WPeMatico RSS Feed Fetcher <= 2.8.17 - Unauthenticated Stored Cross-Site Scripting
7.2
CVSS Rating
7.2 (High)
CVE-ID
CVE-2026-57349
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
WPeMatico RSS Feed Fetcher [wpematico]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Corpkit - Business Consulting WordPress Theme <= 1.0.5 - Authenticated (Subscriber+) Sensitive Information Exopsure
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2025-69132
Patch Status
Unpatched
Published
Jun 30, 2026
Affected Software
Corpkit - Business Consulting WordPress Theme [corpkit]
Researcher
Bonds
More Details >
Custom Field Template <= 2.7.8 - Authenticated (Contributor+) SQL Injection
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-57687
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Custom Field Template [custom-field-template]
Researcher
daroo
More Details >
CWS SVGicons <= 1.5.5 - Authenticated (Contributor+) SQL Injection
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-57787
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
cws-svgicons [cws-svgicons]
Researcher
Phat RiO
More Details >
Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value'
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-9145
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries]
Researcher
Jonah Burgess (CryptoCat)
More Details >
GD Rating System <= 3.7 - Authenticated (Contributor+) SQL Injection
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-57771
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
GD Rating System [gd-rating-system]
Researcher
VanTastic
More Details >
Groundhogg <= 4.5.8 - Authenticated (Custom+) SQL Injection via 'select' Parameter
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-14029
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Groundhogg — CRM, Newsletters, and Marketing Automation [groundhogg]
Researcher
PRISM
More Details >
iNET Webkit 1.2.4 - Authenticated (Contributor+) SQL Injection
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-57752
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
iNET Webkit [inet-webkit]
Researcher
Evan NR
More Details >
LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'userId' Parameter
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-11988
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses [learnpress]
Researcher
javitoia
More Details >
MotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection via 's' Parameter
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-13454
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
MotoPress Appointment Booking [motopress-appointment-lite]
Researcher
MatilJ
More Details >
PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' Parameter
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-11367
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
PixMagix – WordPress Image Editor [pixmagix]
Researcher
devploit
More Details >
Shopping Cart & eCommerce Store <= 5.9.1 - Authenticated (Contributor+) SQL Injection
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-57765
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Shopping Cart & eCommerce Store [wp-easycart]
Researcher
Nguyen Dinh Hai (HaiND)
More Details >
Taskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'task_search' Parameter
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-12110
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Taskbuilder – Project Management & Task Management Tool With Kanban Board [taskbuilder]
Researcher
d.v4n_s3c
More Details >
Taskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'wppm_proj_filter' Parameter
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-12090
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Taskbuilder – Project Management & Task Management Tool With Kanban Board [taskbuilder]
Researcher
Catalin Oancea (0x4D5A)
More Details >
Unicamp - University and College WordPress Theme <= 2.2.2 - Authenticated (Subscriber+) SQL Injection
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2025-69094
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
unicamp [unicamp]
Researcher
Bonds
More Details >
WP Inventory Manager <= 2.4.0 - Authenticated (Contributor+) SQL Injection
6.5
CVSS Rating
6.5 (Medium)
CVE-ID
CVE-2026-57772
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
WP Inventory Manager [wp-inventory-manager]
Researcher
dodoh4t
More Details >
Business Directory Plugin – Easy Listing Directories for WordPress <= 6.4.22 - Authenticated (Subscriber+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-57328
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Business Directory Plugin – Easy Listing Directories for WordPress [business-directory-plugin]
Researcher
she11f
More Details >
CM Business Directory <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Business Address Meta Fields
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-8892
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
CM Business Directory – Optimise and showcase local business [cm-business-directory]
Researcher
Muhammad Yudha - DJ
More Details >
Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-13733
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Download Manager [download-manager]
Researcher
PRISM
More Details >
Envision Page Builder – A collection of WordPress Gutenberg blocks & templates <= 0.22 - Authenticated (Contributor+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-57780
