- What: Weekly report of 223 WordPress plugin and theme vulnerabilities
- Impact: WordPress users should review the report to ensure their sites are secure
Last week, there were 223 vulnerabilities disclosed in 175 WordPress Plugins and 6 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 88 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface , vulnerability API , webhook integration , and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back. Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 35,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free . Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. New Firewall Rules Deployed Last Week The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection. The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium , Care , and Response customers last week: Admin and Site Enhancements (ASE) Pro <= 8.9.0 – Unauthenticated Remote Code Execution via PHP Code Injection via cfgroup[input] Repeater Row Key Wordfence Premium , Care , and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay. Total Unpatched & Patched Vulnerabilities Last Week Patch Status Number of Vulnerabilities Patched 155 Unpatched 68 Total Vulnerabilities by CVSS Severity Last Week Severity Rating Number of Vulnerabilities Medium Severity 172 High Severity 42 Critical Severity 9 Total Vulnerabilities by CWE Type Last Week Vulnerability Type by CWE Number of Vulnerabilities Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 70 Missing Authorization 59 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 25 Exposure of Sensitive Information to an Unauthorized Actor 13 Cross-Site Request Forgery (CSRF) 11 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 8 Server-Side Request Forgery (SSRF) 7 Unrestricted Upload of File with Dangerous Type 5 Authorization Bypass Through User-Controlled Key 4 Deserialization of Untrusted Data 4 Improper Authentication 3 Improper Control of Generation of Code ('Code Injection') 3 Improper Privilege Management 3 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 2 Improper Input Validation 2 Incorrect Privilege Assignment 2 Incorrect Authorization 1 Relative Path Traversal 1 Researchers That Contributed to WordPress Security Last Week Researcher Name Number of Vulnerabilities Ananda Dhakal 49 Wordfence PRISM 28 Trương Hữu Phúc (truonghuuphuc) 6 dutafi 6 Que Thanh Tuan 6 Nabil Irawan 5 Phat RiO 5 hhhai 4 Nguyen Ba Khanh 4 daroo 4 João Pedro S Alcântara (Kinorth) 4 Asaf Mozes 3 VanTastic 3 ed32.dll 3 Bao - BlueRock 3 dodoh4t 3 Legion Hunter 3 Abdullah Kareem "cyberkareem" 2 Tran Nguyen Bao Khanh 2 theviper17y 2 Luc Huynh from Noventiq RedTeam 2 Quốc Huy (jtwings) 2 Steven Julian 2 Muhammad Yudha - DJ 2 Expatch 2 ParkHyunWoo 2 Supakiad S. (m3ez) 2 Mitchell 2 CHOIGYEONGMIN 2 Guillermo Álvarez 1 Taylsec 1 HieuPenguinnn 1 Abu Hurayra 1 L4m 1 Arif Shaikh 1 moonge 1 Afan 1 anhcd05 1 Nguyen Cong Quang 1 z3r0s 1 Bonds 1 Mrreee 1 NosleeP++ 1 babyhack 1 gidget smith 1 timomangcut 1 Rafie Muhammad 1 Vamshi Krishna Upadrasta 1 Austin Ginder 1 Dmitrii Ignatyev 1 zaim 1 Osvaldo Noe Gonzalez Del Rio (Os) 1 Derrick Gilliland 1 japaneseknotweed 1 hivesec 1 Thaer Assfour 1 testoun 1 buitu 1 Riyas M S 1 Celvex Group 1 Manopakorn Kooharueangrong (manop55555) 1 WiniS 1 Securepeak Research Team 1 Vincent Szopa (bioflavonoid) 1 Viet Anh Ngo 1 johska 1 luc 1 Abu Hurayra (HurayraIIT) 1 Denny Abraham Sinaga 1 benzdeus 1 jh_hack 1 Mike Montoya 1 zer0gh0st 1 Zainul Anwar Adi Putra 1 qdtad 1 0xd4rk5id3 1 lhking 1 VuNBT 1 duna 1 James Paremain 1 san6051 1 AeonRisk 1 Jonah Burgess (CryptoCat) 1 Levon Balyan 1 Luis Koleski 1 longnv719 1 bashu 1 Robert Hartinger 1 Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program . Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report. WordPress Plugins with Reported Vulnerabilities Last Week Software Name Software Slug Abandoned Cart Lite for WooCommerce woocommerce-abandoned-cart Accept Donations with PayPal & Stripe easy-paypal-donation Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… acf-views AffiliateWP affiliate-wp AffiliateX – Amazon Affiliate Plugin, Product Boxes, Comparison Tables & Affiliate Link Tracking affiliatex AI Copilot – Content Generator ai-copilot-content-generator Appointment Hour Booking – Booking Calendar appointment-hour-booking ARforms arforms Avada Core fusion-core Avada Custom Branding fusion-white-label-branding AWP Classifieds another-wordpress-classifieds-plugin BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot betterdocs Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment booking-and-rental-manager-for-woocommerce Brands for WooCommerce brands-for-woocommerce Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP videowhisper-live-streaming-integration BSK PDF Manager bsk-pdf-manager Bulk Page Generator – LPagery lpagery Byteflows Travel & Hotel Booking byteflows-travel-hotel-booking Checkout Field Editor for WooCommerce (Pro) woocommerce-checkout-field-editor-pro Civi Framework civi-framework CoCart – Headless REST API for WooCommerce cart-rest-api-for-woocommerce Complianz – GDPR/CCPA Cookie Consent complianz-gdpr Contact Form 7 – Dynamic Text Extension contact-form-7-dynamic-text-extension Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More content-control Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates cozy-addons Create mediavine-create Custom links in Elementor Image Carousel custom-links-in-elementor-image-carousel Customer Support Ticket System & Helpdesk wp-ticket Cyr to Lat Reloaded – Transliteration of Links and File Names cyr-and-lat Directory Listings WordPress plugin – uListing ulisting Ditty – Responsive News Tickers, Sliders, and Lists ditty-news-ticker Dokan Pro dokan-pro Dynamic Pricing With Discount Rules for WooCommerce aco-woo-dynamic-pricing Easy Appointments easy-appointments Easy Digital Downloads – eCommerce Payments and Subscriptions made easy easy-digital-downloads Easy Form Builder by WhiteStudio – Drag & Drop Form Builder easy-form-builder Ebook Store ebook-store Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance accessibility-checker eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams eroom-zoom-meetings-webinar Essential Addons for Elementor – Popular Elementor Templates & Widgets essential-addons-for-elementor-lite Event Post event-post Event Tickets and Registration event-tickets EventON Action User eventon-action-user Events Made Easy events-made-easy Falcon – WordPress Optimizations & Tweaks falcon Firelight Lightbox easy-fancybox Flipbook PDF Viewer & Embedder pdf-embed-viewer Fluent Forms Pro Add On Pack fluentformpro Fluent Support – Helpdesk & Customer Support Ticket System fluent-support FormCraft formcraft3 GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress gamipress GiveWP – Donation Plugin and Fundraising Platform give GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more godam Graphina – Charts and Graphs For Elementor graphina-elementor-charts-and-graphs Grid/List View for WooCommerce gridlist-view-for-woocommerce GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor gutenkit-blocks-addon HashThemes Demo Importer hashthemes-demo-importer