Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | CVEs | Anteil |
|---|---|---|
| ≥90 % | 720 | 0,2 % |
| ≥50 % | 3.223 | 0,9 % |
| ≥10 % | 22.115 | 6,0 % |
| <10 % | 342.373 | 92,9 % |
CVE-2026-97396 | Retainful Email Marketing for WooCommerce Plugin up to 1.0.10 on WordPress data cross site scripting (EUVD-2026-96280)
A vulnerability described as problematic has been identified in Retainful Email Marketing for WooCommerce Plugin up to 1.0.10 on WordPress. This affects an unknown part. Executing a manipulation of the argument data can lead to cross site s
CVE-2026-96765 | WPO365 Plugin up to 44.1 on WordPress id_token cross site scripting (EUVD-2026-96281)
A vulnerability was found in WPO365 Plugin up to 44.1 on WordPress and classified as problematic. Impacted is an unknown function. Such manipulation of the argument id_token leads to cross site scripting. This vulnerability is listed as CVE
CVE-2026-104803 | whyun WPCOM Member Plugin up to 1.7.27 on WordPress Social Login Callback weapp_new_user uuid/code improper authentication (EUVD-2026-96279)
A vulnerability marked as critical has been reported in whyun WPCOM Member Plugin up to 1.7.27 on WordPress. This impacts the function weapp_new_user of the component Social Login Callback Handler. This manipulation of the argument uuid/cod
CVE-2026-96653 | WP Directory Kit Plugin up to 1.5.9 on WordPress Profile Field update_listings_user_editor display_name sql injection (EUVD-2026-96283)
A vulnerability was found in WP Directory Kit Plugin up to 1.5.9 on WordPress. It has been rated as critical. This affects the function WdkCachedUserEditor::update_listings_user_editor of the component Profile Field. The manipulation of the
CVE-2026-100178 | WPAdverts Plugin up to 2.3.4 on WordPress adverts_location cross site scripting (EUVD-2026-96282)
A vulnerability, which was classified as problematic, was found in WPAdverts Plugin up to 2.3.4 on WordPress. This vulnerability affects unknown code. The manipulation of the argument adverts_location results in cross site scripting. This v
CVE-2026-104728 | rubengc AutomatorWP Plugin up to 5.8.4 on WordPress authorization (EUVD-2026-96284)
A vulnerability classified as problematic has been found in rubengc AutomatorWP Plugin up to 5.8.4 on WordPress. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in authorization bypass. This vul
CVE-2026-102774 | BrainstormForce SureDash Plugin up to 1.12.1 on WordPress Post Content cross site scripting (EUVD-2026-96285)
A vulnerability classified as problematic was found in BrainstormForce SureDash Plugin up to 1.12.1 on WordPress. Affected by this issue is some unknown functionality of the component Post Content. Executing a manipulation can lead to cross
CVE-2026-104759 | WPO365 Plugin up to 44.1 on WordPress Deprecated Parser process_openidconnect_token id_token authentication replay (EUVD-2026-96286)
A vulnerability identified as critical has been detected in WPO365 Plugin up to 44.1 on WordPress. The impacted element is the function Id_Token_Service_Deprecated::process_openidconnect_token of the component Deprecated Parser. The manipul
CVE-2026-102291 | meum Kirki Plugin up to 6.3.1 on WordPress Shortcode Execution replace_content display_name command injection (EUVD-2026-96287)
A vulnerability labeled as critical has been found in meum Kirki Plugin up to 6.3.1 on WordPress. This affects the function TheFrontend::replace_content of the component Shortcode Execution. The manipulation of the argument display_name res
CVE-2026-97340 | meFusion Avada up to 7.16.1 on WordPress Author Page get_markup cross site scripting (EUVD-2026-96288)
A vulnerability was found in meFusion Avada up to 7.16.1 on WordPress. It has been declared as problematic. The impacted element is the function Fusion_Social_Icon::get_markup of the component Author Page. Executing a manipulation of the ar
CVE-2026-93746 | WebToffee PDF Invoices Packing Slips Delivery Notes & Shipping Labels Plugin print_document_from_the_mail_link resource injection (EUVD-2026-96289)
A vulnerability categorized as problematic has been discovered in WebToffee PDF Invoices Packing Slips Delivery Notes &amp; Shipping Labels Plugin up to 5.0.2 on WordPress. This impacts the function print_document_from_the_mail_link. Th
CVE-2026-103478 | codename065 Premium Packages Plugin up to 7.2.6 on WordPress phone/state/taxid/email cross site scripting (EUVD-2026-96290)
A vulnerability was found in codename065 Premium Packages Plugin up to 7.2.6 on WordPress. It has been classified as problematic. The affected element is an unknown function. Performing a manipulation of the argument phone/state/taxid/email
CVE-2026-93951 | Bracketweb Zeinet Plugin up to 1.0.0 on WordPress cross site scripting (EUVD-2026-96291)
A vulnerability classified as problematic has been found in Bracketweb Zeinet Plugin up to 1.0.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting. This vulnerability is uniquely identifie
CVE-2026-40345 | RebeccaStevens deepmerge-ts up to 7.x stack-based overflow (WID-SEC-2026-3831)
A vulnerability categorized as problematic has been discovered in RebeccaStevens deepmerge-ts up to 7.x. This affects the function deepmerge/deepmergeCustom/deepmergeInto/deepmergeIntoCustom. The manipulation results in stack-based buffer o
CVE-2018-14718 | Oracle JDeveloper 12.1.3.0.0/12.2.1.3.0 jackson-databind deserialization (ID 176635 / BID-106601)
A vulnerability, which was classified as critical, has been found in Oracle JDeveloper 12.1.3.0.0/12.2.1.3.0. This affects an unknown function of the component jackson-databind. This manipulation causes deserialization. This vulnerability a
CVE-2018-12120 | Node.js up to 6.14.x Debugger --debug=localhost 7pk security (Nessus ID 119511 / ID 172114)
A vulnerability described as critical has been identified in Node.js up to 6.14.x. Affected is an unknown function of the component Debugger. Executing a manipulation of the argument --debug=localhost can lead to 7pk security features. This