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Envision Page Builder – A collection of WordPress Gutenberg blocks & templates [envision-page-builder]
Researcher
Athiwat Tiprasaharn (Jitlada)
More Details >
Event Organiser <= 3.12.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via eo_events Shortcode
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-2387
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Event Organiser [event-organiser]
Researcher
Muhammad Yudha - DJ
More Details >
FV Flowplayer Video Player <= 7.5.51.7212 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'video_player' Shortcode
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-12135
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
FV Flowplayer Video Player [fv-wordpress-flowplayer]
Researcher
Muhammad Yudha - DJ
More Details >
GenerateBlocks <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-9756
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
GenerateBlocks [generateblocks]
Researcher
Kirasec
More Details >
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.161 - Authenticated (Subscriber+) Server-Side Request Forgery
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-57681
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory [geodirectory]
Researcher
dodoh4t
More Details >
GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-13246
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
GiveWP – Donation Plugin and Fundraising Platform [give]
Researcher
AmonRa
More Details >
GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-13704
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
GiveWP – Donation Plugin and Fundraising Platform [give]
Researcher
Chirita Catalin-Andrei (CC99IE)
More Details >
Insert Pages <= 3.11.4 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Field Keys (Meta Key Names)
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-10089
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Insert Pages [insert-pages]
Researcher
Athiwat Tiprasaharn (Jitlada)
More Details >
JetWidgets For Elementor <= 1.0.21 - Authenticated (Author+) Stored Cross-Site Scripting via Animated Box 'animation_effect' Setting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-11380
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
JetWidgets For Elementor [jetwidgets-for-elementor]
Researcher
Athiwat Tiprasaharn (Jitlada)
More Details >
JSON API User <= 4.1.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'content' Parameter
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-9626
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
JSON API User [json-api-user]
Researcher
Yat
More Details >
Kali Forms <= 2.4.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'kaliforms_field_components' Parameter
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-9107
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Kali Forms — Contact Form & Drag-and-Drop Builder [kali-forms]
Researcher
Osvaldo Noe Gonzalez Del Rio (Os)
More Details >
LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-12732
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses [learnpress]
Researchers
zaimPRISM
More Details >
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.27 - Authenticated (Subscriber+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-57330
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system]
Researcher
endy
More Details >
Mosaic Gallery – Advanced Gallery <= 1.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-57755
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Mosaic Gallery – Advanced Gallery [mosaic-gallery-advanced-gallery]
Researcher
zaim
More Details >
Reviews Widgets for Google, Yelp & TripAdvisor <= 2.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'page_id' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-12154
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations [fb-reviews-widget]
Researcher
Ilkeggs
More Details >
RSS Aggregator by Feedzy <= 5.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aspectRatio' Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-13252
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds]
Researcher
PRISM
More Details >
RTMKit <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Heading Widget 'Background Text' Parameter
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-8351
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
RTMKit [rometheme-for-elementor]
Researcher
theviper17y
More Details >
Shortcodes and extra features for Phlox theme <= 2.17.21 - Authenticated (Contributor+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-57737
Patch Status
Unpatched
Published
Jul 1, 2026
Affected Software
Shortcodes and extra features for Phlox theme [auxin-elements]
Researcher
timomangcut
More Details >
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization <= 3.11.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-57342
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images]
Researcher
dodoh4t
More Details >
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management <= 151 - Authenticated (Author+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-57762
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management [simple-urls]
Researcher
Athiwat Tiprasaharn (Jitlada)
More Details >
Speaker <= 4.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-57783
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Speaker [speaker]
Researcher
w41bu1
More Details >
Structured Content (JSON-LD) #wpsc <= 1.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-57763
