Security News

Cybersecurity news aggregator

MEDIUM Vulnerabilities Wordfence

Wordfence Intelligence Weekly WordPress Vulnerability Report (June 15, 2026 to June 21, 2026)

  • What: 146 vulnerabilities disclosed in WordPress plugins and themes
  • Impact: WordPress users should review the report to ensure their sites are secure
Read Full Article →

Last week, there were 146 vulnerabilities disclosed in 127 WordPress Plugins and 1 WordPress Theme that have been added to the Wordfence Intelligence Vulnerability Database, and there were 85 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface , vulnerability API , webhook integration , and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back. Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 35,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free . Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. Total Unpatched & Patched Vulnerabilities Last Week Patch Status Number of Vulnerabilities Patched 139 Unpatched 7 Total Vulnerabilities by CVSS Severity Last Week Severity Rating Number of Vulnerabilities Low Severity 1 Medium Severity 90 High Severity 48 Critical Severity 7 Total Vulnerabilities by CWE Type Last Week Vulnerability Type by CWE Number of Vulnerabilities Missing Authorization 36 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 31 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 26 Exposure of Sensitive Information to an Unauthorized Actor 10 Authorization Bypass Through User-Controlled Key 7 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 7 Incorrect Privilege Assignment 5 Cross-Site Request Forgery (CSRF) 3 Deserialization of Untrusted Data 3 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 3 Improper Control of Generation of Code ('Code Injection') 3 Server-Side Request Forgery (SSRF) 3 Unrestricted Upload of File with Dangerous Type 3 Improper Privilege Management 2 Embedded Malicious Code 1 External Control of File Name or Path 1 Incorrect Authorization 1 Weak Password Recovery Mechanism for Forgotten Password 1 Researchers That Contributed to WordPress Security Last Week Researcher Name Number of Vulnerabilities daroo 14 Nguyen Ba Khanh 8 Chloe Chamberland 7 PRISM 7 dodoh4t 6 endy 4 ParkHyunWoo 4 hhhai 4 h0xilo 3 Jakub Herman 3 VanTastic 3 Ananda Dhakal 3 João Pedro S Alcântara (Kinorth) 3 HieuPenguinnn 3 Nguyen Dinh Hai (HaiND) 2 Vincent Sevkli 2 g0wthr 2 Sajjad Haqi 2 Athiwat Tiprasaharn (Jitlada) 2 she11f 2 Bonds 2 Muhammad Arsalan Diponegoro (tripoloski) 2 Pasindu Dilshan (K4PXD) 2 l3m3s 2 d.v4n_s3c 2 Lucius-log 2 Romain Deperne (ang3L) 1 Teerachai Somprasong 1 有馬 龍成 1 Peng Zhou 1 Yaswanth Reddy Sunkara 1 Truong Tran 1 Alvaro Diaz (alvarodh5) 1 s1kr10s 1 wesley (wcraft) 1 Ahmad Marzouk 1 Powpy 1 Nikita Fenko 1 aetta 1 Duc Long 1 Naoya Takahashi (nakko) 1 Jonathan Dersch 1 Sanjorn Keeratirungsan 1 Legion Hunter 1 Mohamed Haidar 1 Koutrouss Naddara 1 Benedictus Jovan (aillesiM) 1 Duc Manh 1 thevietronin 1 minhgalaxy 1 pham quang huy (Zibanana) 1 Ben Tamam (Ben Tamam) 1 Nguyen Ngoc Duc (duc193) 1 Tiago Ventura (perses) 1 Nguyen Quang Truong 1 Mukhlis Amien 1 Craniums 1 qdtad 1 mxym 1 Alexandru Bucur 1 Philipp Doblhofer 1 hivesec 1 Kirasec 1 Yat 1 Dmitrii Ignatyev 1 Andrew Lacambra 1 Umut Can Yurdayardım 1 loris4py 1 Meher Sudhakar Abbireddi 1 dhamdham 1 Austin Ginder 1 Nabil Irawan 1 Thanh Điềm 1 Ossacip Thanh 1 sequence_X0 1 Manopakorn Kooharueangrong (manop55555) 1 zakaria 1 Jack Taylor 1 Tran Nguyen Bao Khanh 1 Expatch 1 kalomba 1 Ali Osman ERBAS (0110m4n) 1 Evan NR 1 dyingman 1 se1en 1 Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program . Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report. WordPress Plugins with Reported Vulnerabilities Last Week Software Name Software Slug 2Download Connector for 2DL Hosted Checkout 2download-connector Abandoned Cart Pro for WooCommerce woocommerce-abandon-cart-pro Abandoned Contact Form 7 abandoned-contact-form-7 Advanced Ads – Ad Manager & AdSense advanced-ads Advanced Import advanced-import Advanced Order Export For WooCommerce woo-order-export-lite Appointment Booking Calendar appointment-booking-calendar Attendance Manager attendance-manager Avada (Fusion) Builder fusion-builder BetterDocs Pro betterdocs-pro BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot betterdocs Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation bit-integrations Blocksy Companion blocksy-companion Bogo bogo Branda – White Label & Branding, Free Login Page Customizer branda-white-labeling Bricksable for Bricks Builder bricksable Cargo Shipping Location for WooCommerce cargo-shipping-location-for-woocommerce CF7 to Webhook cf7-to-zapier CheckView – Form & Checkout Testing checkview Classified Listing – AI-Powered Classified ads & Business Directory classified-listing Clean Login clean-login Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe contest-gallery Cornerstone cornerstone Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress counter-box Creavi Appointment Booking Calendar creavi-booking-service Database for Contact Form 7, WPforms, Elementor forms contact-form-entries Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy dokan-lite E2Pdf – Export Pdf Tool for WordPress e2pdf Enable CORS enable-cors Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More envira-gallery-lite Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance accessibility-checker Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets eventkoi-lite Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) wp-event-solution Falang multilanguage for WordPress falang Fancy Testimonials fancy-testimonials FireBox Popups – Increase Sales and Grow Your Email List firebox Five Star Restaurant Menu and Food Ordering food-and-drink-menu Five Star Restaurant Reservations – WordPress Booking Plugin restaurant-reservations Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder form-maker GEO my WP geo-my-wp GEO Plugin by Squirrly SEO squirrly-seo GeoDirectory – WP Business Directory Plugin and Classified Listings Directory geodirectory GetGenie – AI Content Writer with Keyword Research & SEO Tracking getgenie GIFT4U – Gift Cards All in One for Woo gift4u-gift-cards-all-in-one-for-woo Gutenverse Companion gutenverse-companion Interactive Content – H5P h5p Intranet & Private Site – All-In-One Intranet all-in-one-intranet JetBooking jet-booking JetEngine jet-engine JetFormBuilder — Dynamic Blocks Form Builder jetformbuilder JobSearch WP Job Board wp-jobsearch Kadence Blocks — Page Builder Toolkit for Gutenberg Editor kadence-blocks King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder king-addons LatePoint – Calendar Booking Plugin for