Security News

Cybersecurity news aggregator

MEDIUM Vulnerabilities Wordfence

Wordfence Intelligence Weekly WordPress Vulnerability Report (May 18, 2026 to May 24, 2026)

  • What: 99 WordPress vulnerabilities disclosed in plugins and themes
  • Impact: WordPress users may be affected if they don't update
Read Full Article →

Last week, there were 99 vulnerabilities disclosed in 87 WordPress Plugins and 1 WordPress Theme that have been added to the Wordfence Intelligence Vulnerability Database, and there were 68 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface , vulnerability API , webhook integration , and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back. Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 35,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free . Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. New Firewall Rules Deployed Last Week The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection. The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium , Care , and Response customers last week: WAF-RULE-915 – Data redacted while we work with the vendor on a patch. Wordfence Premium , Care , and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay. Total Unpatched & Patched Vulnerabilities Last Week Patch Status Number of Vulnerabilities Patched 63 Unpatched 36 Total Vulnerabilities by CVSS Severity Last Week Severity Rating Number of Vulnerabilities Medium Severity 65 High Severity 24 Critical Severity 10 Total Vulnerabilities by CWE Type Last Week Vulnerability Type by CWE Number of Vulnerabilities Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 28 Missing Authorization 18 Cross-Site Request Forgery (CSRF) 13 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 11 Improper Privilege Management 8 Unrestricted Upload of File with Dangerous Type 5 Authorization Bypass Through User-Controlled Key 4 Exposure of Sensitive Information to an Unauthorized Actor 4 Server-Side Request Forgery (SSRF) 2 Deserialization of Untrusted Data 1 Improper Authentication 1 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 1 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1 Incorrect Privilege Assignment 1 Relative Path Traversal 1 Researchers That Contributed to WordPress Security Last Week Researcher Name Number of Vulnerabilities Muhammad Nur Ibnu Hubab 14 h0xilo 5 hhhai 4 Abdulsamad Yusuf (0xVenus) 3 zaim 3 Osvaldo Noe Gonzalez Del Rio (Os) 3 theviper17y 3 Athiwat Tiprasaharn (Jitlada) 2 daroo 2 Dmitrii Ignatyev 2 0xd4rk5id3 2 Que Thanh Tuan 2 Julian Chibuike Nwadinobi (Wackydawg) 2 BIMA IKHSAN 2 snr 1 0x61626390 1 Z3no 1 Thanh Toan Bui 1 oolongeya 1 Rapid0nion 1 Phat RiO 1 Evan NR 1 Tarcísio Luchesi De Almeida Silva (Poystick) 1 Ankit Patel 1 darkmode 1 Nos1x0 1 Joe Bruno 1 Bao Luu Gia Nguyen 1 Tiago Ventura (perses) 1 Md. Moniruzzaman Prodhan (NomanProdhan) 1 Kitch 1 Saleh Elsayed (0xManticore) 1 Tin Pham (TF1T) 1 Trong Pham (dtro) 1 Hao Ngo 1 Doan Dinh Van (DinhVan52) 1 MD. TAREQ AHAMED JONY (itztrq) 1 Itthidej Aramsri (Boeing777) 1 Nguyen Tran Tuan Dung (domiee13) 1 Leonid Semenenko (lsemenenko) 1 Webbernaut 1 Nguyen Ngoc Duc (duc193) 1 walow 1 Van Tho Huynh (l0gs3c) 1 t0ann9uy3n 1 Kazuma Matsumoto 1 endy 1 BaroHaf 1 Peng Zhou 1 Ren Voza 1 Rafie Muhammad 1 Legion Hunter 1 Patryk Siewert 1 Bao - BlueRock 1 Nabil Irawan 1 Hunter Jensen (skid) 1 at1as 1 kudasav 1 momopon1415 1 Nguyen Ba Khanh 1 Nguyen Dinh Hai (HaiND) 1 zakaria 1 sorawautsukushiii 1 Azril Fathoni (kiseki) 1 Bas Albers 1 nudien udin 1 nudien 1 Wannes Verwimp 1 Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program . Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report. WordPress Plugins with Reported Vulnerabilities Last Week Software Name Software Slug Account Switcher account-switcher Active Products Tables for WooCommerce. Use constructor to create tables profit-products-tables-for-woocommerce AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress acymailing Advanced Database Cleaner – Premium advanced-database-cleaner-premium AI Chatbot & Workflow Automation by AIWU ai-copilot-content-generator Alfie – Feed Plugin alfie-the-productfeedtool-wp-plugin All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic all-in-one-seo-pack Amazon Scraper amazon-scraper Anomify AI – Anomaly Detection and Alerting anomify Appointment Booking Plugin for WooCommerce – WpBookingly | All-in-One Service Manager service-booking-manager AudioIgniter Music Player audioigniter Avada (Fusion) Builder fusion-builder Bigfishgames Syndicate bigfishgames-syndicate BLOGCHAT Chat System blogchat-chat-system BookingPress Appointment Booking Pro bookingpress-appointment-booking-pro Boost boost Bottom Bar bottom-bar Broadstreet broadstreet CBX 5 Star Rating & Review cbxscratingreview Child Height Predictor by Ostheimer child-height-predictor Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe contest-gallery