Security News

Cybersecurity news aggregator

LOW Vulnerabilities Wordfence

Wordfence Intelligence Weekly WordPress Vulnerability Report (June 22, 2026 to June 28, 2026)

  • What: Weekly report on WordPress vulnerabilities
  • Impact: WordPress users may be affected by 199 disclosed vulnerabilities in plugins and themes
Read Full Article →

Last week, there were 199 vulnerabilities disclosed in 169 WordPress Plugins and 9 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 111 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface , vulnerability API , webhook integration , and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back. Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 35,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free . Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. New Firewall Rules Deployed Last Week The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection. The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium , Care , and Response customers last week: OMGF Pro <= 5.2.6 – Unauthenticated Arbitrary File Upload via @import URL Reflection WAF-RULE-917 – Data redacted while we work with the vendor on a patch. WAF-RULE-918 – Data redacted while we work with the vendor on a patch. WAF-RULE-919 – Data redacted while we work with the vendor on a patch. WAF-RULE-922 – Data redacted while we work with the vendor on a patch. Wordfence Premium , Care , and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay. Total Unpatched & Patched Vulnerabilities Last Week Patch Status Number of Vulnerabilities Patched 148 Unpatched 51 Total Vulnerabilities by CVSS Severity Last Week Severity Rating Number of Vulnerabilities Low Severity 1 Medium Severity 143 High Severity 49 Critical Severity 6 Total Vulnerabilities by CWE Type Last Week Vulnerability Type by CWE Number of Vulnerabilities Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 53 Missing Authorization 52 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 29 Cross-Site Request Forgery (CSRF) 15 Exposure of Sensitive Information to an Unauthorized Actor 9 Authorization Bypass Through User-Controlled Key 8 Deserialization of Untrusted Data 6 Server-Side Request Forgery (SSRF) 5 Unrestricted Upload of File with Dangerous Type 5 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 3 Improper Control of Generation of Code ('Code Injection') 3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 3 Incorrect Privilege Assignment 3 Weak Password Recovery Mechanism for Forgotten Password 2 External Control of File Name or Path 1 Improper Privilege Management 1 Insufficient Verification of Data Authenticity 1 Researchers That Contributed to WordPress Security Last Week Researcher Name Number of Vulnerabilities Ananda Dhakal 14 daroo 11 Nguyen Ba Khanh 6 PRISM 6 João Pedro S Alcântara (Kinorth) 6 ParkHyunWoo 5 Jakub Herman 5 Nabil Irawan 5 VanTastic 5 Bonds 4 jamaal 4 Muhammad Yudha - DJ 4 Legion Hunter 4 Eason 3 Chloe Chamberland 3 Benedictus Jovan (aillesiM) 3 Abdulsamad Yusuf (0xVenus) 3 Alyudin Nafiie 3 Jonathan Dersch 2 Muhammad Nur Ibnu Hubab 2 hivesec 2 Nguyen Quang Truong 2 theviper17y 2 swat 2 William Matos 2 Austin Ginder 2 dutafi 2 lb 2 Md. Minaruzzaman Shovon 2 hhhai 2 Real_King_Engine 2 g0wthr 2 Averon Averenkov 2 zakaria 2 Rafie Muhammad 1 Viet Anh Ngo 1 Huazu Jiang (anjhz0318) 1 Ali Osman ERBAS (0110m4n) 1 vnth4nhnt 1 0xHerc 1 Trương Hữu Phúc (truonghuuphuc) 1 Rafael Gunawan (kokon) 1 hackthesoul 1 nobody09 1 Benedictus Jovan (aillesim/eneri) 1 Enes Ismail 1 TRAN THE LONG 1 Denver Jackson 1 Jonah Burgess (CryptoCat) 1 dyingman 1 Weerawat Pawanawiwat (ErbaZZ) 1 Abu Hurayra 1 Bao - BlueRock 1 timomangcut 1 sorawautsukushiii 1 Mohamad Nour Almujarkesh 1 Jarno Vos (jrn5151) 1 haitam_lz 1 ilinor 1 Dmitrii Ignatyev 1 Nguyen Ngoc Duc (duc193) 1 NETZLICHT 1 Haitam Lazaar 1 SHIVAM KUMAR 1 Juthawong Naisanguansee 1 Fraudless 1 Mustafa 1 MD ISMAIL 1 endy 1 adhikara13 1 Mokksh Parekh 1 Mustafa Ahmed 1 lhking 1 Kamil Królikowski 1 theviper17 1 Prodigysec 1 Catalin Oancea (0x4D5A) 1 Jamaal ahmed 1 Psalms Christopher Matovu (ByteOverride) 1 tiborisaak 1 Supakiad S. (m3ez) 1 Drew Webber (mcdruid) 1 Tran Nguyen Bao Khanh 1 Aurélien BOURDOIS (Elymaro) 1 Meher Sudhakar Abbireddi 1 Nguyen Dinh Hai (HaiND) 1 Shashank 1 h0xilo 1 Alexander Jurkschat 1 zedeq 1 MD Shariful Islam 1 qdtad 1 Tarcísio Luchesi(Poystick) 1 Netwurm 1 momopon1415 1 Phat RiO 1 L4m 1 Gilang - DJ 1 Hardik Patel 1 Mateo Contenla & Matías Schiappacasse 1 anhcd05 1 Steven Julian 1 valent1 1 nishida azuka 1 dodoh4t 1 Osvaldo Noe Gonzalez Del Rio (Os) 1 bekitousei 1 Doan Dinh Van 1 R4mbb 1 R4m bb 1 lagi bljr 1 Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program . Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report. WordPress Plugins with Reported Vulnerabilities Last Week Software Name Software Slug 24liveblog – live blog tool 24liveblog Abandoned Cart Lite for WooCommerce woocommerce-abandoned-cart AdRotate Banner Manager adrotate Advance Nav Menu Manager advance-nav-menu-manager Advance Product Search- Voice & Ajax Search for WooCommerce th-advance-product-search Advanced Contact Form 7 – Compact DB advanced-contact-form-7-compact-db Advanced Order Export For WooCommerce woo-order-export-lite Affiliates Manager affiliates-manager AI Share & Summarize ai-share-summarize Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments ARforms arforms Assistio assistio Auros Core auros-core Avalon23 Products Filter for WooCommerce avalon23-products-filter-for-woocommerce BitFire Security – Firewall, Malware Scanner, Bot Blocker, Login Protection bitfire Block for Mailchimp – Add Email Subscription Forms and Collect Leads block-for-mailchimp Blocksy Companion Pro blocksy-companion-pro Blog2Social: Social Media Auto Post & Scheduler blog2social Blue Captcha blue-captcha BNE Testimonials bne-testimonials Book a Room Event Calendar book-a-room-event-calendar Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment booking-and-rental-manager-for-woocommerce BookPro - Appointment Booking WordPress Plugin ovabookpro Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools woocommerce-jetpack Bopo – WooCommerce Product Bundle Builder bopo-woo-product-bundle-builder BuddyBoss Platform buddyboss-platform Bulk SEO Image bulk-seo-image Child Theme Wizard child-theme-wizard Cincopa video and media plug-in video-playlist-and-gallery-plugin ClearSale Total clearsale-total CodePeople Post Map for Google Maps codepeople-post-map Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe contest-gallery Cornerstone cornerstone CorvusPay WooCommerce Payment Gateway corvuspay-woocommerce-integration Customer Reviews for WooCommerce customer-reviews-woocommerce Devs Accounting – Simple Accounting and Invoicing Solution devs-accounting Dokan Pro dokan-pro Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy dokan-lite Donation Thermometer donation-thermometer Eagle Booking eagle-booking Elementor Website Builder – more than just a page builder elementor Email JavaScript Cloak email-javascript-cloaker Email Marketing for WooCommerce by Omnisend omnisend-connect EntreDroppers entredropper EventPrime – Events Calendar, Bookings and Tickets eventprime-event-calendar-management Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI everest-forms Exclusive Addons for Elementor exclusive-addons-for-elementor Featured Image featured-image Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution fluent-booking Forget About Shortcode Buttons forget-about-shortcode-buttons Forminator Forms – Contact Form, Payment Form & Custom Form Builder forminator FOX – Currency Switcher Professional for WooCommerce woocommerce-currency-switcher Frisbii Pay reepay-checkout-gateway Frontend File Manager Plugin nmedia-user-file-uploader FunnelKit Payment Gateway for Stripe WooCommerce funnelkit-stripe-woo-payment-gateway FunnelKit – Funnel Builder for WooCommerce Checkout funnel-builder Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress gallery-plugin Generate Security.txt generate-security-txt GetGenie – AI Content Writer with Keyword Research & SEO Tracking getgenie Ghost Kit – Page Builder Blocks, Motion Effects & Extensions ghostkit GIFT4U – Gift Cards All in One for Woo gift4u-gift-cards-all-in-one-for-woo Gmail SMTP gmail-smtp Goya Core goya-core Gravity Bookings gf-bookings-premium GravityView gravityview Groundhogg — CRM, Newsletters, and Marketing Automation groundhogg Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns essential-blocks Gutenverse Form – Contact Form Builder, Block Form & Booking Form gutenverse-form Gutenverse – WordPress Blocks, Page Builder & Site Editor gutenverse HD Quiz hd-quiz Hester Core hester-core HTML5 Video Player – Embed and Play Videos in Custom Player html5-video-player Image Carousel image-carousel Image Sizes on Demand image-sizes-on-demand Infility Global infility-global Interactive Content – H5P h5p Invoice Generator invoice-creator Ivory Search – WordPress Search