CVE-2018-12116 | Node.js up to 6.14.x/8.13.x HTTP Request request smuggling (Nessus ID 119511 / ID 172114)
A vulnerability marked as critical has been reported in Node.js up to 6.14.x/8.13.x. This impacts an unknown function of the component HTTP Request Handler. Performing a manipulation results in http request smuggling. This vulnerability is
CVE-2018-1000880 | libarchive 3.2.0 archive_read_support_format_warc.c warc_read Archive double free (USN-3859-1 / Nessus ID 119893)
A vulnerability has been found in libarchive 3.2.0 and classified as problematic. The impacted element is the function warc_read of the file libarchive/archive_read_support_format_warc.c. The manipulation as part of Archive leads to double
CVE-2018-1000879 | libarchive 3.3.0 libarchive/archive_acl.c archive_acl_from_text_l null pointer dereference (FEDORA-2019-0233ec0ff3 / ID 277759)
A vulnerability, which was classified as problematic, was found in libarchive 3.3.0. The affected element is the function archive_acl_from_text_l of the file libarchive/archive_acl.c. Executing a manipulation can lead to null pointer derefe
Citrix NetScaler ADC and Gateway: eight advisories, two under active exploitation (CVE-2026-88776)
Citrix NetScaler ADC and Gateway: eight advisories, two under active exploitation (CVE-2026-88776) The Dutch national cyber security centre published NCSC-2026-0394 on 27 September 2026 with a High priority rating. The subject is a single h
CVE-2018-5407 | CPU Multi-Threading Timing information disclosure (RHSA-2019:0483 / EDB-45785)
A vulnerability described as critical has been identified in CPU. The impacted element is an unknown function of the component Multi-Threading. The manipulation as part of Timing results in information disclosure. This vulnerability is iden
CVE-2018-0734 | Oracle Enterprise Session Border Controller up to 8.3 Security key management (Nessus ID 211827 / ID 20103)
A vulnerability labeled as critical has been found in Oracle Enterprise Session Border Controller 7.5/8.0/8.1/8.2/8.3. This impacts an unknown function of the component Security. Such manipulation leads to key management error. This vulnera
CVE-2026-77166 | Nextcloud Collectives up to 3.5.0 Page Emoji Update Endpoint emoji injection (WID-SEC-2026-3840)
A vulnerability has been found in Nextcloud Collectives up to 3.5.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Page Emoji Update Endpoint. This manipulation of the argument emoji cau
Two AhsayCBS Zero-Day Vulnerabilities Actively Exploited to Take Over Backup Servers
Threat actors are exploiting two zero-day vulnerabilities in Ahsay Cloud Backup Server (AhsayCBS) to compromise exposed backup servers without authentication and execute commands with SYSTEM privileges. Observed intrusions have deployed web
CVE-2026-96667 | The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The reCAPTCHA check is trivially bypassed by
The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 7.3 due to insufficient input sanitizatio
CVE-2026-94375 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8 via the get_file_path. This makes it possible for unauthenticated attackers to extract download exported order CSV files containing customer PII — including names, billing and shipping addresses, email addresses, phone numbers, and order contents — directly over HTTP with no authentication. This is ex
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8 via the get_file_path. This makes it possible for unauthenticated attackers to
CVE-2026-104763 | The Post Export Import with Media plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.17.1 via the 'file_path' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. This requires the attacker to upload a crafted ZIP archive containing a media_metadata.json f
The Post Export Import with Media plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.17.1 via the 'file_path' parameter parameter. This makes it possible for authenticated attackers, with admin
CVE-2026-104725 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9 This is due to a missing ownership and capability check on the `user` parameter within the `process_edit()` function, which allows any authenticated user with the `edit_contacts` capability to reassign a contact record's linked WordPress user ID to any arbitrary account without requiring the `edit_us
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9 This is due to a missing ownership and capability check on the `user` parameter
CVE-2026-103520 | The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom text attribute (user-defined field name)' parameter in all versions up to, and including, 1.7.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whe
The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom text attribute (user-defined field name)' parameter in all versions up to, and including,
CVE-2026-83526 | The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This is due to insufficient file type validation in check_mimetype(), which writes attacker-supplied remote file content to the public uploads directory before any MIME or extension check, combined with a missing capability check on new player creation. This makes it possible for authenticated attackers, with
The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This is due to insufficient file type validation in check_mimetype(), which writes atta
CVE-2026-16776 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.14.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Wo
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.14.2 due to insufficient input sanitiza
CVE-2026-14379 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_id' parameter in all versions up to, and including, 7.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user a
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_id' parameter in all versions up to, and including, 7.9.4 due t