Correct Prices correct-prices Cost of Goods by PixelYourSite pixel-cost-of-goods Creative Mail – Easier WordPress & WooCommerce Email Marketing creative-mail-by-constant-contact Ditty – Responsive News Tickers, Sliders, and Lists ditty-news-ticker Divi Form Builder divi-form-builder Draft List simple-draft-list E2Pdf – Export Pdf Tool for WordPress e2pdf Easy Elements for Elementor – Addons & Website Templates easy-elements EventPrime – Events Calendar, Bookings and Tickets eventprime-event-calendar-management Faces of Users faces-of-users FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution fluent-crm Games Catalog game-catalog General Options general-options Gift Cards For WooCommerce Pro giftware GSheet For Woo Importer import-products-from-gsheet-for-woo-importer HT Contact Form – Drag & Drop Form Builder for WordPress ht-contactform Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite Infility Global infility-global JaviBola Custom Theme Test javibola-custom-theme KIA Subtitle kia-subtitle Kirki – Freeform Page Builder, Website Builder & Customizer kirki LJ comments import: reloaded lj-comments-import-reloaded Location Weather – WordPress Weather Forecast, AQI, Temperature and Weather Widget location-weather Logo Manager For Enamad logo-manager-for-enamad Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails mail-mint MasterStudy LMS WordPress Plugin – for Online Courses and Education masterstudy-lms-learning-management-system miniOrange OTP Login, Verification and SMS Notifications miniorange-otp-verification MotoPress Hotel Booking motopress-hotel-booking-lite Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE nexa-blocks Oliver POS – WooCommerce POS for iPhone, iPad & Android oliver-pos PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elementor-forms Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery nextgen-gallery Piotnet Addons For Elementor Pro piotnet-addons-for-elementor-pro Piotnet Forms piotnetforms-pro PowerPress Podcasting plugin by Blubrry powerpress Property Hive propertyhive ProSolution WP Client prosolution-wp-client Quads Ads Manager for Google AdSense quick-adsense-reloaded Read More & Accordion expand-maker Remove Yellow BGBOX remove-yellow-bgbox Sentence To SEO (keywords, description and tags) sentence-to-seo Slider by Soliloquy – Responsive Image Slider for WordPress soliloquy-lite Slider Revolution revslider SponsorMe sponsorme Sticky sticky The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce the-plus-addons-for-elementor-page-builder The Ultimate Video Player For WordPress – by Presto Player presto-player TypeSquare Webfonts for ConoHa ts-webfonts-for-conoha VatanSMS WP SMS wp-sms-vatansms-com Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder vedrixa-forms-registration-builder VikBooking Hotel Booking Engine & PMS vikbooking Visualizer: Tables and Charts Manager for WordPress visualizer Widget Context widget-context Wishlist Member wishlist-member-x WooCommerce PayPal Payments woocommerce-paypal-payments Word 2 Cash word-2-cash WOW Styler for CF7 – Visual Styler for Contact Form 7 Forms cf7-styler WP Activity Log wp-security-audit-log WP Blockade – Visual Page Builder wp-blockade WP ERP Pro erp-pro WP Job Portal – AI-Powered Recruitment System for Company or Job Board website wp-job-portal WPB Floating Menu or Categories – Sticky Floating Side Menu & Categories with Icons wpb-floating-menu-or-categories wpForo Forum wpforo Xpro Addons — 140+ Widgets for Elementor xpro-elementor-addons YITH WooCommerce Product Add-Ons yith-woocommerce-product-add-ons 診断ジェネレータ作成プラグイン os-diagnosis-generator WordPress Themes with Reported Vulnerabilities Last Week Software Name Software Slug FastX fastx Vulnerability Details Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration , which is completely free to utilize. Avada (Fusion) Builder <= 3.15.2 - Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics' Shortcode Attribute via Widget AJAX Handler 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-6279 Patch Status Patched Published May 20, 2026 Affected Software Avada (Fusion) Builder [fusion-builder] Researchers Tin Pham (TF1T) Trong Pham (dtro) Hao Ngo More Details > BookingPress Pro <= 5.6 - Unauthenticated Arbitrary File Upload via Signature Custom Field 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-6960 Patch Status Patched Published May 21, 2026 Affected Software BookingPress Appointment Booking Pro [bookingpress-appointment-booking-pro] Researcher h0xilo More Details > Boost <= 2.0.3 - Unauthenticated PHP Object Injection via STYXKEY-BOOST_USER_LOCATION Cookie 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-7637 Patch Status Patched Published May 19, 2026 Affected Software Boost [boost] Researcher Osvaldo Noe Gonzalez Del Rio (Os) More Details > Divi Form Builder <= 5.1.2 - Unauthenticated Privilege Escalation via 'role' 