CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2026-25451

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder bold-page-builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through <= 5.6.9.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25441

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in varunvairavanlc LeadConnector leadconnector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LeadConnector: from n/a through <= 3.0.21.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-25432

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omnipressteam Omnipress omnipress allows Stored XSS.This issue affects Omnipress: from n/a through <= 1.6.7.

    Published: 19 Feb 2026
    4.4
    Medium

    CVE-2026-25428

    Last Modified: 16 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in totalsoft TS Poll poll-wp allows Server Side Request Forgery.This issue affects TS Poll: from n/a through <= 2.5.5.

    Published: 19 Feb 2026
    3.8
    Low

    CVE-2026-25423

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real 3D FlipBook: from n/a through <= 4.19.1.

    Published: 19 Feb 2026
    5.4
    Medium

    CVE-2026-25422

    Last Modified: 16 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Themes4WP Popularis Extra popularis-extra allows Cross Site Request Forgery.This issue affects Popularis Extra: from n/a through <= 1.2.10.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25420

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in MailerLite MailerLite official-mailerlite-sign-up-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MailerLite: from n/a through <= 1.7.18.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25419

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in flycart UpsellWP checkout-upsell-and-order-bumps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UpsellWP: from n/a through <= 2.2.5.

    Published: 19 Feb 2026
    7.6
    High

    CVE-2026-25418

    Last Modified: 16 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form bit-form allows SQL Injection.This issue affects Bit Form: from n/a through <= 2.21.10.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25416

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects News Kit Elementor Addons: from n/a through <= 1.4.2.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25415

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPBookit Pro: from n/a through <= 1.6.18.

    Published: 19 Feb 2026
    Unknown

    CVE-2026-25412

    Last Modified: 24 Feb 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25411

    Last Modified: 16 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in themastercut Revision Manager TMC revision-manager-tmc allows Cross Site Request Forgery.This issue affects Revision Manager TMC: from n/a through <= 2.8.22.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25410

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in tstephenson WP-CORS wp-cors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-CORS: from n/a through <= 0.2.2.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25409

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in crgeary JAMstack Deployments wp-jamstack-deployments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JAMstack Deployments: from n/a through <= 1.1.1.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25408

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in PluginRx Broken Link Notifier broken-link-notifier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Broken Link Notifier: from n/a through <= 1.3.5.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25407

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in cookiebot Cookiebot cookiebot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cookiebot: from n/a through <= 4.6.4.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25404

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Automattic WP Job Manager wp-job-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Manager: from n/a through <= 2.4.0.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25402

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in echoplugins Knowledge Base for Documentation, FAQs with AI Assistance echo-knowledge-base allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Knowledge Base for Documentation, FAQs with AI Assistance: from n/a through <= 16.011.0.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25399

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in CryoutCreations Serious Slider cryout-serious-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Serious Slider: from n/a through <= 1.2.7.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25395

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in ikreatethemes Business Roy business-roy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Roy: from n/a through <= 1.1.4.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25394

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in sparklewpthemes Fitness FSE fitness-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fitness FSE: from n/a through <= 1.0.6.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25393

    Last Modified: 17 Apr 2026

    Missing Authorization vulnerability in sparklewpthemes Hello FSE hello-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hello FSE: from n/a through <= 1.0.6.

    Published: 19 Feb 2026
    4.7
    Medium

    CVE-2026-25392

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in KaizenCoders Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress update-urls allows Phishing.This issue affects Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress: from n/a through <= 1.4.3.

    Published: 19 Feb 2026
    5.4
    Medium

    CVE-2026-25391

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in WP Grids WP Wand ai-content-generation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Wand: from n/a through <= 1.3.07.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25389

    Last Modified: 16 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Retrieve Embedded Sensitive Data.This issue affects EventPrime: from n/a through <= 4.2.8.3.

    Published: 19 Feb 2026
    5.4
    Medium

    CVE-2026-25388

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in scripteo Ads Pro ap-plugin-scripteo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ads Pro: from n/a through <= 5.0.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25387

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Elementor Image Optimizer by Elementor image-optimization allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Optimizer by Elementor: from n/a through <= 1.7.1.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25386

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Elementor Ally pojo-accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ally: from n/a through <= 4.0.2.

    Published: 19 Feb 2026
    5.5
    Medium

    CVE-2026-25385

    Last Modified: 16 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in KaizenCoders URL Shortify url-shortify allows Server Side Request Forgery.This issue affects URL Shortify: from n/a through <= 1.12.3.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25384

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-Lister Lite for eBay: from n/a through <= 3.8.5.

    Published: 19 Feb 2026
    7.6
    High

    CVE-2026-25378

    Last Modified: 16 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Blind SQL Injection.This issue affects Nelio AB Testing: from n/a through <= 8.2.4.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25375

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through <= 3.6.10.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25374

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in raratheme Spa and Salon spa-and-salon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spa and Salon: from n/a through <= 1.3.2.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-25372

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Kodezen LLC Academy LMS academy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Academy LMS: from n/a through <= 3.5.3.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25370

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Compress: from n/a through <= 6.60.28.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-25368

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in codepeople Calculated Fields Form calculated-fields-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Calculated Fields Form: from n/a through <= 5.4.4.1.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25367

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in NooTheme CitiLights noo-citilights allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CitiLights: from n/a through < 3.7.2.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25364

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.8.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25363

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in FooPlugins FooGallery foogallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FooGallery: from n/a through <= 3.1.11.

    Published: 19 Feb 2026
    5.9
    Medium

    CVE-2026-25362

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FooPlugins FooGallery foogallery allows Stored XSS.This issue affects FooGallery: from n/a through <= 3.1.11.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25348

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Alt Text AI: from n/a through <= 1.10.15.

    Published: 19 Feb 2026
    5.9
    Medium

    CVE-2026-25343

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS wp-sms allows DOM-Based XSS.This issue affects WP SMS: from n/a through <= 7.1.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25338

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator by AYS ays-chatgpt-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI ChatBot with ChatGPT and Content Generator by AYS: from n/a through <= 2.7.4.

    Published: 19 Feb 2026
    5.4
    Medium

    CVE-2026-25337

    Last Modified: 16 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wpcoachify Coachify coachify allows Cross Site Request Forgery.This issue affects Coachify: from n/a through <= 1.1.5.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25336

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in wpcoachify Coachify coachify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Coachify: from n/a through <= 1.1.5.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25335

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Ays Pro Secure Copy Content Protection and Content Locking secure-copy-content-protection allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Secure Copy Content Protection and Content Locking: from n/a through <= 5.0.0.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25333

    Last Modified: 17 Apr 2026

    Missing Authorization vulnerability in peregrinethemes Shopwell shopwell allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shopwell: from n/a through <= 1.0.11.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25332

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Fahad Mahmood Endless Posts Navigation endless-posts-navigation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Endless Posts Navigation: from n/a through <= 2.2.9.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-25331

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log wp-security-audit-log allows DOM-Based XSS.This issue affects WP Activity Log: from n/a through <= 5.5.4.

    Published: 19 Feb 2026