Header Footer Script Adder header-and-footer-script-adder Hubbub Lite – Fast, free social sharing and follow buttons social-pug JetBooking jet-booking JetElements jet-elements JetEngine jet-engine Kali Forms — Contact Form & Drag-and-Drop Builder kali-forms Kirki – Freeform Page Builder, Website Builder & Customizer kirki Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages convertkit Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more knit-pay Kwayy HTML Sitemap kwayy-html-sitemap LA-Studio Element Kit for Elementor lastudio-element-kit License Manager for WooCommerce license-manager-for-woocommerce LIQUID SPEECH BALLOON liquid-speech-balloon ListingPro Plugin listingpro-plugin Machete machete MailPoet – Newsletters, Email Marketing, and Automation mailpoet Mailster WordPress Newsletter Plugin mailster MapPress – Google Maps, OpenStreetMap & Leaflet mappress-google-maps-for-wordpress MapSVG mapsvg MapSVG – Vector maps, Image maps, Google Maps mapsvg-lite-interactive-vector-maps MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution marketking-multivendor-marketplace-for-woocommerce Masteriyo LMS – LMS Course Builder, Quizzes & Certificates learning-management-system MDJM Event Management mobile-dj-manager Mediavine Control Panel mediavine-control-panel miniOrange Discord Integration miniorange-discord-integration miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon miniorange-login-openid Modula Image Gallery – Photo Grid & Video Gallery modula-best-grid-gallery MountDev AI MCP Connector for WordPress mountdev-ai-mcp-connector MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar mp3-music-player-by-sonaar Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder the-plus-addons-for-block-editor Ninja Forms – The Contact Form Builder That Grows With You ninja-forms Ninja Tables – Easy Data Table Builder ninja-tables Open User Map – Interactive Leaflet Maps open-user-map Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More themeisle-companion Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction paid-member-subscriptions Participants Database participants-database Payment Gateway for PayPal on WooCommerce woo-paypal-gateway Payment Plugins for Stripe WooCommerce woo-stripe-payment PayU India payu-india PeproDev Ultimate Invoice pepro-ultimate-invoice Photo Block – A Modern Image Block With Lightbox and Caption Support photo-block Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery gt3-photo-video-gallery Photo Gallery – Responsive Image Galleries by Supsystic gallery-by-supsystic Picture Gallery – Frontend Image Uploads, AJAX Photo List picture-gallery PiWeb Product Enquiry or product catalog for WooCommerce enquiry-quotation-for-woocommerce Polylang polylang Popup for CF7 with Sweet Alert cf7-sweet-alert-popup Post Grid Gutenberg Blocks – PostX ultimate-post Post My CF7 Form post-my-contact-form-7 Premium Packages – Sell Digital Products Securely wpdm-premium-packages Product Designer for WooCommerce WordPress | Lumise lumise Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces best-woocommerce-feed Product Slider, Product Grid, Product Masonry woocommerce-products-slider Qubely – Advanced Gutenberg Blocks qubely Query Wrangler query-wrangler QuickCal quickcal Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker quiz-master-next Real Estate Manager Pro real-estate-manager-pro Really Simple CSV Importer really-simple-csv-importer Registrations for the Events Calendar – Event Registration Plugin registrations-for-the-events-calendar Relevanssi Light relevanssi-light reviewer reviewer Rich Showcase for Google Reviews widget-google-reviews rtMedia for WordPress, BuddyPress and bbPress buddypress-media SAML Single Sign On – SSO Login miniorange-saml-20-single-sign-on Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce sender-net-automated-emails Shiptastic for WooCommerce shiptastic-for-woocommerce ShipTime: Discount Shipping shiptime-discount-shipping Slider Pro sliderpro Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management smart-manager-for-wp-e-commerce Smart SEO Tool – SEO优化插件 smart-seo-tool SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery sms-alert Spectra Legacy – Gutenberg Blocks ultimate-addons-for-gutenberg Style Kits for Elementor analogwp-templates SUMO Reward Points for WooCommerce rewardsystem Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers sunshine-photo-cart SureDash – Community, Courses & Member Dashboard suredash Tabs Responsive – With WooCommerce Product Tabs Extension tabs-responsive TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Builder templatespare Thrive Quiz Builder thrive-quiz-builder Thrive Themes – Product Manager thrive-product-manager Tickera – Sell Tickets & Manage Events tickera-event-ticketing-system TinyMCE Templates tinymce-templates Tonda Core tonda-core Tutor LMS Elementor Addons tutor-lms-elementor-addons Ultimate Addons for Elementor header-footer-elementor Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor ultimate-store-kit Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin uncanny-automator Video Player for YouTube – embed videos your visitors will love to watch yt-player VikBooking Hotel Booking Engine & PMS vikbooking Virtue/Ascend/Pinnacle Toolkit virtue-toolkit Visual Composer Website Builder visualcomposer Visualizer – Tables & Charts Manager with Built-in AI Generator visualizer WCPOS – Point of Sale (POS) plugin for WooCommerce woocommerce-pos Web Push Notifications – Webpushr webpushr-web-push-notifications WP Accessibility Helper (WAH) wp-accessibility-helper WP Activity Log wp-security-audit-log WP BASE Booking of Appointments, Services and Events wp-base-booking-of-appointments-services-and-events WP Easy Pay – Payment and Donation Form Builder for Square wp-easy-pay WP Encryption – Lifetime Free SSL Cert & HTTPS, Force SSL / HTTPS Redirect, SSL Security wp-letsencrypt-ssl WP Fast Total Search – The Power of Indexed Search fulltext-search WP Foodbakery wp-foodbakery WP Ghost (Hide My WP Ghost) – Security & Firewall hide-my-wp WP Go Maps – Google Map, OpenStreetMap, Leaflet Map wp-google-maps WP Hotel Booking wp-hotel-booking WP Shortcode by MyThemeShop wp-shortcode WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets wp-social-reviews WP-Polls wp-polls WPForms Pro wpforms WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More wpforms-lite WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce wpify-woo WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) wpo365-login Yoast SEO – Advanced SEO with real-time guidance and built-in AI wordpress-seo Ziina ziina ЮKassa для WooCommerce yookassa افزونه حمل و نقل ووکامرس | پست پیشتاز، تیپاکس و پیک موتوری persian-woocommerce-shipping افزونه پرداخت امن زرینپال برای ووکامرس (ZarinPal for WooCommerce) zarinpal-woocommerce-payment-gateway افزونه پیامک ووکامرس Persian WooCommerce SMS persian-woocommerce-sms WordPress Themes with Reported Vulnerabilities Last Week Software Name Software Slug Civi - Job Board & Freelance Marketplace WordPress Theme civi Grand Photography WordPress grandphotography Manual - Documentation, Knowledge Base & Education WordPress Theme manual