Appointments and Events latepoint License Manager for WooCommerce license-manager-for-woocommerce Listdom: AI-powered Business Directory with Classifieds Ads Listings listdom MapPress Maps for WordPress mappress-google-maps-for-wordpress Master Slider – Responsive Touch Slider master-slider MDTF – Meta Data and Taxonomies Filter wp-meta-data-filter-and-taxonomy-filter Media Library Assistant media-library-assistant Melhor Envio melhor-envio-cotacao Motors – Car Dealership & Classified Listings Plugin motors-car-dealership-classified-listings MStore API – Create Native Android & iOS Apps On The Cloud mstore-api Newsletters newsletters-lite Nexi XPay cartasi-x-pay Object Cache 4 everyone object-cache-4-everyone Ocean Product Sharing ocean-product-sharing Offload, AI & Optimize with Cloudflare Images cf-images Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization optimole-wp Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More themeisle-companion Paymob for WooCommerce paymob-for-woocommerce PDF Builder for WooCommerce. Create invoices,packing slips and more woo-pdf-invoice-builder Permalink Manager Lite permalink-manager Pods – Custom Content Types and Fields pods Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred mycred Popup Box – Create Countdown, Coupon, Video, Contact Form Popups ays-popup-box PowerPress Podcasting plugin by Blubrry powerpress Premmerce Dev Tools premmerce-dev-tools Premmerce Wishlist for WooCommerce premmerce-woocommerce-wishlist PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin pressprimer-quiz Quads Ads Manager for Google AdSense quick-adsense-reloaded Registration Form for WooCommerce registration-form-for-woocommerce Royal Addons for Elementor – Addons and Templates Kit for Elementor royal-elementor-addons Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini royal-mcp RTMKit rometheme-for-elementor SALESmanago & Leadoo salesmanago Secure Client Portal and Private File Sharing Plugin – User Private Files user-private-files Services Section Block – Showcase Service Details in Grid or Columns services-section Sigma Forms Pro sigmaforms-pro Simple File List simple-file-list Simple Membership simple-membership Slideshow Gallery LITE slideshow-gallery SlimStat Analytics wp-slimstat SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery sms-alert Static Block static-block STRABL – A checkout solution strabl-a-checkout-solution Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator stylish-cost-calculator SupportCandy – Helpdesk & Customer Support Ticket System supportcandy SureDash – Community, Courses & Member Dashboard suredash Syncee Premium Dropshipping & Wholesale syncee-global-dropshipping SysBasics Customize My Account for WooCommerce – Live My Account Customizer customize-my-account-for-woocommerce Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups trinity-backup Tutor LMS – eLearning and online course solution tutor UPI QR Code Payment Gateway for WooCommerce upi-qr-code-payment-for-woocommerce User Admin Simplifier user-admin-simplifier UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP userswp Video Conferencing with Zoom video-conferencing-with-zoom-api Visual Link Preview visual-link-preview Vitepos – Point of Sale (POS) for WooCommerce vitepos-lite WC Shop Sync – Square Payment Gateway and Product Synchronization for WooCommerce woosquare WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors wc-vendors WCPOS – Point of Sale (POS) plugin for WooCommerce woocommerce-pos Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets widget-options WooCommerce Stripe Payment Gateway woocommerce-gateway-stripe Woosa – Marktplaats for WooCommerce integration-marktplaats-for-woocommerce Workscout Core workscout-core WP Activity Log wp-security-audit-log WP DSGVO Tools (GDPR) shapepress-dsgvo WP Easy Pay – Payment and Donation form Builder for Square wp-easy-pay Wp EMember wp-eMember WP Go Maps – Google Map, OpenStreetMap, Leaflet Map wp-google-maps WP Hotel Booking wp-hotel-booking WP Photo Album Plus wp-photo-album-plus WP Review Slider Pro wp-review-slider-pro WP Travel Gutenberg Blocks wp-travel-blocks wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin wpdatatables YMC Filter ymc-smart-filter WordPress Themes with Reported Vulnerabilities Last Week Software Name Software Slug Real Estate 7 WordPress realestate-7 Vulnerability Details Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration , which is completely free to utilize. BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-7515 Patch Status Patched Published Jun 18, 2026 Affected Software BetterDocs Pro [betterdocs-pro] Researcher Nguyen Ngoc Duc (duc193) More Details > Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-11551 Patch Status Patched Published Jun 19, 2026 Affected Software Branda – White Label & Branding, Free Login Page Customizer [branda-white-labeling] Researchers thevietronin minhgalaxy More Details > Enable CORS <= 2.0.3 - Backdoor 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-54833 Patch Status Patched Published Jun 18, 2026 Affected Software Enable CORS [enable-cors] Researcher Ananda Dhakal More Details > Registration Form for WooCommerce <= 1.0.9 - Unauthenticated Privilege Escalation 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-54807 Patch Status Patched Published Jun 16, 2026 Affected Software Registration Form for WooCommerce [registration-form-for-woocommerce] Researcher ParkHyunWoo More Details > Sigma Forms Pro <= 1.4.5 - Unauthenticated Arbitrary File Upload 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-52705 Patch Status Patched Published Jun 15, 2026 Affected Software Sigma Forms Pro [sigmaforms-pro] Researcher Nguyen Ba Khanh More Details > Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion via Form Entry Value 9.1 CVSS Rating 9.1 (Critical) CVE-ID CVE-2026-8713 Patch Status Patched Published Jun 18, 2026 Affected Software Avada (Fusion) Builder [fusion-builder] Researcher daroo More Details > Workscout Core <= 1.7.11 - Unauthenticated Arbitrary File Deletion 9.1 CVSS Rating 9.1 (Critical) CVE-ID CVE-2026-52716 Patch Status Patched Published Jun 15, 2026 Affected Software Workscout Core [workscout-core] Researcher Nguyen Ba Khanh More Details > Abandoned Cart Pro for WooCommerce <= 10.4.0 - Authenticated (Subscriber+) Privilege Escalation 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-56010 Patch Status Patched Published Jun 19, 2026 Affected Software Abandoned Cart Pro for WooCommerce [woocommerce-abandon-cart-pro] Researcher Austin Ginder More Details > Avada (Fusion) Builder <= 3.15.4 - Authenticated (Contributor+) Privilege Escalation 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-56008 