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Structured Content (JSON-LD) #wpsc [structured-content]
Researcher
zaim
More Details >
Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-57764
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Surbma | Yoast SEO Breadcrumb Shortcode [surbma-yoast-breadcrumb-shortcode]
Researcher
zaim
More Details >
TheFox <= 3.9.70 - Authenticated (Contributor+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-57684
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
TheFox | Responsive Multi-Purpose WordPress Theme [thefox]
Researcher
Ananda Dhakal
More Details >
Tutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment Title
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-13443
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Tutor LMS – eLearning and online course solution [tutor]
Researcher
skyv3il
More Details >
Ultimate Member <= 2.11.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Non-HTML Custom Textarea Profile Field
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-8489
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member]
Researcher
daroo
More Details >
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'connectorWidth' Block Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-12734
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot [wedocs]
Researcher
PRISM
More Details >
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-12731
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot [wedocs]
Researcher
PRISM
More Details >
WooCommerce Designer Pro <= 1.9.34 - Authenticated (Subscriber+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-57329
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
WooCommerce Designer Pro [wc-designer-pro]
Researcher
Nguyen Ba Khanh
More Details >
WP Photo Album Plus <= 9.1.13.005 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'subtext' Shortcode Attribute
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-10095
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
WP Photo Album Plus [wp-photo-album-plus]
Researcher
Muhammad Yudha - DJ
More Details >
WPBakery Page Builder Addons by Livemesh <= 3.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-57754
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
WPBakery Page Builder Addons by Livemesh [addons-for-visual-composer]
Researcher
timomangcut
More Details >
Zakra <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta REST API
6.4
CVSS Rating
6.4 (Medium)
CVE-ID
CVE-2026-4804
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
Zakra [zakra]
Researcher
Osvaldo Noe Gonzalez Del Rio (Os)
More Details >
ARforms <= 7.1.2 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-57338
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
ARforms [arforms]
Researcher
dutafi
More Details >
Automotive Car Dealership Business WordPress Theme <= 13.3.3 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-27426
Patch Status
Unpatched
Published
Jun 30, 2026
Affected Software
Automotive Car Dealership Business WordPress Theme [automotive]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Automotive Listings <= 18.6 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-27425
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
Automotive Listings [automotive]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Link Whisper Free <= 0.9.4 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-57333
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Link Whisper Free [link-whisper]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
LMS <= 9.7 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-27404
Patch Status
Unpatched
Published
Jun 30, 2026
Affected Software
LMS - Education WordPress Theme [lms]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
NativeChurch <= 4.8.8.2 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-27408
Patch Status
Unpatched
Published
Jun 30, 2026
Affected Software
NativeChurch [NativeChurch]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 3.0.4 - Unauthenticated Server-Side Request Forgery
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-57348
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction [paid-member-subscriptions]
Researcher
yangsori
More Details >
Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization <= 2.6.6 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-57357
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization [metasync]
Researcher
Evan NR
More Details >
SysBasics Customize My Account for WooCommerce – Live My Account Customizer <= 4.3.9 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-57358
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
SysBasics Customize My Account for WooCommerce – Live My Account Customizer [customize-my-account-for-woocommerce]
Researcher
dutafi
More Details >
Trendy Travel <= 6.7 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2025-69153
Patch Status
Unpatched
Published
Jun 30, 2026
Affected Software
Trendy Travel WordPress [trendytravel]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
VikBooking Hotel Booking Engine & PMS <= 1.8.12 - Reflected Cross-Site Scripting via 'layoutstyle' Parameter
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-12754
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
VikBooking Hotel Booking Engine & PMS [vikbooking]
Researcher
PRISM
More Details >
WP Google Review Slider <= 18.1 - Reflected Cross-Site Scripting via 'place' Parameter