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-5118 Patch Status Patched Published May 20, 2026 Affected Software Divi Form Builder [divi-form-builder] Researcher 0xd4rk5id3 More Details > Easy Elements for Elementor <= 1.4.4 - Unauthenticated Privilege Escalation via easyel_handle_register 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-7284 Patch Status Patched Published May 19, 2026 Affected Software Easy Elements for Elementor – Addons & Website Templates [easy-elements] Researcher Ankit Patel More Details > Gift Cards For WooCommerce Pro <= 4.2.6 - Unauthenticated Arbitrary File Upload 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-45444 Patch Status Patched Published May 20, 2026 Affected Software Gift Cards For WooCommerce Pro [giftware] Researcher Joe Bruno More Details > miniOrange OTP Login, Verification and SMS Notifications <= 5.4.9 - Unauthenticated Privilege Escalation 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-42731 Patch Status Patched Published May 24, 2026 Affected Software miniOrange OTP Login, Verification and SMS Notifications [miniorange-otp-verification] Researcher Peng Zhou More Details > Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload via Form File Upload 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-4885 Patch Status Unpatched Published May 18, 2026 Affected Software Piotnet Addons For Elementor Pro [piotnet-addons-for-elementor-pro] Researcher Wannes Verwimp More Details > Piotnet Forms <= 2.1.40 - Unauthenticated Arbitrary File Upload via Form File Upload 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-4883 Patch Status Unpatched Published May 18, 2026 Affected Software Piotnet Forms [piotnetforms-pro] Researcher 0xd4rk5id3 More Details > ProSolution WP Client <= 2.0.0 - Unauthenticated Arbitrary File Upload via 'files' 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-6555 Patch Status Unpatched Published May 19, 2026 Affected Software ProSolution WP Client [prosolution-wp-client] Researcher snr More Details > Account Switcher <= 1.0.2 - Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-6456 Patch Status Unpatched Published May 19, 2026 Affected Software Account Switcher [account-switcher] Researcher Ren Voza More Details > AcyMailing <= 10.8.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via 'acymailing_router' 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-5200 Patch Status Patched Published May 19, 2026 Affected Software AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress [acymailing] Researcher Azril Fathoni (kiseki) More Details > Advanced Database Cleaner – Premium <= 4.1.0 - Authenticated (Subscriber+) Local File Inclusion via 'template' 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-7522 Patch Status Patched Published May 19, 2026 Affected Software Advanced Database Cleaner – Premium [advanced-database-cleaner-premium] Researcher Nguyen Ngoc Duc (duc193) More Details > Easy Elements for Elementor – Addons & Website Templates <= 1.4.5 - Unauthenticated Privilege Escalation via 'custom_meta' Parameter 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-9018 Patch Status Unpatched Published May 21, 2026 Affected Software Easy Elements for Elementor – Addons & Website Templates [easy-elements] Researcher sorawautsukushiii More Details > Read More & Accordion <= 3.5.7 - Privilege Escalation via importData 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-7467 Patch Status Unpatched Published May 19, 2026 Affected Software Read More & Accordion [expand-maker] Researcher BIMA IKHSAN More Details > Wishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) API Secret Key Disclosure and Privilege Escalation via 'wlm3_export_settings' AJAX Action 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-6895 Patch Status Patched Published May 22, 2026 Affected Software Wishlist Member [wishlist-member-x] Researcher h0xilo More Details > Wishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) API Secret Key Disclosure and Privilege Escalation via 'wlm3_get_screen' AJAX action 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-6419 Patch Status Patched Published May 22, 2026 Affected Software Wishlist Member [wishlist-member-x] Researcher h0xilo More Details > WishList Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Generate API Secret Key via 'wlm3_generate_api_key' AJAX action 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-6898 Patch Status Patched Published May 22, 2026 Affected Software Wishlist Member [wishlist-member-x] Researcher h0xilo More Details > Wishlist Member <= 3.32.