Plugin add-search-to-menu JetEngine jet-engine JetSmartFilters jet-smart-filters JS Help Desk – AI-Powered Support & Ticketing System js-support-ticket Kargo Takip kargo-takip Kirki – Freeform Page Builder, Website Builder & Customizer kirki Library Management System library-management-system Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator live-copy-paste Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid magazine-blocks MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites mainwp-child Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin majestic-support Masteriyo LMS – LMS Course Builder, Quizzes & Certificates learning-management-system MasterStudy LMS WordPress Plugin – for Online Courses and Education masterstudy-lms-learning-management-system MaxButtons – Create buttons maxbuttons MIR blocks and shortcodes mir-blocks-and-shortcodes MotorDesk motordesk Motors – Car Dealership & Classified Listings Plugin motors-car-dealership-classified-listings MP Customize Login Page mp-customize-login-page Nelio Content – Editorial Calendar & Social Media Auto-Posting nelio-content Newsletters newsletters-lite NEX-Forms – Ultimate Forms Plugin for WordPress nex-forms-express-wp-form-builder OMGF Pro host-google-fonts-pro Osiris Signature Banner osiris-signature-banner Page Builder by SiteOrigin siteorigin-panels Paid Memberships Pro - Add Member From Admin pmpro-add-member-admin Panorama – 360 degree Virtual Tour, Panoramic Image viewer and More panorama Payment Gateway Based Fees and Discounts for WooCommerce checkout-fees-for-woocommerce Paytium: Mollie payment forms & donations paytium Perfmatters perfmatters Pie Register – User Registration, Profiles & Content Restriction pie-register Popup Box – Create Countdown, Coupon, Video, Contact Form Popups ays-popup-box Post Duplicator post-duplicator Post Snippets – Custom WordPress Code Snippets Customizer post-snippets PPOM – Product Addons & Custom Fields for WooCommerce woocommerce-product-addon PPWP – Password Protect Pages password-protect-page Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes Product Specifications for Woocommerce product-specifications ProfileGrid – User Profiles, Groups and Communities profilegrid-user-profiles-groups-and-communities Quform - WordPress Form Builder quform Quick Interest Slider quick-interest-slider Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker quiz-master-next Quotes llama quotes-llama Recipe Cards For Your Food Blog from Zip Recipes zip-recipes RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login custom-registration-form-builder-with-submission-manager RentMy Real-Time Rental Management Plugin rentmy-online-rental-shop Responsive Lightbox & Gallery responsive-lightbox Restaurant Menu and Food Ordering mp-restaurant-menu Reviews and Rating – Docplanner reviews-and-rating-docplanner SearchPlus searchplus Secufor_OAuth wpoauth SeedProd Pro seedprod-coming-soon-pro-5 SEOPress PRO wp-seopress-pro Shoppable Images (Lookbook) for WooCommerce mabel-shoppable-images-lite ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization shortpixel-adaptive-images SignUp & SignIn signup-signin Simple Basic Contact Form simple-basic-contact-form Site Kit by Google – Analytics, Search Console, AdSense, Speed google-site-kit Site Reviews site-reviews SiteGround Email Marketing siteground-email-marketing Slim SEO – A Fast & Automated SEO Plugin For WordPress slim-seo StatCounter – Free Real Time Visitor Stats official-statcounter-plugin-for-wordpress Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions wp-full-stripe-free Subscriptions for WooCommerce subscriptions-for-woocommerce Surbma | Infusionsoft Shortcode surbma-infusionsoft-shortcode SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments surecart TablePress – Tables in WordPress made easy tablepress TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Builder templatespare Toolset Forms cred-frontend-editor Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin tourfic Transbank Webpay transbank-webpay-plus-rest Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin ultimate-member Uncanny Automator Pro uncanny-automator-pro Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin uncanny-automator URL Preview link-preview User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder user-registration utm.codes utm-dot-codes WCBoost – Products Compare wcboost-products-compare Welcome Software Publishing newscred-publishing weMail – Email Marketing, Newsletter Builder & Email Automations for WooCommerce wemail WhatsOrder – Instant Checkout for WooCommerce whatsorder-instant-checkout-for-woocommerce WordPress Automatic Plugin wp-automatic WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets wp-all-import WP Forms Connector wp-forms-connector WP Job Portal – AI-Powered Recruitment System for Company or Job Board website wp-job-portal WP Latest Posts wp-latest-posts WP Meta SEO wp-meta-seo WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars wp-post-author WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System wp-cafe WPComplete wpcomplete wpForo Forum wpforo Xpro Addons — 140+ Widgets for Elementor xpro-elementor-addons 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 pgall-for-woocommerce WordPress Themes with Reported Vulnerabilities Last Week Software Name Software Slug ListingPro - WordPress Directory & Listing Theme listingpro NanoMag - Responsive WordPress Magazine Theme nanomag Neve PRO neve-pro-addon Real Estate 7 WordPress realestate-7 RH - Real Estate WordPress Theme realhomes Spexo spexo splash splash Travel Booking travel-booking Woodmart woodmart Vulnerability Details Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration , which is completely free to utilize. Dokan Pro <= 5.0.4 - Unauthenticated Privilege Escalation 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-56033 Patch Status Patched Published Jun 23, 2026 Affected Software Dokan Pro [dokan-pro] Researcher VanTastic More Details > Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-12416 Patch Status Unpatched Published Jun 23, 2026 Affected Software Invoice Generator [invoice-creator] Researcher Alyudin Nafiie More Details > Invoice Generator <= 1.0.0 - Unauthenticated Privilege Escalation via Account Takeover via 'user_id' Parameter 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-12415 Patch Status Unpatched Published Jun 26, 2026 Affected Software Invoice Generator [invoice-creator] Researcher Alyudin Nafiie More Details > OMGF Pro <= 5.2.6 - Unauthenticated Arbitrary File Upload via @import URL Reflection 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-57700 Patch Status Patched Published Jun 25, 2026 Affected Software OMGF Pro [host-google-fonts-pro] Researchers Nguyen Ngoc Duc (duc193) NETZLICHT More Details > Paytium: Mollie payment forms & donations <= 5.0.2 - Unauthenticated Privilege Escalation 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-56030 Patch Status Patched Published Jun 23, 2026 Affected Software Paytium: Mollie payment forms & donations [paytium] Researcher Nabil Irawan More Details > SignUp & SignIn <= 1.0.0 - Unauthenticated Privilege Escalation via Weak Password Reset Validation via 'reset_activation_code' Leading to Account Takeover 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-12417 Patch Status Unpatched Published Jun 23, 2026 Affected Software SignUp & SignIn [signup-signin] Researcher Alyudin Nafiie More Details > AdRotate Banner Manager <= 5.17.7 - Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-12242 Patch Status Patched Published Jun 23, 2026 Affected Software AdRotate Banner Manager [adrotate] Researcher Osvaldo Noe Gonzalez Del Rio (Os) More Details > Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools <= 8.0.1 - Authenticated (Customer+) Arbitrary File Upload 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-56027 Patch Status Patched Published Jun 23, 2026 Affected Software Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools [woocommerce-jetpack] Researcher Jakub Herman More Details > Frisbii Pay <= 1.8.2 - Authenticated (Contributor+) Privilege Escalation 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-56038 Patch Status Patched Published Jun 24, 2026 Affected Software Frisbii Pay [reepay-checkout-gateway] Researcher Denver Jackson More Details > JS Help Desk – AI-Powered Support & Ticketing System <= 3.1.1 - Authenticated (Subscriber+) Arbitrary File Deletion 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-56054 Patch Status Patched Published Jun 25, 2026 Affected Software JS Help Desk – AI-Powered Support & Ticketing System [js-support-ticket] Researcher daroo More Details > Post Snippets – Custom WordPress Code Snippets Customizer <= 4.0.19 - Authenticated (Contributor+) Remote Code Execution 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-56049 Patch Status Patched Published Jun 25, 2026 Affected Software Post Snippets – Custom WordPress Code Snippets Customizer [post-snippets] Researcher daroo More Details > Quform - WordPress Form Builder <= 2.23.0 - Authenticated (Subscriber+) Arbitrary File Upload 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-56058 Patch Status Patched Published Jun 25, 2026 Affected Software Quform - WordPress Form Builder [quform] Researcher daroo More Details > Ultimate Member <= 2.11.4 - Authenticated (Contributor+) Account Takeover via Password Reset Link Disclosure 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-7761 Patch Status Patched Published Jun 23, 2026 Affected Software Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] Researcher tiborisaak More Details > Welcome Software Publishing <= 0.0.31 - Authenticated (Subscriber+) Arbitrary Options Update to Privilege Escalation via 'nc.setOption' XML-RPC Method 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-4297 Patch Status Unpatched Published Jun 23, 2026 Affected Software Welcome Software Publishing [newscred-publishing] Researcher Nabil Irawan More Details > Frontend File Manager Plugin <= 23.6 - Authenticated (Subscriber+) Arbitrary File Deletion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-8095 Patch Status Unpatched Published Jun 27, 2026 Affected Software Frontend File Manager Plugin [nmedia-user-file-uploader] Researcher sorawautsukushiii More Details > Interactive Content – H5P <= 1.17.7 - Authenticated (Contributor+) Arbitrary File Deletion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-57321 Patch Status Patched Published Jun 26, 2026 Affected Software Interactive Content – H5P [h5p] Researcher daroo More Details > Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.3.1.2 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-56031 Patch Status Patched Published Jun 23, 2026 Affected Software Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin [uncanny-automator] Researcher VanTastic More Details > Advance Product Search- Voice & Ajax Search for WooCommerce <= 1.4.4 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-56070 Patch Status Patched Published Jun 25, 2026 Affected Software Advance Product Search- Voice & Ajax Search for WooCommerce [th-advance-product-search] Researcher Mokksh Parekh More Details > BuddyBoss Platform <= 3.0.4 - Authenticated (Subscriber+) PHP Object Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-56032 Patch Status Patched Published Jun 23, 2026 Affected Software BuddyBoss Platform [buddyboss-platform] Researcher dutafi More Details > ClearSale Total <= 3.4.2 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-8705 Patch Status Unpatched Published Jun 23, 2026 Affected Software ClearSale Total [clearsale-total] Researcher Catalin Oancea (0x4D5A) More Details > Dokan Pro <= 5.0.4 - Unauthenticated SQL Injection via 'latitude' and 'longitude' Parameters 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-12077 Patch Status Patched Published Jun 24, 2026 Affected Software Dokan Pro [dokan-pro] Researcher lb More Details > EventPrime – Events Calendar, Bookings and Tickets <= 4.3.4.1 - Authenticated (Subscriber+) PHP Object Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-56053 Patch Status Patched Published Jun 25, 2026 Affected Software EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management] Researcher VanTastic More Details > Goya Core < 1.0.9.4 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2025-68064 Patch Status Patched Published Jun 26, 2026 Affected Software Goya Core [goya-core] Researcher João Pedro S Alcântara (Kinorth) More Details > JetEngine <= 3.8.10.2 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-56068 Patch Status Patched Published Jun 25, 2026 Affected Software JetEngine [jet-engine] Researcher Rafie Muhammad More Details > JetSmartFilters <= 3.8.3 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-56067 Patch Status Patched Published Jun 25, 2026 Affected Software JetSmartFilters [jet-smart-filters] Researcher Nguyen Ba Khanh More Details > Library Management System <= 3.5.7 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-56034 Patch Status Patched Published Jun 23, 2026 Affected Software Library Management System [library-management-system] Researcher Benedictus Jovan (aillesim/eneri) More Details > Panorama – 360 degree Virtual Tour, Panoramic Image viewer and More <= 1.6.1 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-57647 Patch Status Patched Published Jun 26, 2026 Affected Software Panorama – 360 degree Virtual Tour, Panoramic Image viewer and More [panorama] Researcher endy More Details > Post Duplicator < 3.0.15 - Authenticated (Contributor+) PHP Object Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-10749 Patch Status Patched Published Jun 25, 2026 Affected Software Post Duplicator [post-duplicator] Researcher Md. Minaruzzaman Shovon More Details > Quotes llama <= 3.1.5 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-56062 Patch Status Patched Published Jun 25, 2026 Affected Software Quotes llama [quotes-llama] Researcher ParkHyunWoo More Details > RH - Real Estate WordPress Theme <= 4.5.3 - Authenticated (Subscriber+) PHP Object Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-56055 Patch Status Patched Published Jun 25, 2026 Affected Software RH - Real Estate WordPress Theme [realhomes] Researcher daroo More Details > Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2025-68063 Patch Status Patched Published Jun 26, 2026 Affected Software splash [splash] Researcher João Pedro S Alcântara (Kinorth) More Details > Tourfic <= 2.22.7 - Unauthenticated SQL Injection via 'post_id' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-12937 Patch Status Patched Published Jun 24, 2026 Affected Software Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin [tourfic] Researcher PRISM More Details > Uncanny Automator Pro <= 7.3.0.6 - Authenticated (Subscriber+) PHP Object Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-56057 Patch Status Patched Published Jun 25, 2026 Affected Software Uncanny Automator Pro [uncanny-automator-pro] Researcher VanTastic More Details > WP Forms Connector <= 1.8 - Missing Authorization to Unauthenticated Information Exposure via 'user/list' REST Endpoint 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-9178 Patch Status Unpatched Published Jun 23, 2026 Affected Software WP Forms Connector [wp-forms-connector] Researcher jamaal More Details > WP Forms Connector <= 1.8 - Unauthenticated SQL Injection via 'order' Parameter 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-9179 Patch Status Unpatched Published Jun 23, 2026 Affected Software WP Forms Connector [wp-forms-connector] Researcher jamaal More Details > 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 <= 5.5.6 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-56036 Patch Status Patched Published Jun 23, 2026 Affected Software 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 [pgall-for-woocommerce] Researcher qdtad More Details > Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57317 Patch Status Patched Published Jun 26, 2026 Affected Software Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] Researcher vnth4nhnt More Details > ARForms <= 7.1.3 - Unauthenticated Stored Cross-Site Scripting via 'value' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-3652 Patch Status Unpatched Published Jun 23, 2026 Affected Software ARforms [arforms] Researcher h0xilo More Details > Blog2Social: Social Media Auto Post & Scheduler <= 8.9.2 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-56044 Patch Status Patched Published Jun 25, 2026 Affected Software Blog2Social: Social Media Auto Post & Scheduler [blog2social] Researcher João Pedro S Alcântara (Kinorth) More Details > Cincopa video and media plug-in <= 1.163 - Unauthenticated Stored Cross-Site Scripting via cincopa Shortcode in Post Comments 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-10092 Patch Status Unpatched Published Jun 23, 2026 Affected Software Cincopa video and media plug-in [video-playlist-and-gallery-plugin] Researcher theviper17y More Details > Customer Reviews for WooCommerce <= 5.110.1 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-56043 Patch Status Patched Published Jun 24, 2026 Affected Software Customer Reviews for WooCommerce [customer-reviews-woocommerce] Researcher daroo More Details > Email JavaScript Cloak <= 1.03 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-10091 Patch Status Unpatched Published Jun 23, 2026 Affected Software Email JavaScript Cloak [email-javascript-cloaker] Researcher theviper17y More Details > Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.53.1 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-56071 Patch Status Patched Published Jun 24, 2026 Affected Software Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] Researcher daroo More Details > FOX – Currency Switcher Professional for WooCommerce <= 1.4.8 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57319 Patch Status Patched Published