photography photography TheGem thegem Vino - A Refined Winery, Wine Bar and Vineyard WordPress Theme vino Vulnerability Details Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration , which is completely free to utilize. Customer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Injection via 'path' Parameter 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-15011 Patch Status Patched Published Jul 22, 2026 Affected Software Customer Support Ticket System & Helpdesk [wp-ticket] Researcher theviper17y More Details > Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-13439 Patch Status Patched Published Jul 20, 2026 Affected Software Easy Form Builder by WhiteStudio – Drag & Drop Form Builder [easy-form-builder] Researcher CHOIGYEONGMIN More Details > GoDAM <= 1.12.2 - Unauthenticated Arbitrary File Upload via WPForms File Upload Field 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-14282 Patch Status Patched Published Jul 22, 2026 Affected Software GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more [godam] Researcher CHOIGYEONGMIN More Details > MountDev AI MCP Connector for WordPress <= 1.6.1 - Unauthenticated Privilege Escalation via OAuth Authorization Endpoint 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-15015 Patch Status Patched Published Jul 22, 2026 Affected Software MountDev AI MCP Connector for WordPress [mountdev-ai-mcp-connector] Researcher AeonRisk More Details > SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-15981 Patch Status Patched Published Jul 23, 2026 Affected Software SAML Single Sign On – SSO Login [miniorange-saml-20-single-sign-on] Researcher Supakiad S. (m3ez) More Details > SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery <= 3.9.6 - Unauthenticated Privilege Escalation 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-59540 Patch Status Patched Published Jul 22, 2026 Affected Software SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery [sms-alert] Researcher Taylsec More Details > WP BASE Booking of Appointments, Services and Events <= 6.3.1 - Authenticated (Subscriber+) Privilege Escalation 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-59541 Patch Status Patched Published Jul 22, 2026 Affected Software WP BASE Booking of Appointments, Services and Events [wp-base-booking-of-appointments-services-and-events] Researcher Afan More Details > Broadcast Live Video <= 7.2.4 - Unauthenticated Arbitrary File Deletion 9.1 CVSS Rating 9.1 (Critical) CVE-ID CVE-2026-57716 Patch Status Patched Published Jul 21, 2026 Affected Software Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP [videowhisper-live-streaming-integration] Researcher dutafi More Details > Participants Database <= 2.7.8.3 - Unauthenticated Arbitrary File Deletion 9.1 CVSS Rating 9.1 (Critical) CVE-ID CVE-2026-59555 Patch Status Patched Published Jul 22, 2026 Affected Software Participants Database [participants-database] Researcher hhhai More Details > Fluent Forms Pro Add On Pack <= 6.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change via User Meta Field 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-15962 Patch Status Patched Published Jul 25, 2026 Affected Software Fluent Forms Pro Add On Pack [fluentformpro] Researcher daroo More Details > MDJM Event Management <= 1.7.8.4 - Authenticated (Subscriber+) Privilege Escalation via 'set-permissions' and 'change_role' Handlers 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-15017 Patch Status Patched Published Jul 22, 2026 Affected Software MDJM Event Management [mobile-dj-manager] Researcher moonge More Details > WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 43.2 - Cross-Site Request Forgery to Privilege Escalation via Plugin Settings Update 8.8 CVSS Rating 8.8 (High) CVE-ID CVE-2026-15212 Patch Status Patched Published Jul 23, 2026 Affected Software WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) [wpo365-login] Researcher Osvaldo Noe Gonzalez Del Rio (Os) More Details > Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Contributor+) Arbitrary Connection Deletion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-8789 Patch Status Patched Published Jul 23, 2026 Affected Software Easy Appointments [easy-appointments] Researcher Vamshi Krishna Upadrasta More Details > Kali Forms — Contact Form & Drag-and-Drop Builder <= 2.4.18 - Authenticated (Subscriber+) Arbitrary File Deletion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-59542 Patch Status Patched Published Jul 22, 2026 Affected Software Kali Forms — Contact Form & Drag-and-Drop Builder [kali-forms] Researcher daroo More Details > Picture Gallery – Frontend Image Uploads, AJAX Photo List <= 1.6.5 - Authenticated (Contributor+) Arbitrary File Deletion 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-57696 Patch Status Patched Published Jul 20, 2026 Affected Software Picture Gallery – Frontend Image Uploads, AJAX Photo List [picture-gallery] Researcher hhhai More Details > Thrive Quiz Builder <= 10.9.3.0 - Unauthenticated PHP Object Injection 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-59544 Patch Status Patched Published Jul 22, 2026 Affected Software Thrive Quiz Builder [thrive-quiz-builder] Researcher VanTastic More Details > WP Foodbakery <= 4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via via delete_locations_backup_file AJAX Action 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-15802 Patch Status Unpatched Published Jul 21, 2026 Affected Software WP Foodbakery [wp-foodbakery] Researcher Rafie Muhammad More Details > WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering 8.1 CVSS Rating 8.1 (High) CVE-ID CVE-2026-10818 Patch Status Patched Published Jul 24, 2026 Affected Software WPForms Pro [wpforms] Researcher lhking More Details > WPify Woo <= 5.4.16 - Authenticated (Shop Manager+) Privilege Escalation via Arbitrary Option Update via save_option REST Endpoint 8.0 CVSS Rating 8.0 (High) CVE-ID CVE-2026-12736 Patch Status Patched Published Jul 23, 2026 Affected Software WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce [wpify-woo] Researcher Wordfence PRISM More Details > AWP Classifieds <= 4.4.7 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-59550 Patch Status Patched Published Jul 23, 2026 Affected Software AWP Classifieds [another-wordpress-classifieds-plugin] Researcher Thaer Assfour More Details > Dokan Pro <= 5.0.2 - Authenticated (Subscriber+) PHP Object Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-65493 Patch Status Unpatched Published Jul 23, 2026 Affected Software Dokan Pro [dokan-pro] Researcher Expatch More Details > GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.9.7 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-59538 Patch Status Patched Published Jul 23, 2026 Affected Software GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress [gamipress] Researcher qdtad More Details > MapSVG – Vector maps, Image maps, Google Maps <= 8.14.0 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-59527 Patch Status Patched Published Jul 23, 2026 Affected Software MapSVG – Vector maps, Image maps, Google Maps [mapsvg-lite-interactive-vector-maps] Researcher Trương Hữu Phúc (truonghuuphuc) More Details > MapSVG <= 8.14.0 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-59526 Patch Status Patched Published Jul 23, 2026 Affected Software MapSVG [mapsvg] Researcher Trương Hữu Phúc (truonghuuphuc) More Details > Participants Database <= 2.7.8.3 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-59525 Patch Status Patched Published Jul 22, 2026 Affected Software Participants Database [participants-database] Researcher L4m More Details > Product Designer for WooCommerce WordPress | Lumise <= 2.1.1 - Unauthenticated SQL Injection via 'id' Parameter in Cart JSON Upload 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-9713 Patch Status Patched Published Jul 22, 2026 Affected Software Product Designer for WooCommerce WordPress | Lumise [lumise] Researcher bashu More Details > Relevanssi Light <= 1.2.2 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-59533 Patch Status Patched Published Jul 23, 2026 Affected Software Relevanssi Light [relevanssi-light] Researcher ParkHyunWoo More Details > rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 - Unauthenticated SQL Injection 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-59549 Patch Status Patched Published Jul 23, 2026 Affected Software rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] Researcher Zainul Anwar Adi Putra More Details > Tonda Core <= 2.1.2 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-65477 Patch Status Unpatched Published Jul 22, 2026 Affected Software Tonda Core [tonda-core] Researcher João Pedro S Alcântara (Kinorth) More Details > Vino <= 1.9 - Authenticated (Contributor+) Local File Inclusion 7.5 CVSS Rating 7.5 (High) CVE-ID CVE-2026-65481 Patch Status Unpatched Published Jul 22, 2026 Affected Software Vino - A Refined Winery, Wine Bar and Vineyard WordPress Theme [vino] Researcher João Pedro S Alcântara (Kinorth) More Details > EventON Action User <= 2.5.14 - Missing Authorization to Unauthenticated Privilege Escalation via evoau_save_capability AJAX Action 7.3 CVSS Rating 7.3 (High) CVE-ID CVE-2026-10033 Patch Status Patched Published Jul 23, 2026 Affected Software EventON Action User [eventon-action-user] Researcher Vincent Szopa (bioflavonoid) More Details > 3D Flipbook PDF Viewer & Embedder <= 1.4.2 - Unauthenticated Server-Side Request Forgery 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-59552 Patch Status Patched Published Jul 23, 2026 Affected Software Flipbook PDF Viewer & Embedder [pdf-embed-viewer] Researcher Nabil Irawan More Details > AffiliateX – Amazon Affiliate Plugin, Product Boxes, Comparison Tables & Affiliate Link Tracking <= 2.3.5 - Unauthenticated Server-Side Request Forgery 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-65558 Patch Status Patched Published Jul 24, 2026 Affected Software AffiliateX – Amazon Affiliate Plugin, Product Boxes, Comparison Tables & Affiliate Link Tracking [affiliatex] Researcher Ananda Dhakal More Details > ARforms <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'password' Field Values 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-12421 Patch Status Unpatched Published Jul 22, 2026 Affected Software ARforms [arforms] Researcher Luc Huynh from Noventiq RedTeam More Details > Dokan Pro <= 5.0.0 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-65492 Patch Status Unpatched Published Jul 23, 2026 Affected Software Dokan Pro [dokan-pro] Researcher dutafi More Details > Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-59556 Patch Status Patched Published Jul 24, 2026 Affected Software Dynamic Pricing With Discount Rules for WooCommerce [aco-woo-dynamic-pricing] Researcher Denny Abraham Sinaga More Details > Easy Form Builder by WhiteStudio – Drag & Drop Form Builder <= 4.0.12 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-59517 Patch Status Patched Published Jul 21, 2026 Affected Software Easy Form Builder by WhiteStudio – Drag & Drop Form Builder [easy-form-builder] Researcher dutafi More Details > FormCraft <= 3.9.14 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Sub-Parameters 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-7232 Patch Status Patched Published Jul 22, 2026 Affected Software FormCraft [formcraft3] Researcher Luc Huynh from Noventiq RedTeam More Details > JetBooking <= 4.1.2 - Authenticated (Custom+) Server-Side Request Forgery 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-65466 Patch Status Patched Published Jul 22, 2026 Affected Software JetBooking [jet-booking] Researcher Ananda Dhakal More Details > Mailster - Email Newsletter Plugin for WordPress <= 4.1.17 - Authenticated (Editor+) Arbitrary File Upload 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-27064 Patch Status Patched Published Jul 22, 2026 Affected Software Mailster WordPress Newsletter Plugin [mailster] Researcher Phat RiO More Details > Manual - Documentation, Knowledge Base & Education WordPress <= 7.5.4 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-65511 Patch Status Unpatched Published Jul 23, 2026 Affected Software Manual - Documentation, Knowledge Base & Education WordPress Theme [manual] Researcher ed32.dll More Details > MapSVG – Vector maps, Image maps, Google Maps <= 8.14.0 - Authenticated (Admin+) Arbitrary File Upload 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-65455 Patch Status Patched Published Jul 22, 2026 Affected Software MapSVG – Vector maps, Image maps, Google Maps [mapsvg-lite-interactive-vector-maps] Researcher Securepeak Research Team More Details > MapSVG <= 8.14.0 - Authenticated (Administrator+) Arbitrary File Upload via '/mapsvg/v1/svgfile' Endpoint 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-1771 Patch Status Patched Published Jul 20, 2026 Affected Software MapSVG – Vector maps, Image maps, Google Maps [mapsvg-lite-interactive-vector-maps] Researcher san6051 More Details > PeproDev Ultimate Invoice <= 2.2.6 - Unauthenticated Server-Side Request Forgery 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-65516 Patch Status Unpatched Published Jul 23, 2026 Affected Software PeproDev Ultimate Invoice [pepro-ultimate-invoice] Researcher longnv719 More Details > PeproDev Ultimate Invoice <= 2.2.6 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-65510 Patch Status Unpatched Published Jul 23, 2026 Affected Software PeproDev Ultimate Invoice [pepro-ultimate-invoice] Researcher hhhai More Details > PiWeb Product Enquiry or product catalog for WooCommerce <= 2.2.34.43 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-59512 Patch Status Patched Published Jul 21, 2026 Affected Software PiWeb Product Enquiry or product catalog for WooCommerce [enquiry-quotation-for-woocommerce] Researcher duna More Details > Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces <= 7.6.1 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-59553 Patch Status Patched Published Jul 24, 2026 Affected Software Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces [best-woocommerce-feed] Researcher hhhai More Details > Really Simple CSV Importer <= 1.3 - Authenticated (Admin+) Arbitrary File Upload 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-65461 Patch Status Patched Published Jul 22, 2026 