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-13015
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
WP Google Review Slider [wp-google-places-review-slider]
Researcher
PRISM
More Details >
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 8.3.2 - Reflected Cross-Site Scripting
6.1
CVSS Rating
6.1 (Medium)
CVE-ID
CVE-2026-57362
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services [chatbot]
Researcher
Nguyen Dinh Hai (HaiND)
More Details >
WP Import Export Lite <= 3.9.30 - Authenticated (Administrator+) Server-Side Request Forgery via 'file_url' Parameter
5.5
CVSS Rating
5.5 (Medium)
CVE-ID
CVE-2026-11397
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
WP Import Export Lite [wp-import-export-lite]
Researcher
밥김국
More Details >
CURCY <= 2.2.14 - Unauthenticated Arbitrary Shortcode Execution via 'exchange' Parameter
5.4
CVSS Rating
5.4 (Medium)
CVE-ID
CVE-2026-11778
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x [woo-multi-currency]
Researcher
sterva
More Details >
Academy LMS <= 3.8.1 - Unauthenticated Insecure Direct Object Reference to Private Topic Disclosure
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-5348
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Academy LMS [academy]
Researcher
Md. Moniruzzaman Prodhan (NomanProdhan)
More Details >
Advanced Booking & Appointment System – Webba Booking Calendar <= 6.4.13 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-27409
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Advanced Booking & Appointment System – Webba Booking Calendar [webba-booking-lite]
Researcher
Legion Hunter
More Details >
ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-57352
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce [woo-alidropship]
Researcher
Ananda Dhakal
More Details >
ApplyOnline – Application Form Builder and Manager <= 2.6.7.6 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-57721
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
ApplyOnline – Application Form Builder and Manager [apply-online]
Researcher
Jakub Herman
More Details >
Appointment Bookings for Zoom GoogleMeet and more – Wappointment <= 2.7.6 - Unauthenticated Insecure Direct Object Reference via Predictable 'edit_key' / 'appointmentkey' Parameter
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-9188
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Appointment Bookings for Zoom GoogleMeet and more – Wappointment [wappointment]
Researcher
davidfdzmorilla
More Details >
Booking calendar, Appointment Booking System <= 3.2.36 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-57778
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Booking calendar, Appointment Booking System [booking-calendar]
Researcher
Nabil Irawan
More Details >
Business Directory Plugin – Easy Listing Directories for WordPress <= 6.4.23 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-57339
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Business Directory Plugin – Easy Listing Directories for WordPress [business-directory-plugin]
Researcher
John Umoru
More Details >
Colissimo shipping methods for WooCommerce <= 2.9.0 - Unauthenticated Insecure Direct Object Reference
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-57341
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Colissimo shipping methods for WooCommerce [colissimo-shipping-methods-for-woocommerce]
Researcher
HieuPenguinnn
More Details >
Exclusive Addons for Elementor <= 2.7.9.9 - Unauthenticated Information Exposure
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-59511
Patch Status
Patched
Published
Jul 5, 2026
Affected Software
Exclusive Addons for Elementor [exclusive-addons-for-elementor]
Researcher
Ananda Dhakal
More Details >
ez Form Calculator Premium <= 2.14.1.2 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-57750
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
ez Form Calculator Premium [ez-form-calculator-premium]
Researcher
Phat RiO
More Details >
Fascinate <= 1.1.5 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-57779
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Fascinate [fascinate]
Researcher
Legion Hunter
More Details >
FormLayer <= 1.0.6 - Unauthenticated Information Exposure
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-59519
Patch Status
Patched
Published
Jul 5, 2026
Affected Software
FormLayer [formlayer]
Researcher
Ananda Dhakal
More Details >
Japanized for WooCommerce <= 2.9.12 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-57340
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Japanized for WooCommerce [woocommerce-for-japan]
Researcher
Nguyen Dinh Hai (HaiND)
More Details >
JetFormBuilder <= 3.6.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'context' Parameter
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-13459
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder]
Researcher
Niv Kochan
More Details >
Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Arbitrary Email Content Injection (Mail Relay / Phishing) via 'emailBody' and 'emailSubject' Parameters
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-12472
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Kirki – Freeform Page Builder, Website Builder & Customizer [kirki]
Researchers
Niv KochanMatan Bahar
More Details >
Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX Action
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-12122
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Kirki – Freeform Page Builder, Website Builder & Customizer [kirki]