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Options Update via 'wishlistmember_team_accounts_save_settings' AJAX action 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-6897 Patch Status Patched Published May 22, 2026 Affected Software Wishlist Member [wishlist-member-x] Researcher h0xilo More Details > WooCommerce PayPal Payments <= 4.0.1 - Missing Authorization to Unauthenticated Order Manipulation and Information Disclosure 8.2 CVSS Rating 8.2 (High) CVE-ID CVE-2026-9284 Patch Status Patched Published May 22, 2026 Affected Software WooCommerce PayPal Payments [woocommerce-paypal-payments] Researcher Dmitrii Ignatyev More Details > Active Products Tables for WooCommerce. Use constructor to create tables <= 1.0.8 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-42727 Patch Status Patched Published May 19, 2026 Affected Software Active Products Tables for WooCommerce. Use constructor to create tables [profit-products-tables-for-woocommerce] Researcher endy More Details > AudioIgniter Music Player <= 2.0.2 - Unauthenticated Insecure Direct Object Reference to 'audioigniter_playlist_id' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-8679 Patch Status Patched Published May 21, 2026 Affected Software AudioIgniter Music Player [audioigniter] Researchers nudien udin nudien More Details > Boost <= 2.0.3 - Unauthenticated Blind SQL Injection via Multiple Parameters 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-9010 Patch Status Patched Published May 19, 2026 Affected Software Boost [boost] Researcher Osvaldo Noe Gonzalez Del Rio (Os) More Details > Contest Gallery <= 28.1.6 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-8912 Patch Status Patched Published May 18, 2026 Affected Software Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe [contest-gallery] Researcher Leonid Semenenko (lsemenenko) More Details > Creative Mail – Easier WordPress & WooCommerce Email Marketing <= 1.6.9 - Unauthenticated SQL Injection via 'checkout_uuid' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-3985 Patch Status Unpatched Published May 19, 2026 Affected Software Creative Mail – Easier WordPress & WooCommerce Email Marketing [creative-mail-by-constant-contact] Researcher Dmitrii Ignatyev More Details > Ditty <= 3.1.65 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via ditty_init AJAX Action 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-9011 Patch Status Patched Published May 21, 2026 Affected Software Ditty – Responsive News Tickers, Sliders, and Lists [ditty-news-ticker] Researcher Md. Moniruzzaman Prodhan (NomanProdhan) More Details > Kirki <= 6.0.6 - Unauthenticated Limited Arbitrary File Read and Deletion via downloadZIP 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-8073 Patch Status Patched Published May 19, 2026 Affected Software Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] Researcher Rafie Muhammad More Details > WP ERP Pro <= 1.5.1 - Unauthenticated SQL Injection via 'search_key' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-4834 Patch Status Unpatched Published May 21, 2026 Affected Software WP ERP Pro [erp-pro] Researcher kudasav More Details > WP Job Portal – AI-Powered Recruitment System for Company or Job Board website <= 2.5.1 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-42684 Patch Status Patched Published May 23, 2026 Affected Software WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] Researcher hhhai More Details > Cost of Goods by PixelYourSite <= 1.2.12 - Unauthenticated Stored Cross-Site Scripting via Cost of Goods Import 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-7613 Patch Status Patched Published May 19, 2026 Affected Software Cost of Goods by PixelYourSite [pixel-cost-of-goods] Researcher Osvaldo Noe Gonzalez Del Rio (Os) More Details > HT Contact Form – Drag & Drop Form Builder for WordPress <= 2.8.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-42728 Patch Status Patched Published May 20, 2026 Affected Software HT Contact Form – Drag & Drop Form Builder for WordPress [ht-contactform] Researcher daroo More Details > Property Hive <= 2.2.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-42729 Patch Status Patched Published May 23, 2026 Affected Software Property Hive [propertyhive] Researcher Nguyen Dinh Hai (HaiND) More Details > VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-42683 Patch Status Patched Published May 20, 2026 Affected Software VikBooking Hotel Booking Engine & PMS [vikbooking] Researcher Evan NR More Details > WP Job Portal – AI-Powered Recruitment System for Company or Job Board website <= 2.5.1 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-42685 Patch Status Patched Published May 23, 2026 Affected Software WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] Researcher hhhai More Details > Infility Global <= 2.15.16 - Authenticated (Subscriber+) SQL Injection via 'orderby' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-8685 Patch Status Unpatched Published May 19, 2026 Affected Software Infility Global [infility-global] Researcher oolongeya More Details > Kirki <= 6.0.6 - Missing Authorization to Authenticated (Subscriber+) Sensitive Form Submission Data Exposure via 'kirki_wp_admin_get_apis' Action 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-8096 Patch Status Patched Published May 19, 2026 Affected Software Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] Researcher Z3no More Details > MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.29 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-42730 Patch Status Patched Published May 24, 2026 Affected Software MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] Researcher walow More Details > Oliver POS <= 2.4.