Affected Software Really Simple CSV Importer [really-simple-csv-importer] Researcher Ananda Dhakal More Details > Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management <= 8.90.0 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57704 Patch Status Patched Published Jul 20, 2026 Affected Software Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management [smart-manager-for-wp-e-commerce] Researcher Nguyen Ba Khanh More Details > SUMO Reward Points for WooCommerce <= 32.7.0 - Unauthenticated Stored Cross-Site Scripting via 'reason' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-7534 Patch Status Patched Published Jul 22, 2026 Affected Software SUMO Reward Points for WooCommerce [rewardsystem] Researcher Nguyen Cong Quang More Details > VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' Parameter 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-15401 Patch Status Patched Published Jul 23, 2026 Affected Software VikBooking Hotel Booking Engine & PMS [vikbooking] Researcher Wordfence PRISM More Details > Complianz – GDPR/CCPA Cookie Consent <= 7.5.1 - Authenticated (Administrator+) PHP Object Injection 6.6 CVSS Rating 6.6 (Medium) CVE-ID CVE-2026-65497 Patch Status Unpatched Published Jul 22, 2026 Affected Software Complianz – GDPR/CCPA Cookie Consent [complianz-gdpr] Researcher Ananda Dhakal More Details > AI Copilot <= 1.5.4 - Authenticated (Subscriber+) SQL Injection via 'order[0][dir]' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-13009 Patch Status Patched Published Jul 22, 2026 Affected Software AI Copilot – Content Generator [ai-copilot-content-generator] Researcher Wordfence PRISM More Details > Checkout Field Editor for WooCommerce (Pro) <= 3.7.7 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read via 'thwcfe_legacy_file' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-14955 Patch Status Patched Published Jul 24, 2026 Affected Software Checkout Field Editor for WooCommerce (Pro) [woocommerce-checkout-field-editor-pro] Researcher 0xd4rk5id3 More Details > Contact Form 7 – Dynamic Text Extension <= 5.0.6 - Unauthenticated Arbitrary Shortcode Execution 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2025-13146 Patch Status Unpatched Published Jul 21, 2026 Affected Software Contact Form 7 – Dynamic Text Extension [contact-form-7-dynamic-text-extension] Researcher NosleeP++ More Details > Create <= 2.5.3 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-24552 Patch Status Unpatched Published Jul 22, 2026 Affected Software Create [mediavine-create] Researcher Nabil Irawan More Details > Dokan Pro <= 5.0.2 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-65494 Patch Status Unpatched Published Jul 23, 2026 Affected Software Dokan Pro [dokan-pro] Researcher Expatch More Details > eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams <= 1.7.1 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-25405 Patch Status Unpatched Published Jul 22, 2026 Affected Software eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams [eroom-zoom-meetings-webinar] Researcher Trương Hữu Phúc (truonghuuphuc) More Details > MapSVG – Vector maps, Image maps, Google Maps <= 8.14.0 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-65450 Patch Status Patched Published Jul 22, 2026 Affected Software MapSVG – Vector maps, Image maps, Google Maps [mapsvg-lite-interactive-vector-maps] Researcher Trương Hữu Phúc (truonghuuphuc) More Details > MapSVG <= 8.14.0 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-65451 Patch Status Patched Published Jul 22, 2026 Affected Software MapSVG [mapsvg] Researcher Trương Hữu Phúc (truonghuuphuc) More Details > Premium Packages <= 7.0.4 - Authenticated (Admin+) SQL Injection via 'orderby' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-15906 Patch Status Patched Published Jul 22, 2026 Affected Software Premium Packages – Sell Digital Products Securely [wpdm-premium-packages] Researcher Wordfence PRISM More Details > Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker <= 11.2.0 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-65454 Patch Status Patched Published Jul 22, 2026 Affected Software Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker [quiz-master-next] Researcher anhcd05 More Details > Registrations for the Events Calendar <= 3.2 - Authenticated (Contributor+) SQL Injection via 'standard' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-13119 Patch Status Patched Published Jul 22, 2026 Affected Software Registrations for the Events Calendar – Event Registration Plugin [registrations-for-the-events-calendar] Researcher Wordfence PRISM More Details > rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 - Authenticated (Subscriber+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-59551 Patch Status Patched Published Jul 23, 2026 Affected Software rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] Researcher Abdullah Kareem "cyberkareem" More Details > Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_event_filter' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-15761 Patch Status Patched Published Jul 22, 2026 Affected Software Tickera – Sell Tickets & Manage Events [tickera-event-ticketing-system] Researcher Wordfence PRISM More Details > Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_order_status_filter' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-15448 Patch Status Patched Published Jul 22, 2026 Affected Software Tickera – Sell Tickets & Manage Events [tickera-event-ticketing-system] Researcher Wordfence PRISM More Details > Visualizer – Tables & Charts Manager with Built-in AI Generator <= 4.0.6 - Authenticated (Contributor+) SQL Injection 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-65526 Patch Status Unpatched Published Jul 23, 2026 Affected Software Visualizer – Tables & Charts Manager with Built-in AI Generator [visualizer] Researcher ParkHyunWoo More Details > WCPOS <= 1.9.8 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read via 'type' Parameter 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-16078 Patch Status Patched Published Jul 22, 2026 Affected Software WCPOS – Point of Sale (POS) plugin for WooCommerce [woocommerce-pos] Researcher Wordfence PRISM More Details > Accept Donations with PayPal & Stripe <= 1.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65518 Patch Status Patched Published Jul 23, 2026 Affected Software Accept Donations with PayPal & Stripe [easy-paypal-donation] Researcher Ananda Dhakal More Details > Appointment Hour Booking – Booking Calendar <= 1.5.86 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65514 Patch Status Patched Published Jul 23, 2026 Affected Software Appointment Hour Booking – Booking Calendar [appointment-hour-booking] Researcher Ananda Dhakal More Details > BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot <= 4.