CVE-2026-104766 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.7.3. This is due to the `OsSettingsController::update()` handler iterating over attacker-supplied `settings` parameters without an allowlist of permitted setting names or values, and `OsSettingsHelper::prepare_value()` performing no role allowlist validation before persisting the `
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.7.3. This is due to the `OsSettingsController::update()` han
CVE-2026-104742 | The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify global site-wide semantic search settings, including vector provider, embedding provider, embeddin
The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized
CVE-2026-78068 | The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell Content in all versions up to, and including, 1.3.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell Content in all versions up to, and including, 1.3.35 due to insufficient input sanitization and output escaping. This ma
CVE-2026-104741 | The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify global plugin indexing and vector-search configuration options (aipkit_training_general_settings a
The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized
CVE-2026-104023 | The Smart Popup by Supsystic plugin for WordPress is vulnerable to generic SQL Injection via the 'sidx' parameter in all versions up to, and including, 1.13.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to ext
The Smart Popup by Supsystic plugin for WordPress is vulnerable to generic SQL Injection via the 'sidx' parameter in all versions up to, and including, 1.13.2 due to insufficient escaping on the user supplied parameter and lack of sufficien
CVE-2026-91050 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference / Missing Authorization in versions up to, and including, 5.7.2. This is due to the publicly reachable steps__start and steps__load_step routes accepting a params[presets][order_item_id] value that is copied verbatim into the booking object without verifying that the referenced order item belongs to the curren
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference / Missing Authorization in versions up to, and including, 5.7.2. This is due to the publ
CVE-2026-18496 | The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.4.3 via the wpbc_is_show_popover_in_flex_timeline() function. This makes it possible for unauthenticated attackers to extract sensitive data including names, email addresses, and phone numbers of customers who have made bookings.
The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.4.3 via the wpbc_is_show_popover_in_flex_timeline() function. This makes it possible for unauthenticated atta
CVE-2026-89301 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to limited file deletion due to insufficient file path validation in the process function in all versions up to, and including, 4.7.13 This makes it possible for unauthenticated attackers to delete arbitrary safe files on the server.. The public nonce (rtmedia_upload_nonce) is emitted into frontend JavaScript on any page rendering the rtMedia gallery or upload shortcode, maki
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to limited file deletion due to insufficient file path validation in the process function in all versions up to, and including, 4.7.13 This makes it possib
CVE-2026-97670 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16.1. This is due to the plugin not properly verifying authorization before dispatching a WordPress action hook whose name is taken from an attacker-supplied form-field value (via the notification email_message [field] placeholder and the {action_hook,...} dynamic-data token; the 3.16.1 trust gate is_content_request_supplied() only ins
The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16.1. This is due to the plugin not properly verifying authorization before dispatching a WordPress action hook wh
CVE-2026-104021 | The Fastcache by Host.it plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.7.4 via the `fastcache_settings[cache_cookie_exclude][]` parameter. This is due to the plugin registering the `cache_cookie_exclude` setting via `register_setting()` without a `sanitize_callback`, while `buildSiteHtaccessRules()` applies only `trim()` to each cookie value before interpolating it directly into an Apache `RewriteCond` line — a
The Fastcache by Host.it plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.7.4 via the `fastcache_settings[cache_cookie_exclude][]` parameter. This is due to the plugin registering the `cache_cooki
CVE-2026-9696 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'not_found' parameter in all versions up to, and including, 3.3.58 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'not_found' parameter in all versions up to, and including, 3.3.58 due to insufficient input sanitization and output escaping. This makes it poss
CVE-2026-104724 | The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to generic SQL Injection via FireBox Form Display Condition in all versions up to, and including, 3.1.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional
The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to generic SQL Injection via FireBox Form Display Condition in all versions up to, and including, 3.1.13 due to in
CVE-2026-103998 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'inputs (array key)' parameter in all versions up to, and including, 1.15.48 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action su
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'inputs (array key)' parameter in all versions up to, and including, 1.15.48 due to insu
CVE-2026-6723 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 1.6.11.11. This is due to the appointment update REST API endpoint not restricting which fields can be modified by token-authenticated customers. This makes it possible for unauthenticated attackers to modify admin-controlled fields on that appointment, including faking payment confir