Researcher
Jagadesh Achanta
More Details >
Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 - Unauthenticated Information Exposure
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-57753
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Kit (formerly ConvertKit) for WooCommerce [convertkit-for-woocommerce]
Researcher
Nguyen Ba Khanh
More Details >
LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-11398
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint]
Researcher
hhhai
More Details >
LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-12657
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint]
Researcher
gidget smith
More Details >
MeetingHub – Webinar & Meeting Plugin for Zoom, Google Meet, Webex, Microsoft Teams, & Jitsi Meet <= 1.25.10 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-57781
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
MeetingHub – Webinar & Meeting Plugin for Zoom, Google Meet, Webex, Microsoft Teams, & Jitsi Meet [meetinghub]
Researcher
Nabil Irawan
More Details >
MotoPress Appointment Booking <= 2.4.4 - Unauthenticated Insecure Direct Object Reference to 'payment_details.booking_id' Parameter
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-9180
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
MotoPress Appointment Booking [motopress-appointment-lite]
Researcher
g0wthr
More Details >
Motors - Car Dealer, Rental & Listing WordPress theme <= 5.6.80 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-27433
Patch Status
Unpatched
Published
Jun 30, 2026
Affected Software
Motors - Car Dealer, Rental & Listing WordPress theme [motors]
Researcher
Rafie Muhammad
More Details >
My Calendar <= 3.7.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'vcal' Parameter
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-11896
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
My Calendar – Accessible Event Manager [my-calendar]
Researchers
Athiwat Tiprasaharn (Jitlada)Tharadol Suksamran (d3kc4rt_1)
More Details >
Ninja Forms - File Uploads <= 3.3.29 - Missing Authorization to Unauthenticated Log Disclosure and Deletion via debug-log/delete-all and debug-log/get-all REST Endpoints
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-12557
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
Ninja Forms - File Uploads [ninja-forms-uploads]
Researcher
Ad4m5
More Details >
NOWPayments for WooCommerce – Crypto Payment Gateway <= 1.4.0 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-39448
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
NOWPayments for WooCommerce – Crypto Payment Gateway [nowpayments-for-woocommerce]
Researcher
b4shu206
More Details >
OpenAI Chatbot for WordPress – Helper <= 1.1.4 - Missing Authorization to Unauthenticated Arbitrary Content Deletion
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2025-69134
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
OpenAI Chatbot for WordPress – Helper [helper]
Researcher
Denver Jackson
More Details >
POS Entegratör – Gurmehub Ödeme Eklentisi <= 3.7.103 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-57688
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
POS Entegratör – Gurmehub Ödeme Eklentisi [pos-entegrator]
Researcher
hivesec
More Details >
Premium Addons for KingComposer <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Custom Sidebar Creation and Deletion via 'add_custom_sidebar' and 'remove_custom_sidebar' AJAX actions
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-12349
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
Premium Addons for KingComposer [premium-addons-for-kingcomposer]
Researcher
Eason
More Details >
Sendcloud Shipping <= 1.0.31 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-57760
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Sendcloud Shipping [sendcloud-connected-shipping]
Researcher
Nguyen Ba Khanh
More Details >
Universal Clocks <= 1.2.0 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-57782
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Universal Clocks [universal-clocks]
Researcher
Legion Hunter
More Details >
User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration <= 4.3.7 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-57334
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration [wp-user-frontend]
Researcher(s): Unknown
More Details >
VW Food Corner <= 1.1.0 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-57774
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
VW Food Corner [vw-food-corner]
Researcher
Nabil Irawan
More Details >
VW Wedding <= 1.3.7 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-57776
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
VW Wedding [vw-wedding]
Researcher
Nabil Irawan
More Details >
Woffice CRM <= 5.4.31 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-27435
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
Woffice CRM [woffice]
Researcher
João Pedro S Alcântara (Kinorth)
More Details >
Woostify Sites Library <= 1.6.2 - Missing Authorization
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2025-66076
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
Woostify Sites Library [woostify-sites-library]
Researcher
Legion Hunter
More Details >
WPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display Name
5.3
CVSS Rating
5.3 (Medium)
CVE-ID
CVE-2026-12127
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite]
Researcher
Jack Pas (Dark.)