Patch Status Patched Published Jun 18, 2026 Affected Software Avada (Fusion) Builder [fusion-builder] Researcher daroo More Details > Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-12165 Patch Status Patched Published Jun 16, 2026 Affected Software Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe [contest-gallery] Researchers Chloe Chamberland PRISM More Details > E2Pdf <= 1.32.26 - Missing Authorization to Authenticated (Custom+) Arbitrary Option Update / Privilege Escalation via 'screen_action' Parameter 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-12407 Patch Status Patched Published Jun 17, 2026 Affected Software E2Pdf – Export Pdf Tool for WordPress [e2pdf] Researcher endy More Details > Falang multilanguage for WordPress <= 1.4.2 - Authenticated (Subscriber+) Privilege Escalation 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-54805 Patch Status Patched Published Jun 16, 2026 Affected Software Falang multilanguage for WordPress [falang] Researcher ParkHyunWoo More Details > JetFormBuilder — Dynamic Blocks Form Builder <= 3.6.1 - Authenticated (Subscriber+) Privilege Escalation 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-54196 Patch Status Patched Published Jun 16, 2026 Affected Software JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] Researcher Jonathan Dersch More Details > Offload, AI & Optimize with Cloudflare Images <= 1.10.2 - Authenticated (Author+) Remote Code Execution via 'api-key' / 'account-id' Parameters in cf_images_do_setup AJAX Action 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-9860 Patch Status Patched Published Jun 17, 2026 Affected Software Offload, AI & Optimize with Cloudflare Images [cf-images] Researcher Yat More Details > PDF Builder for WooCommerce. Create invoices,packing slips and more <= 2.0.8 - Authenticated (Subscriber+) Remote Code Execution 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-52704 Patch Status Patched Published Jun 15, 2026 Affected Software PDF Builder for WooCommerce. Create invoices,packing slips and more [woo-pdf-invoice-builder] Researcher she11f More Details > Premmerce Dev Tools <= 2.0 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via Plugin Creation 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-6933 Patch Status Unpatched Published Jun 15, 2026 Affected Software Premmerce Dev Tools [premmerce-dev-tools] Researcher Nabil Irawan More Details > Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets <= 4.2.3 - Authenticated (Contributor+) Remote Code Execution 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-54823 Patch Status Patched Published Jun 17, 2026 Affected Software Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] Researcher daroo More Details > WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) SQL Injection via 'curselrevs' Parameter 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-8444 Patch Status Patched Published Jun 15, 2026 Affected Software WP Review Slider Pro [wp-review-slider-pro] Researcher h0xilo More Details > WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) SQL Injection via 'stypes' Parameter 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-8443 Patch Status Patched Published Jun 15, 2026 Affected Software WP Review Slider Pro [wp-review-slider-pro] Researcher h0xilo More Details > Advanced Ads – Ad Manager & AdSense <= 2.0.21 - Authenticated (Contributor+) Remote Code Execution 8.3 CVSS Rating 8.3 (High) CVE-ID CVE-2026-54816 Patch Status Patched Published Jun 17, 2026 Affected Software Advanced Ads – Ad Manager & AdSense [advanced-ads] Researcher Nguyen Ba Khanh More Details > Avada (Fusion) Builder <= 3.15.4 - Authenticated (Contributor+) Arbitrary File Deletion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-54193 Patch Status Patched Published Jun 16, 2026 Affected Software Avada (Fusion) Builder [fusion-builder] Researcher daroo More Details > Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Deletion via CF7 File Field POST Value 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-9843 Patch Status Patched Published Jun 19, 2026 Affected Software Database for Contact Form 7, WPforms, Elementor forms [contact-form-entries] Researcher daroo More Details > MDTF – Meta Data and Taxonomies Filter <= 1.3.8 - Unauthenticated Local File Inclusion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-54845 Patch Status Patched Published Jun 18, 2026 Affected Software MDTF – Meta Data and Taxonomies Filter [wp-meta-data-filter-and-taxonomy-filter] Researcher Ossacip Thanh More Details > WP Activity Log <= 5.6.3.1 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-54806 Patch Status Patched Published Jun 16, 2026 Affected Software WP Activity Log [wp-security-audit-log] Researcher daroo More Details > WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) Arbitrary File Deletion via 'myaction' Parameter 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-8442 Patch Status Patched Published Jun 15, 2026 Affected Software WP Review Slider Pro [wp-review-slider-pro] Researcher h0xilo More Details > Avada (Fusion) Builder <= 3.15.4 - Authenticated (Contributor+) PHP Object Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-54194 Patch Status Patched Published Jun 15, 2026 Affected Software Avada (Fusion) Builder [fusion-builder] Researcher daroo More Details > Cargo Shipping Location for WooCommerce <= 5.6 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-54815 Patch Status Patched Published Jun 17, 2026 Affected Software Cargo Shipping Location for WooCommerce [cargo-shipping-location-for-woocommerce] Researcher Benedictus Jovan (aillesiM) More Details > GEO my WP <= 4.5.5 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-52715 Patch Status Patched Published Jun 15, 2026 Affected Software GEO my WP [geo-my-wp] Researcher Alvaro Diaz (alvarodh5) More Details > GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.162 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-54831 Patch Status Patched Published Jun 17, 2026 Affected Software GeoDirectory – WP Business Directory Plugin and Classified Listings Directory [geodirectory] Researcher Manopakorn Kooharueangrong (manop55555) More Details > GIFT4U – Gift Cards All in One for Woo <= 1.0.10 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-54809 Patch Status Patched Published Jun 17, 2026 Affected Software GIFT4U – Gift Cards All in One for Woo [gift4u-gift-cards-all-in-one-for-woo] Researcher Ali Osman ERBAS (0110m4n) More Details > JetBooking <= 4.0.4.1 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-54820 Patch Status Patched Published Jun 17, 2026 Affected Software JetBooking [jet-booking] Researcher daroo More Details > JetEngine <= 3.8.10.1 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-54187 Patch Status Patched Published Jun 15, 2026 Affected Software JetEngine [jet-engine] Researcher VanTastic More Details > JetEngine <= 3.8.10.1 - Unauthenticated SQL Injection via Listing Grid Load More AJAX Endpoint 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-12360 Patch Status Patched Published Jun 16, 2026 Affected Software JetEngine [jet-engine] Researcher d.v4n_s3c More Details > JobSearch WP Job Board <= 3.2.9 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-54186 Patch Status Patched Published Jun 16, 2026 Affected Software JobSearch WP Job Board [wp-jobsearch] Researcher Nguyen Ba Khanh More Details > LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-8176 Patch Status Patched Published Jun 15, 2026 Affected Software LatePoint – Calendar Booking Plugin for Appointments and Events [latepoint] Researcher d.v4n_s3c More Details > Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 5.4.0 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-54819 Patch Status Patched Published Jun 17, 2026 Affected Software Listdom: AI-powered Business Directory with Classifieds Ads Listings [listdom] Researcher Evan NR More Details > MDTF – Meta Data and Taxonomies Filter <= 1.3.7 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-54843 Patch Status Patched Published Jun 18, 2026 Affected Software MDTF – Meta Data and Taxonomies Filter [wp-meta-data-filter-and-taxonomy-filter] Researcher Nguyen Quang Truong More Details > Motors – Car Dealership & Classified Listings Plugin <= 1.4.109 - Authenticated (Subscriber+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-54814 Patch Status Patched Published Jun 17, 2026 Affected Software Motors – Car Dealership & Classified Listings Plugin [motors-car-dealership-classified-listings] Researcher endy More Details > Motors – Car Dealership & Classified Listings Plugin <= 1.4.109 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-54812 Patch Status Patched Published Jun 17, 2026 Affected Software Motors – Car Dealership & Classified Listings Plugin [motors-car-dealership-classified-listings] Researcher endy More Details > Premmerce Wishlist for WooCommerce <= 1.1.11 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-54849 Patch Status Patched Published Jun 18, 2026 Affected Software Premmerce Wishlist for WooCommerce [premmerce-woocommerce-wishlist] Researcher hhhai More Details > Real Estate 7 WordPress <= 3.5.9 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-54827 Patch Status Patched Published Jun 17, 2026 Affected Software Real Estate 7 WordPress [realestate-7] Researcher João Pedro S Alcântara (Kinorth) More Details > Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-11912 Patch Status Patched Published Jun 19, 2026 Affected Software Simple File List [simple-file-list] Researchers Chloe Chamberland PRISM More Details > Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-11911 Patch Status Patched Published Jun 19, 2026 Affected Software Simple File List [simple-file-list] Researchers Chloe Chamberland PRISM More Details > Wp EMember < v10.9.4 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-54811 Patch Status Patched Published Jun 16, 2026 Affected Software Wp EMember [wp-eMember] Researcher Tran Nguyen Bao Khanh More Details > WP Photo Album Plus <= 9.1.13.005 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-54829 Patch Status Patched Published Jun 17, 2026 Affected Software WP Photo Album Plus [wp-photo-album-plus] Researcher daroo More Details > WP Travel Gutenberg Blocks <= 3.9.4 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-54808 Patch Status Patched Published Jun 17, 2026 Affected Software WP Travel Gutenberg Blocks [wp-travel-blocks] Researcher daroo More Details > wpDataTables (Premium) <= 7.4 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-54825 Patch Status Patched Published Jun 17, 2026 Affected Software wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables] Researcher Expatch More Details > YMC Filter <= 3.11.5 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-54836 Patch Status Patched Published Jun 18, 2026 Affected Software YMC Filter [ymc-smart-filter] Researcher Nguyen Ba Khanh More Details > CF7 to Webhook <= 5.0.0 - Unauthenticated Server-Side Request Forgery via CF7 Field Placeholder in Webhook URL Host 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-11395 Patch Status Patched Published Jun 17, 2026 Affected Software CF7 to Webhook [cf7-to-zapier] Researcher Lucius-log More Details > JetEngine <= 3.8.10 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-54189 Patch Status Patched Published Jun 16, 2026 Affected Software JetEngine [jet-engine] Researcher VanTastic More Details > JetEngine <= 3.8.10 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-54188 Patch Status Patched Published Jun 16, 2026 Affected Software JetEngine [jet-engine] Researcher VanTastic More Details > JetFormBuilder — Dynamic Blocks Form Builder <= 3.6.0.1 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-54195 Patch Status Patched Published Jun 16, 2026 Affected Software JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] Researcher daroo More Details > MapPress Maps for WordPress <= 2.97.3 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-56011 Patch Status Patched Published Jun 19, 2026 Affected Software MapPress Maps for WordPress [mappress-google-maps-for-wordpress] Researcher l3m3s More Details > Master Slider – Responsive Touch Slider <= 3.11.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-56014 Patch Status Unpatched Published Jun 19, 2026 Affected Software Master Slider – Responsive Touch Slider [master-slider] Researcher João Pedro S Alcântara (Kinorth) More Details > Pods – Custom Content Types and Fields <= 3.3.8 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-54191 Patch Status Patched Published Jun 15, 2026 Affected Software Pods – Custom Content Types and Fields [pods] Researcher Bonds More Details > Counter Box <= 2.0.13 - Authenticated (Administrator+) PHP Object Injection via Import 6.6 CVSS Rating 6.6 (Medium) CVE-ID CVE-2026-12115 Patch Status Patched Published Jun 16, 2026 Affected Software Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress [counter-box] Researcher Duc Long More Details > Attendance Manager <= 0.6.2 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-52712 Patch Status Patched Published Jun 15, 2026 Affected Software Attendance Manager [attendance-manager] Researcher daroo More Details > Bit integrations <= 2.8.7 - Unauthenticated Server-Side Request Forgery via