Jun 25, 2026 Affected Software FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] Researcher Nguyen Ba Khanh More Details > Gutenverse Form – Contact Form Builder, Block Form & Booking Form <= 2.4.7 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-56040 Patch Status Patched Published Jun 24, 2026 Affected Software Gutenverse Form – Contact Form Builder, Block Form & Booking Form [gutenverse-form] Researcher hivesec More Details > Kargo Takip <= 1.2 - Unauthenticated Server-Side Request Forgery via 'api_url' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-12095 Patch Status Unpatched Published Jun 23, 2026 Affected Software Kargo Takip [kargo-takip] Researcher Eason More Details > NanoMag <= 1.8 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57325 Patch Status Patched Published Jun 26, 2026 Affected Software NanoMag - Responsive WordPress Magazine Theme [nanomag] Researcher Tran Nguyen Bao Khanh More Details > Responsive Lightbox & Gallery <= 2.7.6 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-56041 Patch Status Patched Published Jun 24, 2026 Affected Software Responsive Lightbox & Gallery [responsive-lightbox] Researcher Nguyen Ba Khanh More Details > Simple Basic Contact Form <= 20250114 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-8172 Patch Status Unpatched Published Jun 25, 2026 Affected Software Simple Basic Contact Form [simple-basic-contact-form] Researcher Juthawong Naisanguansee More Details > TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Builder <= 4.2.0 - Authenticated (Admin+) Arbitrary File Upload 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57658 Patch Status Patched Published Jun 25, 2026 Affected Software TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Builder [templatespare] Researcher Ananda Dhakal More Details > Transbank Webpay < 1.14.0 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-6858 Patch Status Patched Published Jun 22, 2026 Affected Software Transbank Webpay [transbank-webpay-plus-rest] Researcher Mateo Contenla & Matías Schiappacasse More Details > URL Preview <= 1.0 - Unauthenticated Server-Side Request Forgery via 'url' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-12100 Patch Status Unpatched Published Jun 23, 2026 Affected Software URL Preview [link-preview] Researcher Eason More Details > Woodmart <= 8.5.3 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-56072 Patch Status Patched Published Jun 25, 2026 Affected Software Woodmart [woodmart] Researcher daroo More Details > WordPress Automatic Plugin < 3.135.1 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-56045 Patch Status Patched Published Jun 25, 2026 Affected Software WordPress Automatic Plugin [wp-automatic] Researcher Nguyen Ba Khanh More Details > WP Meta SEO <= 4.5.18 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI in 404 Logging 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-9643 Patch Status Unpatched Published Jun 23, 2026 Affected Software WP Meta SEO [wp-meta-seo] Researcher zedeq More Details > Auros Core <= 5.3.1 - Unauthenticated Arbitrary Shortcode Execution 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2025-64637 Patch Status Unpatched Published Jun 26, 2026 Affected Software Auros Core [auros-core] Researcher Bonds More Details > Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 30.0.0 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-57662 Patch Status Patched Published Jun 26, 2026 Affected Software Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe [contest-gallery] Researcher Trương Hữu Phúc (truonghuuphuc) More Details > Dokan Pro <= 5.0.4 - Authenticated (Subscriber+) SQL Injection via 'orderby' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-12079 Patch Status Patched Published Jun 24, 2026 Affected Software Dokan Pro [dokan-pro] Researcher lb More Details > Frisbii Pay <= 1.8.9 - Missing Authorization to Authenticated (Subscriber+) Payment Token Modification 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-3462 Patch Status Patched Published Jun 26, 2026 Affected Software Frisbii Pay [reepay-checkout-gateway] Researcher momopon1415 More Details > Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress <= 4.7.8 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-57642 Patch Status Patched Published Jun 26, 2026 Affected Software Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress [gallery-plugin] Researcher dodoh4t More Details > Gravity Forms Booking <= 2.7.1 - Authenticated (Subscriber+) Time-Based SQL Injection via 'staff_id' 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-2508 Patch Status Patched Published Jun 24, 2026 Affected Software Gravity Bookings [gf-bookings-premium] Researcher Abdulsamad Yusuf (0xVenus) More Details > Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.5 - Authenticated (Sales representative+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-57667 Patch Status Patched Published Jun 26, 2026 Affected Software Groundhogg — CRM, Newsletters, and Marketing Automation [groundhogg] Researcher Jonathan Dersch More Details > Groundhogg <= 4.5.4 - Authenticated (Custom+) SQL Injection via 'after' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-13226 Patch Status Patched Published Jun 25, 2026 Affected Software Groundhogg — CRM, Newsletters, and Marketing Automation [groundhogg] Researcher PRISM More Details > Groundhogg <= 4.5.5 - Authenticated (Marketer+) SQL Injection via 'search' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-13331 Patch Status Patched Published Jun 26, 2026 Affected Software Groundhogg — CRM, Newsletters, and Marketing Automation [groundhogg] Researchers PRISM Chloe Chamberland More Details > Groundhogg <= 4.5.5 - Authenticated (Sales Rep+) SQL Injection via 'query[select]' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-13333 Patch Status Patched Published Jun 26, 2026 Affected Software Groundhogg — CRM, Newsletters, and Marketing Automation [groundhogg] Researchers Chloe Chamberland PRISM More Details > Infility Global < 2.15.19 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-8163 Patch Status Patched Published Jun 25, 2026 Affected Software Infility Global [infility-global] Researcher TRAN THE LONG More Details > Recipe Cards For Your Food Blog from Zip Recipes <= 8.2.7 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-57663 Patch Status Patched Published Jun 26, 2026 Affected Software Recipe Cards For Your Food Blog from Zip Recipes [zip-recipes] Researcher ParkHyunWoo More Details > Restaurant Menu and Food Ordering <= 2.4.10 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-57644 Patch Status Patched Published Jun 26, 2026 Affected Software Restaurant Menu and Food Ordering [mp-restaurant-menu] Researcher Jonathan Dersch More Details > Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin <= 2.22.5 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-56064 Patch Status Patched Published Jun 25, 2026 Affected Software Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin [tourfic] Researcher anhcd05 More Details > User Registration & Membership <= 5.2.0 - Missing Authorization to Unauthenticated Payment Bypass 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-1869 Patch Status Patched Published Jun 25, 2026 Affected Software User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder [user-registration] Researcher Supakiad S. (m3ez) More Details > WP Job Portal – AI-Powered Recruitment System for Company or Job Board website <= 2.5.2 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-57653 Patch Status Patched Published Jun 26, 2026 Affected Software WP Job Portal – AI-Powered Recruitment System for Company or Job Board website [wp-job-portal] Researcher hhhai More Details > WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars <= 3.9.1 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-57643 Patch Status Patched Published Jun 26, 2026 Affected Software WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars [wp-post-author] Researcher hhhai More Details > wpForo Forum <= 3.0.9 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-57636 Patch Status Patched Published Jun 26, 2026 Affected Software wpForo Forum [wpforo] Researcher daroo More Details > Advanced Order Export For WooCommerce <= 4.0.9 - Authenticated (Customer+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-56042 Patch Status Patched Published Jun 24, 2026 Affected Software Advanced Order Export For WooCommerce [woo-order-export-lite] Researcher ParkHyunWoo More Details > AI Share & Summarize < 2.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-10531 Patch Status Patched Published Jun 25, 2026 Affected Software AI Share & Summarize [ai-share-summarize] Researcher Haitam Lazaar More Details > Avalon23 Products Filter for WooCommerce <= 1.