More Details >
Advanced Shipment Tracking for WooCommerce <= 4.0 - Authenticated (Shop manager+) SQL Injection
4.9
CVSS Rating
4.9 (Medium)
CVE-ID
CVE-2026-57773
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
Advanced Shipment Tracking for WooCommerce [woo-advanced-shipment-tracking]
Researcher
Nguyen Ba Khanh
More Details >
Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Administrator+) SQL Injection via 's' Parameter
4.9
CVSS Rating
4.9 (Medium)
CVE-ID
CVE-2026-12920
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent [gdpr-cookie-consent]
Researcher
PRISM
More Details >
Houzez Property Feed <= 2.5.46 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
4.9
CVSS Rating
4.9 (Medium)
CVE-ID
CVE-2026-13357
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Houzez Property Feed [houzez-property-feed]
Researcher
PRISM
More Details >
Editorial Rating <= 4.0.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Link URL' Field
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-12560
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
Editorial Rating – Product Review & Rating System [editorial-rating]
Researcher
Supoj Polsawas (sp0x5ec)
More Details >
Enable Media Replace <= 4.2.1 - Authenticated (Editor+) Stored Cross-Site Scripting
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-57722
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Enable Media Replace [enable-media-replace]
Researcher
Ananda Dhakal
More Details >
Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via custom_thumbnail Parameter
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-10104
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Product Video Gallery for Woocommerce [product-video-gallery-slider-for-woocommerce]
Researcher
Ravindu Lakmina Munaweera
More Details >
Team Members <= 8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'custom_css' Parameter
4.4
CVSS Rating
4.4 (Medium)
CVE-ID
CVE-2026-12114
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Team Members – Multi Language Supported Team Plugin [team-showcase-supreme]
Researcher
Averon Averenkov (Averon Averenkov)
More Details >
Ad Inserter <= 2.8.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via 'data' Shortcode Attribute
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-11900
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
Ad Inserter – Ad Manager & AdSense Ads [ad-inserter]
Researcher
nightward
More Details >
Advanced Contact form 7 DB <= 2.0.9 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57669
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Advanced Contact form 7 DB [advanced-cf7-db]
Researcher
timomangcut
More Details >
Appointment Booking Calendar <= 1.4.02 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-12113
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Appointment Booking Calendar [appointment-booking-calendar]
Researcher
PRISM
More Details >
Booked - Appointment Booking for WordPress <= 3.0.0 - Cross-Site Request Forgery
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57747
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Booked - Appointment Booking for WordPress [booked]
Researcher
Phat RiO
More Details >
Booked - Appointment Booking for WordPress <= 3.0.0 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57746
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Booked - Appointment Booking for WordPress [booked]
Researcher
Phat RiO
More Details >
Classified Listing – AI-Powered Classified ads & Business Directory <= 5.4.2 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57355
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Classified Listing – AI-Powered Classified ads & Business Directory [classified-listing]
Researcher
Septio Noerdiansyah
More Details >
CrawlWP SEO – Instant Search Engine Indexing & SEO Performance Monitor <= 3.0.16 - Cross-Site Request Forgery
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-59520
Patch Status
Patched
Published
Jul 5, 2026
Affected Software
CrawlWP SEO – Instant Search Engine Indexing & SEO Performance Monitor [mihdan-index-now]
Researcher
Ananda Dhakal
More Details >
EduMall - Professional LMS Education Center WordPress Theme <= 4.5.1 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57797
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
EduMall - Professional LMS Education Center WordPress Theme [edumall]
Researcher
Nguyen Ba Khanh
More Details >
Email Subscribers & Newsletters <= 5.9.27 - Missing Authorization to Authenticated (Contributor+) Settings Modification via ig_es_handle_request AJAX Action
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-11592
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress [email-subscribers]
Researcher
Dmitrii Ignatyev
More Details >
Envo's Templates & Widgets for Elementor and WooCommerce <= 1.4.26 - Missing Authorization to Authenticated (Author+) Private Content Disclosure via Envo Tabs Widget 'templates' Setting