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to 'OliverAuth' Header 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-6072 Patch Status Patched Published May 19, 2026 Affected Software Oliver POS – WooCommerce POS for iPhone, iPad & Android [oliver-pos] Researcher Hunter Jensen (skid) More Details > PowerPress Podcasting plugin by Blubrry <= 11.15.10 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-24637 Patch Status Patched Published May 20, 2026 Affected Software PowerPress Podcasting plugin by Blubrry [powerpress] Researcher Phat RiO More Details > AI Chatbot & Workflow Automation by AIWU <= 1.4.14 - Unauthenticated Stored Cross-Site Scripting via 'X-Forwarded-For' Header 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-2955 Patch Status Patched Published May 19, 2026 Affected Software AI Chatbot & Workflow Automation by AIWU [ai-copilot-content-generator] Researcher Kazuma Matsumoto More Details > Avada (Fusion) Builder <= 3.15.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Multiple Shortcodes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-1543 Patch Status Patched Published May 20, 2026 Affected Software Avada (Fusion) Builder [fusion-builder] Researcher Webbernaut More Details > Draft List <= 2.6.3 - Authenticated (Author+) Stored Cross-Site Scripting via Draft Post Title 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-9104 Patch Status Patched Published May 21, 2026 Affected Software Draft List [simple-draft-list] Researcher Athiwat Tiprasaharn (Jitlada) More Details > EventPrime – Events Calendar, Bookings and Tickets <= 4.3.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-42686 Patch Status Patched Published May 24, 2026 Affected Software EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] Researcher hhhai More Details > Faces of Users <= 0.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'default' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-8038 Patch Status Unpatched Published May 19, 2026 Affected Software Faces of Users [faces-of-users] Researcher zakaria More Details > KIA Subtitle <= 4.0.1 - [Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')] 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-7509 Patch Status Patched Published May 21, 2026 Affected Software KIA Subtitle [kia-subtitle] Researcher zaim More Details > Logo Manager For Enamad <= 0.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-6549 Patch Status Unpatched Published May 19, 2026 Affected Software Logo Manager For Enamad [logo-manager-for-enamad] Researcher zaim More Details > Sticky <= 2.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'readmoretext' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-6397 Patch Status Unpatched Published May 19, 2026 Affected Software Sticky [sticky] Researcher zaim More Details > The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) Patch Status Patched Published May 21, 2026 Affected Software The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] Researcher theviper17y More Details > The Plus Addons for Elementor <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes 6.4 CVSS Rating 6.4 (Medium) Patch Status Patched Published May 21, 2026 Affected Software The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] Researcher theviper17y More Details > Visualizer: Tables and Charts Manager for WordPress < 4.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-24573 Patch Status Patched Published May 20, 2026 Affected Software Visualizer: Tables and Charts Manager for WordPress [visualizer] Researcher Doan Dinh Van (DinhVan52) More Details > WP Activity Log <= 5.6.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-45435 Patch Status Patched Published May 19, 2026 Affected Software WP Activity Log [wp-security-audit-log] Researcher daroo More Details > 診断ジェネレータ作成プラグイン <= 1.4.16 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'js' Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-5293 Patch Status Unpatched Published May 19, 2026 Affected Software 診断ジェネレータ作成プラグイン [os-diagnosis-generator] Researcher Nabil Irawan More Details > BLOGCHAT Chat System <= 1.3.6.