Form Field Upload Mapping 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-11989 Patch Status Patched Published Jun 18, 2026 Affected Software Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation [bit-integrations] Researcher Lucius-log More Details > Cornerstone < 7.8.8 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-54185 Patch Status Patched Published Jun 16, 2026 Affected Software Cornerstone [cornerstone] Researcher Nguyen Ba Khanh More Details > Media Library Assistant <= 3.35 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-56012 Patch Status Patched Published Jun 18, 2026 Affected Software Media Library Assistant [media-library-assistant] Researcher daroo More Details > Royal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1058 - 1.7.1059 - Authenticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File Source 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-8118 Patch Status Patched Published Jun 18, 2026 Affected Software Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] Researcher Jack Taylor More Details > RTMKit <= 2.0.7 - Authenticated (Contributor+) Missing Authorization to Arbitrary Form Submission Access via 'entries_id' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-5149 Patch Status Patched Published Jun 15, 2026 Affected Software RTMKit [rometheme-for-elementor] Researcher wesley (wcraft) More Details > SALESmanago & Leadoo <= 3.11.2 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-54822 Patch Status Patched Published Jun 17, 2026 Affected Software SALESmanago & Leadoo [salesmanago] Researcher endy More Details > Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-12119 Patch Status Patched Published Jun 19, 2026 Affected Software Simple File List [simple-file-list] Researchers Chloe Chamberland PRISM More Details > SlimStat Analytics <= 5.4.11 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-54818 Patch Status Patched Published Jun 17, 2026 Affected Software SlimStat Analytics [wp-slimstat] Researcher hhhai More Details > SureDash – Community, Courses & Member Dashboard <= 1.8.0 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-54813 Patch Status Patched Published Jun 17, 2026 Affected Software SureDash – Community, Courses & Member Dashboard [suredash] Researcher dodoh4t More Details > WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors <= 2.6.8 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-54838 Patch Status Patched Published Jun 18, 2026 Affected Software WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors [wc-vendors] Researcher hhhai More Details > WooCommerce Stripe Payment Gateway <= 10.7.0 - Missing Authorization to Unauthenticated Order Status Manipulation via 'order' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-2381 Patch Status Patched Published Jun 15, 2026 Affected Software WooCommerce Stripe Payment Gateway [woocommerce-gateway-stripe] Researcher Dmitrii Ignatyev More Details > Advanced Import: One-Click Demo Import for WordPress <= 1.4.6 - Authenticated (Author+) Server-Side Request Forgery via 'demo_file' Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4328 Patch Status Patched Published Jun 18, 2026 Affected Software Advanced Import [advanced-import] Researcher loris4py More Details > Appointment Booking Calendar <= 1.4.4 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Booking Field Label 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-1856 Patch Status Patched Published Jun 18, 2026 Affected Software Creavi Appointment Booking Calendar [creavi-booking-service] Researchers Athiwat Tiprasaharn (Jitlada) Powpy More Details > BetterDocs <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'blockId' Block Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-12157 Patch Status Patched Published Jun 18, 2026 Affected Software BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot [betterdocs] Researcher Craniums More Details > Bricksable for Bricks Builder <= 1.6.83 - Authenticated (Author+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-56009 Patch Status Patched Published Jun 18, 2026 Affected Software Bricksable for Bricks Builder [bricksable] Researcher Ananda Dhakal More Details > Fancy Testimonials <= 1.0 - Authenticated (Author+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-8039 Patch Status Unpatched Published Jun 17, 2026 Affected Software Fancy Testimonials [fancy-testimonials] Researcher zakaria More Details > File Sharing & Download Manager <= 2.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'fldr_ttl' Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-10093 Patch Status Patched Published Jun 15, 2026 Affected Software Secure Client Portal and Private File Sharing Plugin – User Private Files [user-private-files] Researcher pham quang huy (Zibanana) More Details > King Addons for Elementor <= 51.1.62 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'form_page_id' Parameter 6.4 CVSS Rating 6.4 (Medium) Patch Status Patched Published Jun 15, 2026 Affected Software King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder [king-addons] Researcher Naoya Takahashi (nakko) More Details > myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrap' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-8607 Patch Status Patched Published Jun 16, 2026 Affected Software Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred [mycred] Researcher Romain Deperne (ang3L) More Details > Permalink Manager Lite <= 2.5.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-8494 Patch Status Patched Published Jun 16, 2026 Affected Software Permalink Manager Lite [permalink-manager] Researcher Ahmad Marzouk More Details > PowerPress Podcasting plugin by Blubrry <= 11.16.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'embed' Episode Meta Field 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-12098 Patch Status Patched Published Jun 17, 2026 Affected Software PowerPress Podcasting plugin by Blubrry [powerpress] Researcher Mukhlis Amien More Details > Services Section Block <= 1.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Block Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-11402 Patch Status Patched Published Jun 17, 2026 Affected Software Services Section Block – Showcase Service Details in Grid or Columns [services-section] Researcher Philipp Doblhofer More Details > Slideshow Gallery LITE <= 1.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'alwaysauto' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-2021 Patch Status Patched Published Jun 17, 2026 Affected Software Slideshow Gallery LITE [slideshow-gallery] Researcher Athiwat Tiprasaharn (Jitlada) More Details > SysBasics Customize My Account for WooCommerce <= 4.