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-11600
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Envo's Templates & Widgets for Elementor and WooCommerce [envo-elementor-for-woocommerce]
Researchers
Alessandro Greco (Aleff)Giovanbattista Ianni
More Details >
Flatsome <= 3.20.5 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57730
Patch Status
Unpatched
Published
Jul 1, 2026
Affected Software
Flatsome [flatsome]
Researcher
Bonds
More Details >
Flatsome <= 3.20.5 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57731
Patch Status
Unpatched
Published
Jul 1, 2026
Affected Software
Flatsome [flatsome]
Researcher
Bonds
More Details >
GiveWP <= 4.15.3 - Cross-Site Request Forgery
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-11981
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
GiveWP – Donation Plugin and Fundraising Platform [give]
Researcher
javitoia
More Details >
Heateor Social Login WordPress <= 1.1.39 - Cross-Site Request Forgery
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57751
Patch Status
Unpatched
Published
Jul 1, 2026
Affected Software
Heateor Social Login WordPress [heateor-social-login]
Researcher
ParkHyunWoo
More Details >
HubSpot All-In-One Marketing – Forms, Popups, Live Chat <= 11.3.56 - Authenticated (Contributor+) Information Exposure
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57736
Patch Status
Unpatched
Published
Jul 1, 2026
Affected Software
HubSpot All-In-One Marketing – Forms, Popups, Live Chat [leadin]
Researcher
Jakub Herman
More Details >
JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Creation/Modification via season_groupedit AJAX action
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-12134
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
JoomSport – for Sports: Team & League, Football, Hockey & more [joomsport-sports-league-results-management]
Researchers
PRISMChloe Chamberland
More Details >
JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Deletion via season_groupdel AJAX action
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-12133
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
JoomSport – for Sports: Team & League, Football, Hockey & more [joomsport-sports-league-results-management]
Researchers
Chloe ChamberlandPRISM
More Details >
Kadence Blocks <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Optimizer Data Deletion/Read/Modification via 'post_path' Parameter
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-12904
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks]
Researcher
se1en
More Details >
Kadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Attachment Creation via kadence_import_process_pattern/kadence_import_process_data AJAX Actions
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-12902
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks]
Researcher
se1en
More Details >
Link Whisper Premium <= 2.9.0 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57353
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
Link Whisper Premium [link-whisper-premium]
Researcher
Austin Ginder
More Details >
MainWP Dashboard: Self-hosted WordPress Management for Agencies <= 6.1.1 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57327
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
MainWP Dashboard: Self-hosted WordPress Management for Agencies [mainwp]
Researcher
sleeper
More Details >
Martfury - WooCommerce Marketplace WordPress <= 3.2.8 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57685
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
Martfury - Marketplace Mobile App Figma Template [martfury]
Researcher
Ananda Dhakal
More Details >
MotoPress Hotel Booking <= 6.0.3 - Authenticated (Subscriber+) Information Exposure
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57347
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
MotoPress Hotel Booking [motopress-hotel-booking-lite]
Researcher
Sakimi
More Details >
Motors <= 1.4.111 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'stm_mark_as_sold_car' Parameter
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-12435
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Motors – Car Dealership & Classified Listings Plugin [motors-car-dealership-classified-listings]
Researcher
Michael Perla (vizen5)
More Details >
pCloud WP Backup <= 2.0.4 - Cross-Site Request Forgery
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57757
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
pCloud WP Backup [pcloud-wp-backup]
Researcher
R2D2
More Details >
Permalink Manager for WooCommerce <= 1.0.8.2 - Cross-Site Request Forgery
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57758
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
Permalink Manager for WooCommerce [permalink-manager-for-woocommerce]
Researcher
dodoh4t
More Details >