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Update 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-8420 Patch Status Unpatched Published May 19, 2026 Affected Software BLOGCHAT Chat System [blogchat-chat-system] Researcher Muhammad Nur Ibnu Hubab More Details > CBX 5 Star Rating & Review <= 1.0.7 - Reflected Cross-Site Scripting via 'page' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-6864 Patch Status Patched Published May 21, 2026 Affected Software CBX 5 Star Rating & Review [cbxscratingreview] Researcher Julian Chibuike Nwadinobi (Wackydawg) More Details > Correct Prices <= 1.0 - Reflected Cross-Site Scripting via PHP_SELF Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-8627 Patch Status Unpatched Published May 19, 2026 Affected Software Correct Prices [correct-prices] Researcher Abdulsamad Yusuf (0xVenus) More Details > E2Pdf – Export Pdf Tool for WordPress <= 1.32.14 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-42681 Patch Status Patched Published May 18, 2026 Affected Software E2Pdf – Export Pdf Tool for WordPress [e2pdf] Researcher hhhai More Details > LJ comments import: reloaded <= 0.97.1 - Reflected Cross-Site Scripting via PHP_SELF Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-8624 Patch Status Unpatched Published May 19, 2026 Affected Software LJ comments import: reloaded [lj-comments-import-reloaded] Researcher Abdulsamad Yusuf (0xVenus) More Details > Sentence To SEO (keywords, description and tags) <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Page Parameters 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-6391 Patch Status Unpatched Published May 19, 2026 Affected Software Sentence To SEO (keywords, description and tags) [sentence-to-seo] Researcher Muhammad Nur Ibnu Hubab More Details > SponsorMe <= 0.5.2 - Reflected Cross-Site Scripting via PHP_SELF Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-8626 Patch Status Unpatched Published May 19, 2026 Affected Software SponsorMe [sponsorme] Researcher Abdulsamad Yusuf (0xVenus) More Details > VatanSMS WP SMS <= 1.01 - Reflected Cross-Site Scripting via 'page' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-7462 Patch Status Unpatched Published May 19, 2026 Affected Software VatanSMS WP SMS [wp-sms-vatansms-com] Researcher Julian Chibuike Nwadinobi (Wackydawg) More Details > Word 2 Cash <= 0.9.2 - Cross-Site Request Forgeryto Stored Cross-Site Scripting via Settings Page 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-6395 Patch Status Unpatched Published May 19, 2026 Affected Software Word 2 Cash [word-2-cash] Researcher Muhammad Nur Ibnu Hubab More Details > WP Blockade <= 0.9.14 - Reflected Cross-Site Scripting via 'shortcode' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-3481 Patch Status Unpatched Published May 21, 2026 Affected Software WP Blockade – Visual Page Builder [wp-blockade] Researcher theviper17y More Details > FluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' Parameter 5.4 CVSS Rating 5.4 (Medium) CVE-ID CVE-2026-7798 Patch Status Patched Published May 21, 2026 Affected Software FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] Researcher Saleh Elsayed (0xManticore) More Details > Nexa Blocks <= 1.1.1 - Unauthenticated Blind Server-Side Request Forgery via 'demo_json_file' Parameter 5.4 CVSS Rating 5.4 (Medium) CVE-ID CVE-2026-6394 Patch Status Unpatched Published May 19, 2026 Affected Software Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [nexa-blocks] Researcher Patryk Siewert More Details > MotoPress Hotel Booking <= 6.0.1 - Missing Authorization to Unauthenticated Arbitrary Booking Notes Modification via mphb_update_booking_notes AJAX Action 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-8684 Patch Status Patched Published May 21, 2026 Affected Software MotoPress Hotel Booking [motopress-hotel-booking-lite] Researcher MD. TAREQ AHAMED JONY (itztrq) More Details > Quads Ads Manager for Google AdSense <= 3.0.2 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-42732 Patch Status Patched Published May 24, 2026 Affected Software Quads Ads Manager for Google AdSense [quick-adsense-reloaded] Researcher Bas Albers More Details > Slider Revolution <= 7.0.9 - Unauthenticated Sensitive Information Exposure via 'sliders/stream' 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-6728 Patch Status Patched Published May 19, 2026 Affected Software Slider Revolution [revslider] Researcher Nos1x0 More Details > The Ultimate Video Player For WordPress – by Presto Player <= 4.1.3 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-45442 Patch Status Patched Published May 19, 2026 Affected Software The Ultimate Video Player For WordPress – by Presto Player [presto-player] Researcher Bao - BlueRock More Details > WOW Styler for CF7 – Visual Styler for Contact Form 7 Forms <= 1.7.6 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-27393 Patch Status Patched Published May 21, 2026 Affected Software WOW Styler for CF7 – Visual Styler for Contact Form 7 Forms [cf7-styler] Researcher Rapid0nion More Details > wpForo Forum <= 3.0.6 