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-12136 Patch Status Patched Published Jun 17, 2026 Affected Software SysBasics Customize My Account for WooCommerce – Live My Account Customizer [customize-my-account-for-woocommerce] Researchers Chloe Chamberland PRISM More Details > WP Activity Log <= 5.6.3.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-56005 Patch Status Patched Published Jun 19, 2026 Affected Software WP Activity Log [wp-security-audit-log] Researcher daroo More Details > Interactive Content – H5P <= 1.17.6 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-56006 Patch Status Patched Published Jun 18, 2026 Affected Software Interactive Content – H5P [h5p] Researcher Koutrouss Naddara More Details > Media Library Assistant <= 3.35 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-54198 Patch Status Patched Published Jun 15, 2026 Affected Software Media Library Assistant [media-library-assistant] Researcher Bonds More Details > Popup Box – Create Countdown, Coupon, Video, Contact Form Popups <= 6.2.9 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-54192 Patch Status Patched Published Jun 16, 2026 Affected Software Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] Researcher João Pedro S Alcântara (Kinorth) More Details > SysBasics Customize My Account for WooCommerce <= 4.3.6 - Reflected Cross-Site Scripting via 'tab' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-12137 Patch Status Patched Published Jun 17, 2026 Affected Software SysBasics Customize My Account for WooCommerce – Live My Account Customizer [customize-my-account-for-woocommerce] Researchers Chloe Chamberland PRISM More Details > 2Download Connector for 2DL Hosted Checkout <= 0.1.5 - Missing Authorization to Unauthenticated Sensitive Customer Subscription Data Exposure via 'ToDownload_email' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-6798 Patch Status Patched Published Jun 18, 2026 Affected Software 2Download Connector for 2DL Hosted Checkout [2download-connector] Researcher Mohamed Haidar More Details > Abandoned Contact Form 7 <= 2.2 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'recover_id' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-9187 Patch Status Unpatched Published Jun 15, 2026 Affected Software Abandoned Contact Form 7 [abandoned-contact-form-7] Researcher g0wthr More Details > CheckView – Form & Checkout Testing <= 2.1.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54844 Patch Status Patched Published Jun 19, 2026 Affected Software CheckView – Form & Checkout Testing [checkview] Researcher sequence_X0 More Details > Clean Login <= 1.15 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54184 Patch Status Patched Published Jun 16, 2026 Affected Software Clean Login [clean-login] Researcher Jakub Herman More Details > Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More <= 1.12.5 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54190 Patch Status Patched Published Jun 15, 2026 Affected Software Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More [envira-gallery-lite] Researcher Tiago Ventura (perses) More Details > Event Koi Lite <= 1.3.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via REST API Endpoints 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-10029 Patch Status Patched Published Jun 17, 2026 Affected Software Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets [eventkoi-lite] Researcher Umut Can Yurdayardım More Details > Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) <= 4.1.12 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2025-68045 Patch Status Patched Published Jun 15, 2026 Affected Software Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) [wp-event-solution] Researcher l3m3s More Details > FireBox Popups <= 3.1.7 - Unauthenticated Sensitive Information Exposure in 'form_id' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-12120 Patch Status Patched Published Jun 17, 2026 Affected Software FireBox Popups – Increase Sales and Grow Your Email List [firebox] Researcher Duc Manh More Details > Five Star Restaurant Menu and Food Ordering <= 2.5.2 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54835 Patch Status Patched Published Jun 18, 2026 Affected Software Five Star Restaurant Menu and Food Ordering [food-and-drink-menu] Researcher Vincent Sevkli More Details > Five Star Restaurant Reservations – WordPress Booking Plugin <= 2.7.19 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54830 Patch Status Patched Published Jun 17, 2026 Affected Software Five Star Restaurant Reservations – WordPress Booking Plugin [restaurant-reservations] Researcher Vincent Sevkli More Details > GEO Plugin by Squirrly SEO <= 12.4.16 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-52714 Patch Status Patched Published Jun 15, 2026 Affected Software GEO Plugin by Squirrly SEO [squirrly-seo] Researcher Nguyen Ba Khanh More Details > GetGenie – AI Content Writer with Keyword Research & SEO Tracking <= 4.4.1 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54197 Patch Status Patched Published Jun 15, 2026 Affected Software GetGenie – AI Content Writer with Keyword Research & SEO Tracking [getgenie] Researcher hhhai More Details > Gutenverse Companion <= 2.5.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54832 Patch Status Patched Published Jun 17, 2026 Affected Software Gutenverse Companion [gutenverse-companion] Researcher mxym More Details > Intranet & Private Site – All-In-One Intranet <= 1.8.1 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54837 Patch Status Patched Published Jun 18, 2026 Affected Software Intranet & Private Site – All-In-One Intranet [all-in-one-intranet] Researcher dodoh4t More Details > License Manager for WooCommerce <= 3.0.15 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-56013 Patch Status Patched Published Jun 19, 2026 Affected Software License Manager for WooCommerce [license-manager-for-woocommerce] Researcher dodoh4t More Details > Motors – Car Dealership & Classified Listings Plugin <= 1.4.109 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54828 Patch Status Patched Published Jun 17, 2026 Affected Software Motors – Car Dealership & Classified Listings Plugin [motors-car-dealership-classified-listings] Researcher Nguyen Dinh Hai (HaiND) More Details > MStore API – Create Native Android & iOS Apps On The Cloud <= 4.18.4 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54817 Patch Status Patched Published Jun 17, 2026 Affected Software MStore API – Create Native Android & iOS Apps On The Cloud [mstore-api] Researcher Jakub Herman More Details > Newsletters <= 4.13 