Plugin for Google Analytics by IO technologies <= 1.1 - Cross-Site Request Forgery via 'ga_id' Parameter
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-8944
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
Plugin for Google Analytics by IO technologies [io-engagement-analytics]
Researcher
afnaan
More Details >
ProfileGrid – User Profiles, Groups and Communities <= 5.9.9.8 - Cross-Site Request Forgery
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57759
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities]
Researcher
dodoh4t
More Details >
Qi Blocks <= 1.4.9 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Style Modification via 'page_id' Parameter
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-10096
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Qi Blocks [qi-blocks]
Researcher
Dmitrii Ignatyev
More Details >
Quads Ads Manager for Google AdSense <= 3.0.3 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57335
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Quads Ads Manager for Google AdSense [quick-adsense-reloaded]
Researcher
Ananda Dhakal
More Details >
Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structure
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-9230
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker [quiz-master-next]
Researcher
Kirasec
More Details >
RTMKit <= 2.0.7 - Authenticated (Contributor+) Limited Local File Inclusion via 'template' Parameter
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-5137
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
RTMKit [rometheme-for-elementor]
Researcher
wesley (wcraft)
More Details >
Simple User Avatar <= 4.9 - Authenticated (Subscriber+) Insecure Direct Object Reference
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57676
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Simple User Avatar [simple-user-avatar]
Researcher
Ananda Dhakal
More Details >
Slim SEO <= 4.9.8 - Authenticated (Contributor+) Insufficient Authorization to Private Content Disclosure via 'object.ID' Parameter
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-12408
Patch Status
Patched
Published
Jun 30, 2026
Affected Software
Slim SEO – A Fast & Automated SEO Plugin For WordPress [slim-seo]
Researcher
Abu Hurayra (HurayraIIT)
More Details >
Tax Exempt for WooCommerce <= 1.9.3 - Authenticated (Customer+) Path Traversal
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-49779
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
Tax Exempt for WooCommerce [woocommerce-tax-exempt-plugin]
Researcher
Saad Malik
More Details >
ThumbPress – Compress Images, Manage Thumbnails, Detect Image Issues, WebP/AVIF, Lazy Loading, Hotlinking & More <= 6.3.2 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57720
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
ThumbPress – Compress Images, Manage Thumbnails, Detect Image Issues, WebP/AVIF, Lazy Loading, Hotlinking & More [image-sizes]
Researcher
Denver Jackson
More Details >
VikBooking Hotel Booking Engine & PMS <= 1.8.12 - Cross-Site Request Forgery
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57723
Patch Status
Patched
Published
Jul 1, 2026
Affected Software
VikBooking Hotel Booking Engine & PMS [vikbooking]
Researcher
VDsec
More Details >
Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments <= 2.7.6 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57332
Patch Status
Patched
Published
Jun 29, 2026
Affected Software
Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments [wallet-system-for-woocommerce]
Researcher
Evan NR
More Details >
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Missing Authorization to Authenticated (Subscriber+) Data Migration via wedocs_migrate_betterdocs_to_wedocs AJAX Action
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-12729
Patch Status
Patched
Published
Jul 2, 2026
Affected Software
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot [wedocs]
Researcher
PRISM
More Details >
Werkstatt - Creative Portfolio WordPress Theme <= 4.7.2 - Cross-Site Request Forgery
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57690
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
Werkstatt - Creative Portfolio WordPress Theme [werkstatt]
Researcher
Ananda Dhakal
More Details >
Werkstatt - Creative Portfolio WordPress Theme <= 4.7.2 - Missing Authorization
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57689
Patch Status
Unpatched
Published
Jun 29, 2026
Affected Software
Werkstatt - Creative Portfolio WordPress Theme [werkstatt]
Researcher
Ananda Dhakal
More Details >
WPIDE – File Manager & Code Editor <= 3.5.6 - Cross-Site Request Forgery
4.3
CVSS Rating
4.3 (Medium)
CVE-ID
CVE-2026-57766
Patch Status
Unpatched
Published
Jul 2, 2026
Affected Software
WPIDE – File Manager & Code Editor [wpide]
Researcher
dodoh4t
More Details >
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (June 29, 2026 to July 5, 2026) appeared first on Wordfence.
Quelle: www.wordfence.com