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-42682 Patch Status Patched Published May 18, 2026 Affected Software wpForo Forum [wpforo] Researcher Tiago Ventura (perses) More Details > Xpro Addons — 140+ Widgets for Elementor <= 1.5.0 - Missing Authorization to Unauthenticated Xpro Template Creation 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2025-15369 Patch Status Patched Published May 19, 2026 Affected Software Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] Researcher at1as More Details > Read More & Accordion <= 3.5.7 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-7472 Patch Status Unpatched Published May 19, 2026 Affected Software Read More & Accordion [expand-maker] Researcher BIMA IKHSAN More Details > WPB Floating Menu or Categories – Sticky Floating Side Menu & Categories with Icons <= 1.0.8 - Authenticated (Editor+) Stored Cross-Site Scripting via 'Icon CSS Class' Category Field 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-4811 Patch Status Patched Published May 20, 2026 Affected Software WPB Floating Menu or Categories – Sticky Floating Side Menu & Categories with Icons [wpb-floating-menu-or-categories] Researcher BaroHaf More Details > YITH WooCommerce Product Add-Ons <= 4.29.0 - Authenticated (Shop manager+) SQL Injection 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-42383 Patch Status Patched Published May 20, 2026 Affected Software YITH WooCommerce Product Add-Ons [yith-woocommerce-product-add-ons] Researcher Nguyen Ba Khanh More Details > Anomify AI <= 0.3.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'anomify_api_key' Parameter 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-6404 Patch Status Unpatched Published May 19, 2026 Affected Software Anomify AI – Anomaly Detection and Alerting [anomify] Researcher Muhammad Nur Ibnu Hubab More Details > General Options <= 1.1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'ad_contact_number' Parameter 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-6399 Patch Status Unpatched Published May 19, 2026 Affected Software General Options [general-options] Researcher Muhammad Nur Ibnu Hubab More Details > Alfie <= 1.2.1 - Cross-Site Request Forgery to Feed Deletion via 'delete' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-4070 Patch Status Unpatched Published May 21, 2026 Affected Software Alfie – Feed Plugin [alfie-the-productfeedtool-wp-plugin] Researcher Muhammad Nur Ibnu Hubab More Details > All in One SEO <= 4.9.7 - Authenticated (Contributor+) Sensitive Information Exposure via 'internalOptions' Localized Script Data 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-5075 Patch Status Patched Published May 19, 2026 Affected Software All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic [all-in-one-seo-pack] Researcher 0x61626390 More Details > Amazon Scraper <= 1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Update 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-8419 Patch Status Unpatched Published May 19, 2026 Affected Software Amazon Scraper [amazon-scraper] Researcher Muhammad Nur Ibnu Hubab More Details > Anomify AI <= 0.3.6 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-6405 Patch Status Unpatched Published May 19, 2026 Affected Software Anomify AI – Anomaly Detection and Alerting [anomify] Researcher Muhammad Nur Ibnu Hubab More Details > Appointment Booking Plugin for WooCommerce – WpBookingly | All-in-One Service Manager <= 1.2.9 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-27405 Patch Status Patched Published May 20, 2026 Affected Software Appointment Booking Plugin for WooCommerce – WpBookingly | All-in-One Service Manager [service-booking-manager] Researcher Athiwat Tiprasaharn (Jitlada) More Details > Bigfishgames Syndicate <= 1.2 - Cross-Site Request Forgery to Settings Reset and Update 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-6452 Patch Status Unpatched Published May 19, 2026 Affected Software Bigfishgames Syndicate [bigfishgames-syndicate] Researcher Muhammad Nur Ibnu Hubab More Details > Bottom Bar <= 0.1.7 - Cross-Site Request Forgery to Settings Update 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-6401 Patch Status Unpatched Published May 19, 2026 Affected Software Bottom Bar [bottom-bar] Researcher Muhammad Nur Ibnu Hubab More Details > Broadstreet <= 1.52.2 - Authenticated (Subscriber+) Private Post Meta Disclosure via get_sponsored_meta 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-1881 Patch Status Patched Published May 20, 2026 Affected Software Broadstreet [broadstreet] Researcher Tarcísio Luchesi De Almeida Silva (Poystick) More Details > Child Height Predictor by Ostheimer <= 1.3 - Cross-Site Request Forgery to Settings Update via Plugin Settings Form 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-6400 Patch Status Unpatched Published May 19, 2026 Affected Software Child Height Predictor