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65562 Patch Status Patched Published Jul 24, 2026 Affected Software BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot [betterdocs] Researcher Ananda Dhakal More Details > Brands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15646 Patch Status Patched Published Jul 22, 2026 Affected Software Brands for WooCommerce [brands-for-woocommerce] Researcher Wordfence PRISM More Details > Brands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'width' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15648 Patch Status Patched Published Jul 23, 2026 Affected Software Brands for WooCommerce [brands-for-woocommerce] Researcher Wordfence PRISM More Details > BSK PDF Manager <= 3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65528 Patch Status Unpatched Published Jul 23, 2026 Affected Software BSK PDF Manager [bsk-pdf-manager] Researcher luc More Details > Bulk Page Generator <= 2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15404 Patch Status Patched Published Jul 22, 2026 Affected Software Bulk Page Generator – LPagery [lpagery] Researcher Wordfence PRISM More Details > Complianz – GDPR/CCPA Cookie Consent <= 7.5.1 - Authenticated (Author+) Server-Side Request Forgery 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65496 Patch Status Unpatched Published Jul 22, 2026 Affected Software Complianz – GDPR/CCPA Cookie Consent [complianz-gdpr] Researcher Ananda Dhakal More Details > Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15333 Patch Status Patched Published Jul 23, 2026 Affected Software Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates [cozy-addons] Researcher Wordfence PRISM More Details > Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon.view' Block Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15334 Patch Status Patched Published Jul 23, 2026 Affected Software Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates [cozy-addons] Researcher Wordfence PRISM More Details > Custom links in Elementor Image Carousel <= 1.1.1 - Authenticated (Author+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65534 Patch Status Unpatched Published Jul 23, 2026 Affected Software Custom links in Elementor Image Carousel [custom-links-in-elementor-image-carousel] Researcher Ananda Dhakal More Details > Equalize Digital Accessibility Checker <= 1.46.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'html' Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-14481 Patch Status Patched Published Jul 22, 2026 Affected Software Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance [accessibility-checker] Researcher Wordfence PRISM More Details > Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15145 Patch Status Patched Published Jul 20, 2026 Affected Software Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] Researcher Asaf Mozes More Details > Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15156 Patch Status Patched Published Jul 20, 2026 Affected Software Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] Researcher Jonah Burgess (CryptoCat) More Details > Firelight Lightbox <= 2.3.20 - Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-6454 Patch Status Patched Published Jul 23, 2026 Affected Software Firelight Lightbox [easy-fancybox] Researcher Quốc Huy (jtwings) More Details > Fluent Support – Helpdesk & Customer Support Ticket System <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65470 Patch Status Patched Published Jul 22, 2026 Affected Software Fluent Support – Helpdesk & Customer Support Ticket System [fluent-support] Researcher Ananda Dhakal More Details > Fluent Support <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15665 Patch Status Patched Published Jul 23, 2026 Affected Software Fluent Support – Helpdesk & Customer Support Ticket System [fluent-support] Researcher Wordfence PRISM More Details > Grid/List View for WooCommerce <= 3.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'position' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15794 Patch Status Patched Published Jul 22, 2026 Affected Software Grid/List View for WooCommerce [gridlist-view-for-woocommerce] Researcher Wordfence PRISM More Details > HashThemes Demo Importer <= 1.4.2 - Authenticated (Author+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65483 Patch Status Unpatched Published Jul 22, 2026 Affected Software HashThemes Demo Importer [hashthemes-demo-importer] Researcher Mike Montoya More Details > Header Footer Script Adder <= 2.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'asm_code' Snippet Meta 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15394 Patch Status Patched Published Jul 22, 2026 Affected Software Header Footer Script Adder [header-and-footer-script-adder] Researcher Wordfence PRISM More Details > Hubbub Lite <= 1.36.3 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-27403 Patch Status Patched Published Jul 22, 2026 Affected Software Hubbub Lite – Fast, free social sharing and follow buttons [social-pug] Researcher zaim More Details > JetElements <= 2.9.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65465 Patch Status Patched Published Jul 22, 2026 Affected Software JetElements [jet-elements] Researcher Ananda Dhakal More Details > JetEngine <= 3.8.11 - Authenticated (Contributor+) Sever-Side Request Forgery 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65467 Patch Status Patched Published Jul 22, 2026 Affected Software JetEngine [jet-engine] Researcher Ananda Dhakal More Details > LA-Studio Element Kit for Elementor <= 1.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65482 Patch Status Unpatched Published Jul 22, 2026 Affected Software LA-Studio Element Kit for Elementor [lastudio-element-kit] Researcher Abu Hurayra More Details > LIQUID SPEECH BALLOON <= 1.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65527 Patch Status Unpatched Published Jul 23, 2026 Affected Software LIQUID SPEECH BALLOON [liquid-speech-balloon] Researcher Ananda Dhakal More Details > Machete <= 5.2 - Authenticated (Author+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65538 Patch Status Unpatched Published Jul 23, 2026 Affected Software Machete [machete] Researcher Ananda Dhakal More Details > Manual - Documentation, Knowledge Base & Education WordPress <= 7.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65522 Patch Status Unpatched Published Jul 22, 2026 Affected Software Manual - Documentation, Knowledge Base & Education WordPress Theme [manual] Researcher ed32.dll More Details > MapSVG – Vector maps, Image maps, Google Maps <= 8.14.0 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65449 Patch Status Patched Published Jul 22, 2026 Affected Software MapSVG – Vector maps, Image maps, Google Maps [mapsvg-lite-interactive-vector-maps] Researcher johska More Details > MapSVG Lite <= 8.14.0 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2025-9205 Patch Status Patched Published Jul 23, 2026 Affected Software MapSVG – Vector maps, Image maps, Google Maps [mapsvg-lite-interactive-vector-maps] Researcher zer0gh0st More Details > Masteriyo LMS – LMS Course Builder, Quizzes & Certificates <= 2.3.