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-8865 Patch Status Unpatched Published Jun 23, 2026 Affected Software Avalon23 Products Filter for WooCommerce [avalon23-products-filter-for-woocommerce] Researcher Gilang - DJ More Details > BNE Testimonials <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2025-68075 Patch Status Unpatched Published Jun 26, 2026 Affected Software BNE Testimonials [bne-testimonials] Researcher Muhammad Yudha - DJ More Details > CodePeople Post Map for Google Maps <= 1.2.6 - Authenticated (Contributor +) Stored Cross-Site Scripting via 'cpm_point' Post Meta 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-13335 Patch Status Patched Published Jun 26, 2026 Affected Software CodePeople Post Map for Google Maps [codepeople-post-map] Researchers Chloe Chamberland PRISM More Details > Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-11783 Patch Status Patched Published Jun 26, 2026 Affected Software Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] Researcher hackthesoul More Details > Exclusive Addons for Elementor <= 2.7.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57620 Patch Status Patched Published Jun 26, 2026 Affected Software Exclusive Addons for Elementor [exclusive-addons-for-elementor] Researcher Nguyen Ba Khanh More Details > Featured Image <= 2.1 - Authenticated (Author+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57431 Patch Status Patched Published Jun 25, 2026 Affected Software Featured Image [featured-image] Researcher Muhammad Yudha - DJ More Details > Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution <= 2.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57638 Patch Status Patched Published Jun 26, 2026 Affected Software Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution [fluent-booking] Researcher Tarcísio Luchesi(Poystick) More Details > Frontend File Manager Plugin <= 23.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-8378 Patch Status Unpatched Published Jun 25, 2026 Affected Software Frontend File Manager Plugin [nmedia-user-file-uploader] Researcher Mohamad Nour Almujarkesh More Details > Ghost Kit – Page Builder Blocks, Motion Effects & Extensions <= 3.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57651 Patch Status Patched Published Jun 26, 2026 Affected Software Ghost Kit – Page Builder Blocks, Motion Effects & Extensions [ghostkit] Researcher Ananda Dhakal More Details > Gutenberg Essential Blocks - Page Builder for Gutenberg Blocks & Patterns <= 6.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'configurablePrefix' Block Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-10833 Patch Status Patched Published Jun 24, 2026 Affected Software Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] Researcher Viet Anh Ngo More Details > Hester Core <= 1.1.8 - Authenticated (Author+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57656 Patch Status Patched Published Jun 26, 2026 Affected Software Hester Core [hester-core] Researcher Ananda Dhakal More Details > Image Carousel <= 1.0.0.41 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2025-68074 Patch Status Unpatched Published Jun 26, 2026 Affected Software Image Carousel [image-carousel] Researcher Muhammad Yudha - DJ More Details > Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.0.11 - Authenticated (Subscriber+) Server-Side Request Forgery 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57627 Patch Status Patched Published Jun 26, 2026 Affected Software Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] Researcher Ananda Dhakal More Details > ListingPro - WordPress Directory & Listing Theme <= 2.9.11 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-56046 Patch Status Patched Published Jun 24, 2026 Affected Software ListingPro - WordPress Directory & Listing Theme [listingpro] Researcher daroo More Details > Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid <= 1.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57650 Patch Status Patched Published Jun 26, 2026 Affected Software Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid [magazine-blocks] Researcher Jarno Vos (jrn5151) More Details > MIR blocks and shortcodes <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-8896 Patch Status Unpatched Published Jun 23, 2026 Affected Software MIR blocks and shortcodes [mir-blocks-and-shortcodes] Researcher zakaria More Details > Neve PRO <= 3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57618 Patch Status Patched Published Jun 25, 2026 Affected Software Neve PRO [neve-pro-addon] Researcher João Pedro S Alcântara (Kinorth) More Details > Page Builder by SiteOrigin <= 2.34.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via panels_data Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-13295 Patch Status Patched Published Jun 26, 2026 Affected Software Page Builder by SiteOrigin [siteorigin-panels] Researcher lhking More Details > ProfileGrid <= 5.9.9.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Message Content 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-4610 Patch Status Patched Published Jun 22, 2026 Affected Software ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] Researcher Jonah Burgess (CryptoCat) More Details > SeedProd Pro < 6.19.5 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57617 Patch Status Patched Published Jun 25, 2026 Affected Software SeedProd Pro [seedprod-coming-soon-pro-5] Researcher João Pedro S Alcântara (Kinorth) More Details > StatCounter – Free Real Time Visitor Stats <= 2.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57629 Patch Status Patched Published Jun 26, 2026 Affected Software StatCounter – Free Real Time Visitor Stats [official-statcounter-plugin-for-wordpress] Researcher timomangcut More Details > Surbma | Infusionsoft Shortcode <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-11597 Patch Status Patched Published Jun 26, 2026 Affected Software Surbma | Infusionsoft Shortcode [surbma-infusionsoft-shortcode] Researcher zakaria More Details > SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments <= 4.2.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57313 Patch Status Patched Published Jun 25, 2026 Affected Software SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] Researcher Psalms Christopher Matovu (ByteOverride) More Details > utm.codes <= 1.9.0 - Authenticated (Subscriber+) Server-Side Request Forgery 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-56026 Patch Status Patched Published Jun 23, 2026 Affected Software utm.codes [utm-dot-codes] Researcher theviper17 More Details > WP Latest Posts <= 5.0.11 - Authenticated (Author+) Stored Cross-Site Scripting via Post Content Image src Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-9620 Patch Status Unpatched Published Jun 23, 2026 Affected Software WP Latest Posts [wp-latest-posts] Researcher Muhammad Yudha - DJ More Details > WP Meta SEO <= 4.5.18 - Authenticated (Contributor+) Server-Side Request Forgery via 'new_link' Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-11370 Patch Status Unpatched Published Jun 23, 2026 Affected Software WP Meta SEO [wp-meta-seo] Researcher Enes Ismail More Details > Xpro Addons <= 1.7.2 - Authenticated (Author+) Stored Cross-Site Scripting via 'custom_attributes' Parameter of Multiple Widgets 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-11614 Patch Status Patched Published Jun 23, 2026 Affected Software Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] Researcher Huazu Jiang (anjhz0318) More Details > EntreDroppers <= 1.1.2 - Reflected Cross-Site Scripting via PHP_SELF Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-8628 Patch Status Unpatched Published Jun 23, 2026 Affected Software EntreDroppers [entredropper] Researcher Abdulsamad Yusuf (0xVenus) More Details > Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <= 3.4.8 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-57312 Patch Status Patched Published Jun 25, 2026 Affected Software Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI [everest-forms] Researcher bekitousei More Details > Image Sizes on Demand <= 1.3 - Reflected Cross-Site Scripting via PHP_SELF Server Variable 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-8622 Patch Status Unpatched Published Jun 23, 2026 Affected Software Image Sizes on Demand [image-sizes-on-demand] Researcher Abdulsamad Yusuf (0xVenus) More Details > MaxButtons <= 9.8.5 - Reflected Cross-Site Scripting via 'view' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-13245 Patch Status Patched Published Jun 26, 2026 Affected Software MaxButtons – Create buttons [maxbuttons] Researcher Dmitrii Ignatyev More Details > Osiris Signature Banner <= 0.