by Ostheimer [child-height-predictor] Researcher Muhammad Nur Ibnu Hubab More Details > FastX <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installation and Activation 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-2518 Patch Status Unpatched Published May 21, 2026 Affected Software FastX [fastx] Researcher Itthidej Aramsri (Boeing777) More Details > Games Catalog <= 1.2.0 - Cross-Site Request Forgery to Arbitrary Game/Post Deletion 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-8418 Patch Status Unpatched Published May 19, 2026 Affected Software Games Catalog [game-catalog] Researcher Muhammad Nur Ibnu Hubab More Details > GSheet For Woo Importer <= 2.3.1 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Reset 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-4843 Patch Status Patched Published May 21, 2026 Affected Software GSheet For Woo Importer [import-products-from-gsheet-for-woo-importer] Researcher Legion Hunter More Details > Image Photo Gallery Final Tiles Grid <= 3.6.11 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-27424 Patch Status Patched Published May 20, 2026 Affected Software Image Photo Gallery Final Tiles Grid [final-tiles-grid-gallery-lite] Researcher Que Thanh Tuan More Details > JaviBola Custom Theme Test <= 2.0.5 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-8423 Patch Status Unpatched Published May 19, 2026 Affected Software JaviBola Custom Theme Test [javibola-custom-theme] Researcher Muhammad Nur Ibnu Hubab More Details > Location Weather <= 3.0.2 - Missing Authorization to Authenticated (Contributor+) Block Settings Modification and Cache Purging 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-7249 Patch Status Patched Published May 21, 2026 Affected Software Location Weather – WordPress Weather Forecast, AQI, Temperature and Weather Widget [location-weather] Researcher momopon1415 More Details > Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails <= 1.19.5 - Authenticated (Subscriber+) Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-27349 Patch Status Patched Published May 21, 2026 Affected Software Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails [mail-mint] Researcher Que Thanh Tuan More Details > PDF for Elementor Forms + Drag And Drop Template Builder <= 5.5.1 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-45443 Patch Status Patched Published May 20, 2026 Affected Software PDF for Elementor Forms + Drag And Drop Template Builder [pdf-for-elementor-forms] Researcher Nguyen Tran Tuan Dung (domiee13) More Details > Photo Gallery, Sliders, Proofing and Themes <= 4.2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Image Deletion via REST API 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-6566 Patch Status Patched Published May 19, 2026 Affected Software Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] Researcher Bao Luu Gia Nguyen More Details > Remove Yellow BGBOX <= 1.0 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-8424 Patch Status Unpatched Published May 19, 2026 Affected Software Remove Yellow BGBOX [remove-yellow-bgbox] Researcher Muhammad Nur Ibnu Hubab More Details > Slider by Soliloquy <= 2.8.1 - Authenticated (Subscriber+) Information Disclosure via REST API Endpoint 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-7636 Patch Status Patched Published May 21, 2026 Affected Software Slider by Soliloquy – Responsive Image Slider for WordPress [soliloquy-lite] Researcher Kitch More Details > TypeSquare Webfonts for ConoHa <= 2.0.4 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification via 'fontThemeUseType' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-8610 Patch Status Unpatched Published May 19, 2026 Affected Software TypeSquare Webfonts for ConoHa [ts-webfonts-for-conoha] Researchers Van Tho Huynh (l0gs3c) t0ann9uy3n More Details > Vedrixa Forms <= 1.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Structure Modification via wefb_save_form_structure AJAX Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-8692 Patch Status Patched Published May 21, 2026 Affected Software Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder [vedrixa-forms-registration-builder] Researcher Thanh Toan Bui More Details > Widget Context <= 1.3.3 - Cross-Site Request Forgery to Settings Update via 'wl' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-7615 Patch Status Patched Published May 21, 2026 Affected Software Widget Context [widget-context] Researcher darkmode More Details > As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence. This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program , and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can. Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. The post Wordfence Intelligence Weekly WordPress Vulnerability Report (May 18, 2026 to May 24, 2026) appeared first on Wordfence .

Share this article