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-59513 Patch Status Patched Published Jul 21, 2026 Affected Software Masteriyo LMS – LMS Course Builder, Quizzes & Certificates [learning-management-system] Researcher(s): Unknown More Details > miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65561 Patch Status Patched Published Jul 24, 2026 Affected Software miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon [miniorange-login-openid] Researcher Ananda Dhakal More Details > Modula Image Gallery – Photo Grid & Video Gallery 2.14.25-2.14.30 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65475 Patch Status Patched Published Jul 22, 2026 Affected Software Modula Image Gallery – Photo Grid & Video Gallery [modula-best-grid-gallery] Researcher Abdullah Kareem "cyberkareem" More Details > Open User Map <= 1.4.45 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15755 Patch Status Patched Published Jul 23, 2026 Affected Software Open User Map – Interactive Leaflet Maps [open-user-map] Researcher Quốc Huy (jtwings) More Details > Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More <= 3.0.7 - Authenticated (Author+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65563 Patch Status Patched Published Jul 24, 2026 Affected Software Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] Researcher Ananda Dhakal More Details > Photo Block – A Modern Image Block With Lightbox and Caption Support <= 1.7.1 - Authenticated (Author+) Sever-Side Request Forgery 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-24639 Patch Status Unpatched Published Jul 22, 2026 Affected Software Photo Block – A Modern Image Block With Lightbox and Caption Support [photo-block] Researcher Arif Shaikh More Details > Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery <= 2.7.7.29 - Authenticated (Author+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65519 Patch Status Patched Published Jul 23, 2026 Affected Software Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery [gt3-photo-video-gallery] Researcher Ananda Dhakal More Details > Post Grid Gutenberg Blocks <= 5.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'searchnoresult' Block Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15100 Patch Status Patched Published Jul 23, 2026 Affected Software Post Grid Gutenberg Blocks – PostX [ultimate-post] Researcher Wordfence PRISM More Details > Rich Showcase for Google Reviews <= 6.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pagination' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15739 Patch Status Patched Published Jul 23, 2026 Affected Software Rich Showcase for Google Reviews [widget-google-reviews] Researcher Wordfence PRISM More Details > Slider Pro <= 4.8.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-57699 Patch Status Patched Published Jul 20, 2026 Affected Software Slider Pro [sliderpro] Researcher Manopakorn Kooharueangrong (manop55555) More Details > Smart SEO Tool – SEO优化插件 <= 4.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65533 Patch Status Unpatched Published Jul 23, 2026 Affected Software Smart SEO Tool – SEO优化插件 [smart-seo-tool] Researcher Ananda Dhakal More Details > Spectra Gutenberg Blocks <= 2.19.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-12900 Patch Status Patched Published Jul 20, 2026 Affected Software Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] Researcher theviper17y More Details > SureDash <= 1.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15821 Patch Status Patched Published Jul 23, 2026 Affected Software SureDash – Community, Courses & Member Dashboard [suredash] Researcher Wordfence PRISM More Details > TheGem <= 5.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65480 Patch Status Unpatched Published Jul 22, 2026 Affected Software TheGem [thegem] Researcher João Pedro S Alcântara (Kinorth) More Details > Ultimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15787 Patch Status Patched Published Jul 21, 2026 Affected Software Ultimate Addons for Elementor [header-footer-elementor] Researcher Asaf Mozes More Details > Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor <= 3.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65503 Patch Status Patched Published Jul 22, 2026 Affected Software Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor [ultimate-store-kit] Researcher Nguyen Ba Khanh More Details > Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 - Authenticated (Contributor+) Stored Cross-Site Scripting 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-65473 Patch Status Patched Published Jul 22, 2026 Affected Software Virtue/Ascend/Pinnacle Toolkit [virtue-toolkit] Researcher Ananda Dhakal More Details > Visualizer <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'backend-title' Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15653 Patch Status Patched Published Jul 23, 2026 Affected Software Visualizer – Tables & Charts Manager with Built-in AI Generator [visualizer] Researcher Wordfence PRISM More Details > Web Push Notifications <= 4.39.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'webpushr_notification_title' Post Meta Parameter 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-9729 Patch Status Unpatched Published Jul 22, 2026 Affected Software Web Push Notifications – Webpushr [webpushr-web-push-notifications] Researcher Muhammad Yudha - DJ More Details > WP Hotel Booking <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15464 Patch Status Patched Published Jul 23, 2026 Affected Software WP Hotel Booking [wp-hotel-booking] Researcher Wordfence PRISM More Details > WP Shortcode by MyThemeShop <= 1.4.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-9635 Patch Status Unpatched Published Jul 22, 2026 Affected Software WP Shortcode by MyThemeShop [wp-shortcode] Researcher Muhammad Yudha - DJ More Details > Yoast SEO <= 28.0 - Authenticated (Author+) Stored Cross-Site Scripting via Post Slug (post_name) 6.4 CVSS Rating 6.4 (Medium) CVE-ID CVE-2026-15425 Patch Status Patched Published Jul 24, 2026 Affected Software Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] Researcher Dmitrii Ignatyev More Details > Premium Packages <= 7.0.4 - Authentication Bypass to Non-Admin via 'wpdmppdl' Parameter 6.3 CVSS Rating 6.3 (Medium) CVE-ID CVE-2026-15348 Patch Status Patched Published Jul 22, 2026 Affected Software Premium Packages – Sell Digital Products Securely [wpdm-premium-packages] Researcher Wordfence PRISM More Details > AffiliateWP <= 2.34.0 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-57809 Patch Status Patched Published Jul 21, 2026 Affected Software AffiliateWP [affiliate-wp] Researcher dutafi More Details > Grand Photography WordPress <= 5.7.8 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-57769 Patch Status Unpatched Published Jul 21, 2026 Affected Software Grand Photography WordPress [grandphotography] Researcher Tran Nguyen Bao Khanh More Details > Real Estate Manager Pro <= 12.8.5 - Reflected Cross-Site Scripting 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-57701 Patch Status Patched Published Jul 20, 2026 Affected Software Real Estate Manager Pro [real-estate-manager-pro] Researcher dutafi More Details > VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Reflected Cross-Site Scripting via 'category_id' Parameter 6.1 CVSS Rating 6.1 (Medium) CVE-ID CVE-2026-15346 Patch Status Patched Published Jul 23, 2026 Affected Software VikBooking Hotel Booking Engine & PMS [vikbooking] Researcher