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54840 Patch Status Patched Published Jun 18, 2026 Affected Software Newsletters [newsletters-lite] Researcher HieuPenguinnn More Details > Nexi XPay <= 8.3.1 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54810 Patch Status Patched Published Jun 17, 2026 Affected Software Nexi XPay [cartasi-x-pay] Researcher hivesec More Details > Object Cache 4 everyone <= 2.3.2 - Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54834 Patch Status Patched Published Jun 17, 2026 Affected Software Object Cache 4 everyone [object-cache-4-everyone] Researcher dodoh4t More Details > Paymob for WooCommerce <= 4.1.2 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-56025 Patch Status Unpatched Published Jun 19, 2026 Affected Software Paymob for WooCommerce [paymob-for-woocommerce] Researcher Sajjad Haqi More Details > Quads Ads Manager for Google AdSense <= 3.0.3 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54824 Patch Status Patched Published Jun 17, 2026 Affected Software Quads Ads Manager for Google AdSense [quick-adsense-reloaded] Researcher Nguyen Dinh Hai (HaiND) More Details > Simple Membership <= 4.7.5 - Missing Authorization to Unauthenticated Arbitrary Member Account Deactivation via Forged Stripe 'charge.refunded' Webhook 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-12093 Patch Status Patched Published Jun 17, 2026 Affected Software Simple Membership [simple-membership] Researcher Nikita Fenko More Details > SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery <= 3.9.3 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54802 Patch Status Patched Published Jun 16, 2026 Affected Software SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery [sms-alert] Researcher Jakub Herman More Details > STRABL <= 4.5 - Unauthenticated Arbitrary Webhook Creation via REST API Endpoint 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-3640 Patch Status Patched Published Jun 18, 2026 Affected Software STRABL – A checkout solution [strabl-a-checkout-solution] Researcher Teerachai Somprasong More Details > Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator <= 8.3.9 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54847 Patch Status Patched Published Jun 18, 2026 Affected Software Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator [stylish-cost-calculator] Researcher ParkHyunWoo More Details > Syncee Premium Dropshipping & Wholesale <= 1.0.27 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54846 Patch Status Patched Published Jun 18, 2026 Affected Software Syncee Premium Dropshipping & Wholesale [syncee-global-dropshipping] Researcher dodoh4t More Details > Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups <= 2.0.9 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54839 Patch Status Patched Published Jun 18, 2026 Affected Software Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups [trinity-backup] Researcher dodoh4t More Details > Video Conferencing with Zoom <= 4.6.7 - Missing Authorization to Unauthenticated Zoom SDK Credential Exposure via 'get_auth' AJAX Action 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-6964 Patch Status Patched Published Jun 15, 2026 Affected Software Video Conferencing with Zoom [video-conferencing-with-zoom-api] Researcher aetta More Details > Vitepos – Point of Sale (POS) for WooCommerce <= 3.4.2 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54841 Patch Status Patched Published Jun 18, 2026 Affected Software Vitepos – Point of Sale (POS) for WooCommerce [vitepos-lite] Researcher qdtad More Details > WC Shop Sync – Square Payment Gateway and Product Synchronization for WooCommerce <= 4.7.3 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-54848 Patch Status Patched Published Jun 18, 2026 Affected Software WC Shop Sync – Square Payment Gateway and Product Synchronization for WooCommerce [woosquare] Researcher Peng Zhou More Details > WCPOS – Point of Sale (POS) plugin for WooCommerce <= 1.8.14 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-52711 Patch Status Patched Published Jun 15, 2026 Affected Software WCPOS – Point of Sale (POS) plugin for WooCommerce [woocommerce-pos] Researcher Nguyen Ba Khanh More Details > WP DSGVO Tools (GDPR) <= 3.1.39 - Missing Authorization to Unauthenticated Sensitive Personal Data Disclosure via subject-access-request AJAX Endpoint (process_now/is_ajax Parameters) 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-10034 Patch Status Patched Published Jun 18, 2026 Affected Software WP DSGVO Tools (GDPR) [shapepress-dsgvo] Researcher kalomba More Details > WP Go Maps <= 10.1.01 - Unauthenticated Arbitrary Record Creation 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-12238 Patch Status Patched Published Jun 19, 2026 Affected Software WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] Researcher Thanh Điềm More Details > Advanced Order Export For WooCommerce <= 4.0.10 - Authenticated (Shop Manager+) SQL Injection via 'sort_direction' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-11360 Patch Status Patched Published Jun 17, 2026 Affected Software Advanced Order Export For WooCommerce [woo-order-export-lite] Researcher Yaswanth Reddy Sunkara More Details > Form Maker by 10Web <= 1.15.43 - Authenticated (Administrator+) SQL Injection via 'name' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-11777 Patch Status Patched Published Jun 17, 2026 Affected Software Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] Researcher Muhammad Arsalan Diponegoro (tripoloski) More Details > Form Maker by 10Web <= 1.15.43 - Authenticated (Adminsitrator+) SQL Injection via 'groupids' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-11776 Patch Status Patched Published Jun 17, 2026 Affected Software Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] Researcher Muhammad Arsalan Diponegoro (tripoloski) More Details > Tutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-10736 Patch Status Patched Published Jun 17, 2026 Affected Software Tutor LMS – eLearning and online course solution [tutor] Researcher s1kr10s More Details > Woosa <= 2.0.5 - Authenticated (Administrator+) Arbitrary File Read via 'log_file' Parameter 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-7547 Patch Status Patched Published Jun 18, 2026 Affected Software Woosa – Marktplaats for WooCommerce [integration-marktplaats-for-woocommerce] Researcher Legion Hunter More Details > Blocksy Companion <= 2.1.45 - Authenticated (Editor+) Stored Cross-Site Scripting via 'product_description' Parameter 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-12430 Patch Status Patched Published Jun 18, 2026 Affected Software Blocksy Companion [blocksy-companion] Researcher Pasindu Dilshan (K4PXD) More Details > Ocean Product Sharing <= 2.2.2 - Authenticated (Shop manager+) Stored Cross-Site Scripting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-56007 Patch Status Patched Published Jun 18, 2026 Affected Software Ocean Product Sharing [ocean-product-sharing] Researcher Ananda Dhakal More Details > Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More <= 3.0.