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 1.6.11.11. This is due to the appointment update REST API end
CVE-2026-103424 | The Anti-Spam by CleanTalk – Spam Protection Without CAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 6.88 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is exploitable once a comment
The Anti-Spam by CleanTalk – Spam Protection Without CAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 6.88 due to insufficient input sanitization and
CVE-2026-87869 | The Filter Everything — WordPress & WooCommerce Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9.6. This is due to insufficient input sanitization and output escaping in the flrt_elementor_load_more_anchor() function. The function reads query parameters from $_SERVER['REQUEST_URI'] via getFormActionOrFullPageUrl(true), which URL-decodes them through parse_str() and re-assembles them using build
The Filter Everything — WordPress & WooCommerce Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9.6. This is due to insufficient input sanitization and output escaping in the
CVE-2026-104735 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Feedzy Loop Block Feed URL / RSS <title> in all versions up to, and including, 5.2.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execu
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Feedzy Loop Block Feed URL / RSS in all versions up to, and including, 5
CVE-2026-103964 | The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.71 via the 'first_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the administrator's full Cookie header, including wordpress_logged_in_* session cookies, from the suspension email sent during the administrator's authenticated request, enabling full session
The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.71 via the 'first_name' parameter. This makes it possible for authenticated attackers, with subscriber-level
CVE-2026-97630 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Unquoted popup Shortcode Attribute in all versions up to, and including, 7.5.54.7212 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Unquoted popup Shortcode Attribute in all versions up to, and including, 7.5.54.7212 due to insufficient input sanitization and output esca
CVE-2026-5727 | The Hello Plus plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to publish their own Hello+ header/footer templates and draft currently active templates owned by higher-privileged users.
The Hello Plus plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible f
CVE-2026-102401 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regurl' parameter in all versions up to, and including, 3.3.71 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload only fires for logged-out s
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regurl' parameter in all versions up to, and including, 3.3.71 due to insufficient input sanitization and output escaping. This makes it possibl
CVE-2026-103889 | The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter parameter. This is due to missing authentication and nonce checks on the wp_loaded handler combined with no sanitization of the xpv_image POST parameter before it is echoed unescaped into a Dompdf-rendered HTML template with PHP execution enabled. This makes it possible for unauthen
The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter parameter. This is due to missing authentication and nonce ch
CVE-2026-101324 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'any attacker-chosen name matching the {get.NAME} placeholder (PoC uses 'proof')' parameter in all versions up to, and including, 6.2.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'any attacker-chosen name matching the {get.NAME} placeholder (PoC uses
CVE-2026-96648 | The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell 'data' Value via updateRows Action in all versions up to, and including, 1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is o
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell 'data' Value via updateRows Action in all versions up to, and including, 1.15.1 due to insufficient input sanitization a
CVE-2026-104993 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email (Contact Email custom field htmlvar_name)' parameter in all versions up to, and including, 2.8.188 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that wi
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email (Contact Email custom field htmlvar_name)' parameter in all versions up to, a
CVE-2026-108501 | ZTE Z80 Ultra has a system interface permission verification defect. The interface lacks necessary access control, and relevant information can be read by reflectively invoking the interface.
ZTE Z80 Ultra has a system interface permission verification defect. The interface lacks necessary access control, and relevant information can be read by reflectively invoking the interface.
CVE-2026-94589 | The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7_submit function. This is due to missing file extension, MIME type, and size validation in the signature field's validation_filter(), combined with the absence of PHP-execution guards in the upload directory and a sanitize_file_name() bypass that converts shel
The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7_submit function. This is due to miss
CVE-2026-104732 | The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 8.13.13 The vulnerability exists because `handle_login_action()` performs no server-side check — via transient, session marker, or equivalent — that a requester completed step-1 password authentication before processing a step-2 TOTP submission for the POSTed `user_id`; compounding this, an error branch in the function unconditionally min
The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 8.13.13 The vulnerability exists because `handle_login_action()` performs no server-side check — via transient, sessio