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'prepend_text' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-8905 Patch Status Unpatched Published Jun 23, 2026 Affected Software Osiris Signature Banner [osiris-signature-banner] Researcher Muhammad Nur Ibnu Hubab More Details > Perfmatters <= 2.6.3 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-56047 Patch Status Patched Published Jun 25, 2026 Affected Software Perfmatters [perfmatters] Researcher dutafi More Details > Quick Interest Slider <= 3.1.6 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-56039 Patch Status Patched Published Jun 24, 2026 Affected Software Quick Interest Slider [quick-interest-slider] Researcher hivesec More Details > SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments <= 4.3.2 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-57314 Patch Status Patched Published Jun 26, 2026 Affected Software SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] Researcher Bonds More Details > TablePress – Tables in WordPress made easy <= 3.3.1 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-56051 Patch Status Patched Published Jun 25, 2026 Affected Software TablePress – Tables in WordPress made easy [tablepress] Researcher Bonds More Details > weMail – Email Marketing, Newsletter Builder & Email Automations for WooCommerce <= 2.1.2 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-57322 Patch Status Patched Published Jun 26, 2026 Affected Software weMail – Email Marketing, Newsletter Builder & Email Automations for WooCommerce [wemail] Researcher Nguyen Ba Khanh More Details > Advanced Contact Form 7 <= 1.0.0 - Missing Authorization to Unauthenticated Arbitrary Contact Form Submission Deletion via 'form_id' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-12094 Patch Status Unpatched Published Jun 23, 2026 Affected Software Advanced Contact Form 7 – Compact DB [advanced-contact-form-7-compact-db] Researcher Eason More Details > BitFire Security – Firewall, Malware Scanner, Bot Blocker, Login Protection <= 5.0.3 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-56035 Patch Status Patched Published Jun 23, 2026 Affected Software BitFire Security – Firewall, Malware Scanner, Bot Blocker, Login Protection [bitfire] Researcher Aurélien BOURDOIS (Elymaro) More Details > Block for Mailchimp – Add Email Subscription Forms and Collect Leads <= 1.1.15 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-56063 Patch Status Patched Published Jun 25, 2026 Affected Software Block for Mailchimp – Add Email Subscription Forms and Collect Leads [block-for-mailchimp] Researcher Nguyen Quang Truong More Details > Blocksy Companion Pro <= 2.1.46 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57630 Patch Status Patched Published Jun 26, 2026 Affected Software Blocksy Companion Pro [blocksy-companion-pro] Researcher Austin Ginder More Details > Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment <= 2.7.1 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57660 Patch Status Patched Published Jun 26, 2026 Affected Software Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment [booking-and-rental-manager-for-woocommerce] Researcher Averon Averenkov More Details > BookPro - Appointment Booking WordPress Plugin <= 1.1.0 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2025-66123 Patch Status Unpatched Published Jun 26, 2026 Affected Software BookPro - Appointment Booking WordPress Plugin [ovabookpro] Researcher Phat RiO More Details > Bopo – WooCommerce Product Bundle Builder <= 1.1.6 - Unauthenticated Sensitive Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57664 Patch Status Patched Published Jun 26, 2026 Affected Software Bopo – WooCommerce Product Bundle Builder [bopo-woo-product-bundle-builder] Researcher Bao - BlueRock More Details > CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-56029 Patch Status Patched Published Jun 23, 2026 Affected Software CorvusPay WooCommerce Payment Gateway [corvuspay-woocommerce-integration] Researcher ParkHyunWoo More Details > Devs Accounting <= 1.2.0 - Missing Authorization to Unauthenticated Account Deletion via /delete-account/ REST Endpoint 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-9172 Patch Status Unpatched Published Jun 23, 2026 Affected Software Devs Accounting – Simple Accounting and Invoicing Solution [devs-accounting] Researcher jamaal More Details > Devs Accounting <= 1.2.0 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'id' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-9175 Patch Status Unpatched Published Jun 23, 2026 Affected Software Devs Accounting – Simple Accounting and Invoicing Solution [devs-accounting] Researcher jamaal More Details > Donation Thermometer <= 2.2.7 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2025-64636 Patch Status Unpatched Published Jun 26, 2026 Affected Software Donation Thermometer [donation-thermometer] Researcher Legion Hunter More Details > Frontend File Manager Plugin <= 23.6 - Missing Authorization to Unauthenticated File Download 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-8379 Patch Status Unpatched Published Jun 25, 2026 Affected Software Frontend File Manager Plugin [nmedia-user-file-uploader] Researcher Alexander Jurkschat More Details > GIFT4U – Gift Cards All in One for Woo <= 1.0.10 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57324 Patch Status Patched Published Jun 26, 2026 Affected Software GIFT4U – Gift Cards All in One for Woo [gift4u-gift-cards-all-in-one-for-woo] Researcher Ali Osman ERBAS (0110m4n) More Details > GravityView <= 3.0.0 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57665 Patch Status Patched Published Jun 26, 2026 Affected Software GravityView [gravityview] Researcher Austin Ginder More Details > HTML5 Video Player – Embed and Play Videos in Custom Player <= 2.11.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57323 Patch Status Patched Published Jun 26, 2026 Affected Software HTML5 Video Player – Embed and Play Videos in Custom Player [html5-video-player] Researcher Nabil Irawan More Details > JS Help Desk – AI-Powered Support & Ticketing System <= 3.1.0 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57652 Patch Status Patched Published Jun 26, 2026 Affected Software JS Help Desk – AI-Powered Support & Ticketing System [js-support-ticket] Researcher William Matos More Details > MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites <= 6.1.1 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-27366 Patch Status Patched Published Jun 23, 2026 Affected Software MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] Researcher Drew Webber (mcdruid) More Details > NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via CSVExport Class 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-12404 Patch Status Patched Published Jun 26, 2026 Affected Software NEX-Forms – Ultimate Forms Plugin for WordPress [nex-forms-express-wp-form-builder] Researcher valent1 More Details > Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-56048 Patch Status Patched Published Jun 25, 2026 Affected Software Payment Gateway Based Fees and Discounts for WooCommerce [checkout-fees-for-woocommerce] Researcher Jakub Herman More Details > Pie Register – User Registration, Profiles & Content Restriction < 3.8.4.10 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-10530 Patch Status Patched Published Jun 22, 2026 Affected Software Pie Register – User Registration, Profiles & Content Restriction [pie-register] Researcher haitam_lz More Details > PPOM – Product Addons & Custom Fields for WooCommerce <= 33.0.18 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-56050 Patch Status Patched Published Jun 25, 2026 Affected Software PPOM – Product Addons & Custom Fields for WooCommerce [woocommerce-product-addon] Researcher Nguyen Dinh Hai (HaiND) More Details > Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-56060 Patch Status Patched Published Jun 25, 2026 Affected Software Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] Researcher Jakub Herman More Details > RegistrationMagic <= 6.0.8.6 - Authenticated (Subscriber+) Authentication Bypass via Forged PayPal IPN Request 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-9242 Patch Status Patched Published Jun 26, 2026 Affected Software RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login [custom-registration-form-builder-with-submission-manager] Researcher Rafael Gunawan (kokon) More Details > RentMy Real-Time Rental Management Plugin <= 4.0.4.1 - Missing Authorization to Unauthenticated Settings Update via rentmy_cdn_request AJAX Action 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-8690 Patch Status Unpatched Published Jun 23, 2026 Affected Software RentMy Real-Time Rental Management Plugin [rentmy-online-rental-shop] Researcher Legion Hunter More Details > SearchPlus <= 1.7.1 - Missing Authorization to Unauthenticated Settings Modification and Deletion via searchplus_save_token & searchplus_reset_token AJAX Actions 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-8617 Patch Status Unpatched Published Jun 23, 2026 Affected Software SearchPlus [searchplus] Researcher Legion Hunter More Details > Secufor_OAuth <= 1.0.7 - Missing Authorization to Unauthenticated Account Logout via 'secuforoauth_unregister_action' AJAX Action 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-7617 