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu-item-icon' Parameter 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-11358 Patch Status Patched Published Jun 17, 2026 Affected Software Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] Researcher Meher Sudhakar Abbireddi More Details > Appointment Booking Calendar <= 1.4.01 - Authenticated (Contributor+) Sensitive Information Exposure via 'id' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-12111 Patch Status Patched Published Jun 17, 2026 Affected Software Appointment Booking Calendar [appointment-booking-calendar] Researchers Chloe Chamberland PRISM More Details > Bogo <= 3.9.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via REST API 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9013 Patch Status Patched Published Jun 18, 2026 Affected Software Bogo [bogo] Researcher Andrew Lacambra More Details > Classified Listing <= 5.4.2 - Missing Authorization to Authenticated (Subscriber+) Feature Modification via Multiple AJAX Handlers ('listingId'/'id' Parameters) 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-10779 Patch Status Patched Published Jun 18, 2026 Affected Software Classified Listing – AI-Powered Classified ads & Business Directory [classified-listing] Researcher Ben Tamam (Ben Tamam) More Details > Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.3 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modification via Multiple AJAX Handlers 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-10023 Patch Status Patched Published Jun 17, 2026 Affected Software Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] Researcher Kirasec More Details > Equalize Digital Accessibility Checker <= 1.42.1 - Missing Authorization to Authenticated (Author+) Arbitrary Accessibility Issue Modification via 'largeBatch' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9199 Patch Status Patched Published Jun 17, 2026 Affected Software Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance [accessibility-checker] Researcher g0wthr More Details > Kadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData Localization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-11357 Patch Status Patched Published Jun 17, 2026 Affected Software Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] Researcher se1en More Details > Melhor Envio <= 2.16.3 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-54804 Patch Status Patched Published Jun 16, 2026 Affected Software Melhor Envio [melhor-envio-cotacao] Researcher HieuPenguinnn More Details > Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.6 - Cross-Site Request Forgery via 'optml_replace_file' AJAX Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-11784 Patch Status Patched Published Jun 17, 2026 Affected Software Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization [optimole-wp] Researcher Alexandru Bucur More Details > PressPrimer Quiz <= 2.3.0 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Modification via 'quiz_id', 'item_id', and 'rule_id' Parameters 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-10623 Patch Status Patched Published Jun 17, 2026 Affected Software PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin [pressprimer-quiz] Researcher Truong Tran More Details > Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini <= 1.4.25 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-54842 Patch Status Patched Published Jun 18, 2026 Affected Software Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini [royal-mcp] Researcher dhamdham More Details > Static Block <= 2.2 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via Shortcode 'id' Attribute 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-10780 Patch Status Unpatched Published Jun 15, 2026 Affected Software Static Block [static-block] Researcher dyingman More Details > SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.6 - Authenticated (Subscriber+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-54826 Patch Status Patched Published Jun 17, 2026 Affected Software SupportCandy – Helpdesk & Customer Support Ticket System [supportcandy] Researcher HieuPenguinnn More Details > UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-56023 Patch Status Patched Published Jun 19, 2026 Affected Software UPI QR Code Payment Gateway for WooCommerce [upi-qr-code-payment-for-woocommerce] Researcher ParkHyunWoo More Details > User Admin Simplifier <= 3.0.0 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-11775 Patch Status Patched Published Jun 18, 2026 Affected Software User Admin Simplifier [user-admin-simplifier] Researcher 有馬 龍成 More Details > Visual Link Preview <= 2.3.1 - Authenticated (Subscriber+) Sensitive Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-54821 Patch Status Patched Published Jun 17, 2026 Affected Software Visual Link Preview [visual-link-preview] Researcher she11f More Details > WP Easy Pay – Payment and Donation form Builder for Square <= 4.5.0 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-56024 Patch Status Unpatched Published Jun 18, 2026 Affected Software WP Easy Pay – Payment and Donation form Builder for Square [wp-easy-pay] Researcher Sajjad Haqi More Details > WP Hotel Booking < 2.3.1 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9822 Patch Status Patched Published Jun 19, 2026 Affected Software WP Hotel Booking [wp-hotel-booking] Researcher Sanjorn Keeratirungsan More Details > UsersWP <= 1.2.63 - Insecure Direct Object Reference to Authenticated (Editor+) Arbitrary User Avatar/Banner Reset via 'user_id' Parameter 2.7 CVSS Rating 2.7 (Low) CVE-ID CVE-2026-12102 Patch Status Patched Published Jun 17, 2026 Affected Software UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP [userswp] Researcher Pasindu Dilshan (K4PXD) More Details > As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence. This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program , and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can. Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. The post Wordfence Intelligence Weekly WordPress Vulnerability Report (June 15, 2026 to June 21, 2026) appeared first on Wordfence .

Share this article