Patch Status Unpatched Published Jun 23, 2026 Affected Software Secufor_OAuth [wpoauth] Researcher SHIVAM KUMAR More Details > ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization <= 3.11.4 - Unauthenticated Arbitrary File Deletion 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-56066 Patch Status Patched Published Jun 25, 2026 Affected Software ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization [shortpixel-adaptive-images] Researcher Ananda Dhakal More Details > SiteGround Email Marketing <= 1.7.5 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-24547 Patch Status Patched Published Jun 25, 2026 Affected Software SiteGround Email Marketing [siteground-email-marketing] Researcher Nabil Irawan More Details > Stripe Payment Forms by WP Full Pay <= 8.4.3 - Missing Authorization to Unauthenticated Payment Record Manipulation via 'paymentIntentId' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-12432 Patch Status Patched Published Jun 26, 2026 Affected Software Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions [wp-full-stripe-free] Researcher Netwurm More Details > Subscriptions for WooCommerce <= 1.9.5 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-56061 Patch Status Patched Published Jun 25, 2026 Affected Software Subscriptions for WooCommerce [subscriptions-for-woocommerce] Researcher Jakub Herman More Details > Toolset Forms <= 2.6.24 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-56069 Patch Status Patched Published Jun 25, 2026 Affected Software Toolset Forms [cred-frontend-editor] Researcher VanTastic More Details > User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 5.2.2 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-52701 Patch Status Patched Published Jun 22, 2026 Affected Software User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder [user-registration] Researcher nobody09 More Details > WCBoost – Products Compare <= 1.1.0 - Unauthenticated Sensitive Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57633 Patch Status Patched Published Jun 26, 2026 Affected Software WCBoost – Products Compare [wcboost-products-compare] Researcher Ananda Dhakal More Details > WhatsOrder <= 1.0.1 - Unauthenticated Sensitive Information Exposure via Predictable Invoice File URLs 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-9612 Patch Status Unpatched Published Jun 23, 2026 Affected Software WhatsOrder – Instant Checkout for WooCommerce [whatsorder-instant-checkout-for-woocommerce] Researcher Benedictus Jovan (aillesiM) More Details > FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.15.0.5 - Authenticated (Administrator+) SQL Injection 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-56052 Patch Status Patched Published Jun 24, 2026 Affected Software FunnelKit – Funnel Builder for WooCommerce Checkout [funnel-builder] Researcher Ananda Dhakal More Details > Infility Global < 2.15.20 - Authenticated (Editor+) SQL Injection 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-7842 Patch Status Patched Published Jun 25, 2026 Affected Software Infility Global [infility-global] Researcher Mustafa Ahmed More Details > Popup Box – Create Countdown, Coupon, Video, Contact Form Popups <= 6.0.1 - Authenticated (Administrator+) SQL Injection 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-57631 Patch Status Patched Published Jun 26, 2026 Affected Software Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] Researcher Doan Dinh Van More Details > WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets <= 4.0.1 - Authenticated (Administrator+) SQL Injection 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-57628 Patch Status Patched Published Jun 26, 2026 Affected Software WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] Researcher Ananda Dhakal More Details > Gutenverse <= 3.8.0 - Authenticated (Editor+) Stored Cross-Site Scripting via 'fonts[].font.font.value' Parameter 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-12399 Patch Status Patched Published Jun 26, 2026 Affected Software Gutenverse – WordPress Blocks, Page Builder & Site Editor [gutenverse] Researchers R4mbb R4m bb More Details > Ivory Search <= 5.5.15 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-11356 Patch Status Patched Published Jun 26, 2026 Affected Software Ivory Search – WordPress Search Plugin [add-search-to-menu] Researcher Meher Sudhakar Abbireddi More Details > 24liveblog <= 2.2 - Authenticated (Contributor+) Exposure of Sensitive Information via Block Editor Script Localization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9183 Patch Status Unpatched Published Jun 23, 2026 Affected Software 24liveblog – live blog tool [24liveblog] Researcher g0wthr More Details > 24liveblog <= 2.2 - Missing Authorization to Authenticated (Author+) Settings Modification via update_lb24_token AJAX action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9184 Patch Status Unpatched Published Jun 23, 2026 Affected Software 24liveblog – live blog tool [24liveblog] Researcher g0wthr More Details > Abandoned Cart Lite for WooCommerce <= 6.8.0 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57637 Patch Status Patched Published Jun 26, 2026 Affected Software Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] Researcher Ananda Dhakal More Details > Advance Nav Menu Manager <= 1.3 - Missing Authorization to Authenticated (Subscriber+) Nav Menu Item Modification via anmm_save_menu_data AJAX Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-8688 Patch Status Unpatched Published Jun 23, 2026 Affected Software Advance Nav Menu Manager [advance-nav-menu-manager] Researcher Hardik Patel More Details > Affiliates Manager <= 2.9.49 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57654 Patch Status Patched Published Jun 26, 2026 Affected Software Affiliates Manager [affiliates-manager] Researcher Jakub Herman More Details > Assistio <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Deletion via assistio_plugin_delete_assistio_settings AJAX Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-8614 Patch Status Unpatched Published Jun 23, 2026 Affected Software Assistio [assistio] Researcher Legion Hunter More Details > Blue Captcha <= 2.0.1 - Cross-Site Request Forgery via 'blcap_action' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-10552 Patch Status Unpatched Published Jun 23, 2026 Affected Software Blue Captcha [blue-captcha] Researcher Kamil Królikowski More Details > Book a Room Event Calendar <= 1.9 - Cross-Site Request Forgery to Settings Update 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9721 Patch Status Unpatched Published Jun 23, 2026 Affected Software Book a Room Event Calendar [book-a-room-event-calendar] Researcher swat More Details > Bulk SEO Image <= 1.1 - Cross-Site Request Forgery to Settings Update 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-11997 Patch Status Unpatched Published Jun 23, 2026 Affected Software Bulk SEO Image [bulk-seo-image] Researcher nishida azuka More Details > Child Theme Wizard <= 1.4 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57655 Patch Status Patched Published Jun 26, 2026 Affected Software Child Theme Wizard [child-theme-wizard] Researcher Ananda Dhakal More Details > Cornerstone < 7.8.8 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9710 Patch Status Patched Published Jun 25, 2026 Affected Software Cornerstone [cornerstone] Researcher Real_King_Engine More Details > Cornerstone < 7.8.9 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9709 Patch Status Patched Published Jun 25, 2026 Affected Software Cornerstone [cornerstone] Researcher Real_King_Engine More Details > Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-11987 Patch Status Patched Published Jun 26, 2026 Affected Software Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy [dokan-lite] Researcher 0xHerc More Details > Eagle Booking <= 1.3.4.3 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2025-68052 Patch Status Unpatched Published Jun 26, 2026 Affected Software Eagle Booking [eagle-booking] Researcher Bonds More Details > Elementor Website Builder – more than just a page builder <= 4.1.3 - Authenticated (Contributor+) Sensitive Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57619 Patch Status Patched Published Jun 25, 2026 Affected Software Elementor Website Builder – more than just a page builder [elementor] Researcher Steven Julian More Details > Email Marketing for WooCommerce by Omnisend <= 1.19.0 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57632 Patch Status Patched Published Jun 26, 2026 Affected Software Email Marketing for WooCommerce by Omnisend [omnisend-connect] Researcher(s): Unknown More Details > Forget About Shortcode Buttons <= 2.1.3 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2025-63041 Patch Status Unpatched Published Jun 26, 2026 Affected Software Forget About Shortcode Buttons [forget-about-shortcode-buttons] Researcher Nabil Irawan More Details > FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57635 Patch Status Patched Published Jun 26, 2026 Affected Software FunnelKit Payment Gateway for Stripe WooCommerce [funnelkit-stripe-woo-payment-gateway] Researcher ParkHyunWoo More Details > Generate Security.txt <= 1.0.12 - Missing Authorization to Authenticated (Subscriber+) Security.txt Deletion via delete_securitytxt AJAX Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9616 Patch Status Unpatched Published Jun 23, 2026 Affected Software Generate Security.txt [generate-security-txt] Researcher Benedictus Jovan (aillesiM) More Details > GetGenie – AI Content Writer with Keyword Research & SEO Tracking <= 4.4.2 - Authenticated (Subscriber+) Sensitive Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57316 Patch Status Patched Published Jun 26, 2026 Affected Software GetGenie – AI Content Writer with Keyword Research & SEO Tracking [getgenie] Researcher Fraudless More Details > Gmail SMTP <= 1.2.3.19 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57657 Patch Status Patched Published Jun 26, 2026 Affected Software Gmail SMTP [gmail-smtp] Researcher Ananda Dhakal More Details > HD Quiz 2.2.0 - 2.2.1 - Cross-Site Request Forgery via Multiple AJAX Handlers 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-13422 Patch Status Patched Published Jun 26, 2026 Affected Software HD Quiz [hd-quiz] Researcher PRISM More Details > Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator <= 1.5.3 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2025-63079 Patch Status Unpatched Published Jun 26, 2026 Affected Software Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator [live-copy-paste] Researcher MD ISMAIL More Details > Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin <= 1.1.7 - Authenticated (Subscriber+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57646 Patch Status Patched Published Jun 26, 2026 Affected Software Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin [majestic-support] Researcher William Matos More Details > Masteriyo LMS <= 2.2.1 - Missing Authorization to Authenticated (Student+) Arbitrary Course Announcement Modification 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-11773 Patch Status Patched Published Jun 26, 2026 Affected Software Masteriyo LMS – LMS Course Builder, Quizzes & Certificates [learning-management-system] Researcher ilinor More Details > MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.30 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57640 Patch Status Patched Published Jun 26, 2026 Affected Software MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] Researcher lagi bljr More Details > MotorDesk <= 1.1.2 - Cross-Site Request Forgery to Settings Update 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9724 Patch Status Unpatched Published Jun 23, 2026 Affected Software MotorDesk [motordesk] Researcher swat More Details > Motors – Car Dealership & Classified Listings Plugin < 1.4.110 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-7859 Patch Status Patched Published Jun 22, 2026 Affected Software Motors – Car Dealership & Classified Listings Plugin [motors-car-dealership-classified-listings] Researcher Mustafa More Details > MP Customize Login Page <= 1.0 - Cross-Site Request Forgery to Settings Update 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-6292 Patch Status Unpatched Published Jun 23, 2026 Affected Software MP Customize Login Page [mp-customize-login-page] Researcher Muhammad Nur Ibnu Hubab More Details > Nelio Content – Editorial Calendar & Social Media Auto-Posting <= 4.3.4 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57648 Patch Status Patched Published Jun 26, 2026 Affected Software Nelio Content – Editorial Calendar & Social Media Auto-Posting [nelio-content] Researcher Averon Averenkov More Details > Newsletters <= 4.13 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57645 Patch Status Patched Published Jun 26, 2026 Affected Software Newsletters [newsletters-lite] Researcher Prodigysec More Details > Paid Memberships Pro - Add Member From Admin <= 0.7.2 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57659 Patch Status Patched Published Jun 26, 2026 Affected Software Paid Memberships Pro - Add Member From Admin [pmpro-add-member-admin] Researcher Nguyen Quang Truong More Details > PPWP – Password Protect Pages <= 1.9.19 - Authenticated (Contributor+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57634 Patch Status Patched Published Jun 26, 2026 Affected Software PPWP – Password Protect Pages [password-protect-page] Researcher Ananda Dhakal More Details > Product Specifications for Woocommerce <= 0.8.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attribute/Group Creation, Modification, and Deletion via 'dwps_modify_groups' and 'dwps_modify_attributes' AJAX Actions 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-11364 Patch Status Patched Published Jun 26, 2026 Affected Software Product Specifications for Woocommerce [product-specifications] Researcher dyingman More Details > Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9233 Patch Status Patched Published Jun 26, 2026 Affected Software Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker [quiz-master-next] Researcher Weerawat Pawanawiwat (ErbaZZ) More Details > Real Estate 7 WordPress <= 3.5.9 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57641 Patch Status Patched Published Jun 26, 2026 Affected Software Real Estate 7 WordPress [realestate-7] Researcher João Pedro S Alcântara (Kinorth) More Details > Restaurant Menu and Food Ordering <= 2.4.11 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2025-63078 Patch Status Unpatched Published Jun 26, 2026 Affected Software Restaurant Menu and Food Ordering [mp-restaurant-menu] Researcher daroo More Details > Reviews and Rating <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via sync_reviews AJAX Action 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-9619 Patch Status Unpatched Published Jun 23, 2026 Affected Software Reviews and Rating – Docplanner [reviews-and-rating-docplanner] Researcher Benedictus Jovan (aillesiM) More Details > SEOPress PRO <= 9.1.1 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57430 Patch Status Patched Published Jun 25, 2026 Affected Software SEOPress PRO [wp-seopress-pro] Researcher MD Shariful Islam More Details > Shoppable Images (Lookbook) for WooCommerce <= 1.3 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57649 Patch Status Patched Published Jun 26, 2026 Affected Software Shoppable Images (Lookbook) for WooCommerce [mabel-shoppable-images-lite] Researcher Ananda Dhakal More Details > Site Reviews <= 8.0.11 - Authenticated (Subscriber+) Sensitive Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57318 Patch Status Patched Published Jun 26, 2026 Affected Software Site Reviews [site-reviews] Researcher Ananda Dhakal More Details > Slim SEO – A Fast & Automated SEO Plugin For WordPress <= 4.6.2 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57429 Patch Status Patched Published Jun 25, 2026 Affected Software Slim SEO – A Fast & Automated SEO Plugin For WordPress [slim-seo] Researcher Abu Hurayra More Details > Spexo <= 2.0.11 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Activation 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-12471 Patch Status Patched Published Jun 26, 2026 Affected Software Spexo [spexo] Researcher adhikara13 More Details > Travel Booking <= 2.2.5 - Authenticated (Subscriber+) Arbitrary File Upload 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-56059 Patch Status Patched Published Jun 25, 2026 Affected Software Travel Booking [travel-booking] Researcher Jamaal ahmed More Details > WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System <= 3.0.14 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57622 Patch Status Patched Published Jun 25, 2026 Affected Software WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] Researcher L4m More Details > WPComplete <= 2.9.5.5 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57661 Patch Status Patched Published Jun 26, 2026 Affected Software WPComplete [wpcomplete] Researcher Md. Minaruzzaman Shovon More Details > Site Kit by Google – Analytics, Search Console, AdSense, Speed < 1.176.0 - Missing Authorization to Authenticated (Editor+) Settings Update 2.7 CVSS Rating 2.7 (Low) CVE-ID CVE-2026-10753 Patch Status Patched Published Jun 25, 2026 Affected Software Site Kit by Google – Analytics, Search Console, AdSense, Speed [google-site-kit] Researcher Shashank More Details > As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence. This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program , and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can. Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. The post Wordfence Intelligence Weekly WordPress Vulnerability Report (June 22, 2026 to June 28, 2026) appeared first on Wordfence .

Share this article