Wordfence PRISM More Details > AWP Classifieds <= 4.4.7 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65469 Patch Status Patched Published Jul 22, 2026 Affected Software AWP Classifieds [another-wordpress-classifieds-plugin] Researcher z3r0s More Details > Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment <= 2.7.2 - Unauthenticated Price Maniputlation 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-59532 Patch Status Patched Published Jul 23, 2026 Affected Software Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment [booking-and-rental-manager-for-woocommerce] Researcher dodoh4t More Details > Byteflows Travel & Hotel Booking <= 1.0.0 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-59548 Patch Status Patched Published Jul 23, 2026 Affected Software Byteflows Travel & Hotel Booking [byteflows-travel-hotel-booking] Researcher Ananda Dhakal More Details > Civi - Job Board & Freelance Marketplace WordPress Theme <= 2.2.4 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65476 Patch Status Unpatched Published Jul 22, 2026 Affected Software Civi - Job Board & Freelance Marketplace WordPress Theme [civi] Researcher João Pedro S Alcântara (Kinorth) More Details > Civi Framework <= 2.2.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65525 Patch Status Unpatched Published Jul 23, 2026 Affected Software Civi Framework [civi-framework] Researcher Tran Nguyen Bao Khanh More Details > CoCart – Headless REST API for WooCommerce <= 4.8.4 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-59536 Patch Status Patched Published Jul 23, 2026 Affected Software CoCart – Headless REST API for WooCommerce [cart-rest-api-for-woocommerce] Researcher VanTastic More Details > Complianz – GDPR/CCPA Cookie Consent <= 7.5.1 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65498 Patch Status Unpatched Published Jul 22, 2026 Affected Software Complianz – GDPR/CCPA Cookie Consent [complianz-gdpr] Researcher Ananda Dhakal More Details > Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More <= 2.6.5 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65485 Patch Status Unpatched Published Jul 22, 2026 Affected Software Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More [content-control] Researcher Que Thanh Tuan More Details > Create <= 2.5.3 - Unauthenticated Sensitive Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65490 Patch Status Unpatched Published Jul 22, 2026 Affected Software Create [mediavine-create] Researcher Que Thanh Tuan More Details > Ditty – Responsive News Tickers, Sliders, and Lists <= 3.1.66 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-27355 Patch Status Patched Published Jul 22, 2026 Affected Software Ditty – Responsive News Tickers, Sliders, and Lists [ditty-news-ticker] Researcher Legion Hunter More Details > Dokan Pro <= 5.0.3 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65495 Patch Status Unpatched Published Jul 23, 2026 Affected Software Dokan Pro [dokan-pro] Researcher VanTastic More Details > Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.6.7 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-59524 Patch Status Patched Published Jul 22, 2026 Affected Software Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] Researcher James Paremain More Details > Ebook Store <= 6.19 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65452 Patch Status Patched Published Jul 22, 2026 Affected Software Ebook Store [ebook-store] Researcher benzdeus More Details > Ebook Store <= 6.19 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65453 Patch Status Patched Published Jul 22, 2026 Affected Software Ebook Store [ebook-store] Researcher Nabil Irawan More Details > Ebook Store <= 6.19 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-59529 Patch Status Patched Published Jul 23, 2026 Affected Software Ebook Store [ebook-store] Researcher hivesec More Details > Event Post <= 6.1.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65486 Patch Status Unpatched Published Jul 22, 2026 Affected Software Event Post [event-post] Researcher Que Thanh Tuan More Details > Event Tickets and Registration <= 5.29.0.1 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65567 Patch Status Patched Published Jul 24, 2026 Affected Software Event Tickets and Registration [event-tickets] Researcher Ananda Dhakal More Details > Events Made Easy <= 3.1.3 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-59557 Patch Status Patched Published Jul 24, 2026 Affected Software Events Made Easy [events-made-easy] Researcher HieuPenguinnn More Details > Falcon – WordPress Optimizations & Tweaks <= 2.10.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-59531 Patch Status Patched Published Jul 23, 2026 Affected Software Falcon – WordPress Optimizations & Tweaks [falcon] Researcher dodoh4t More Details > Graphina – Charts and Graphs For Elementor <= 3.1.12 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65529 Patch Status Unpatched Published Jul 23, 2026 Affected Software Graphina – Charts and Graphs For Elementor [graphina-elementor-charts-and-graphs] Researcher Ananda Dhakal More Details > GutenKit <= 2.4.12 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Mailchimp REST Endpoints 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-15827 Patch Status Patched Published Jul 22, 2026 Affected Software GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor [gutenkit-blocks-addon] Researcher Viet Anh Ngo More Details > JetBooking <= 4.1.2 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65468 Patch Status Patched Published Jul 22, 2026 Affected Software JetBooking [jet-booking] Researcher Ananda Dhakal More Details > Kirki <= 6.0.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'context' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-13464 Patch Status Patched Published Jul 23, 2026 Affected Software Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] Researcher Abu Hurayra (HurayraIIT) More Details > Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages <= 3.3.5 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65472 Patch Status Patched Published Jul 22, 2026 Affected Software Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages [convertkit] Researcher Ananda Dhakal More Details > Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more <= 9.6.0.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-57717 Patch Status Patched Published Jul 21, 2026 Affected Software Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more [knit-pay] Researcher Riyas M S More Details > LA-Studio Element Kit for Elementor <= 1.6.2 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65489 Patch Status Unpatched Published Jul 22, 2026 Affected Software LA-Studio Element Kit for Elementor [lastudio-element-kit] Researcher Steven Julian More Details > Manual - Documentation, Knowledge Base & Education WordPress <= 7.5.4 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65500 Patch Status Unpatched Published Jul 23, 2026 Affected Software Manual - Documentation, Knowledge Base & Education WordPress Theme [manual] Researcher ed32.dll More Details > MapPress – Google Maps, OpenStreetMap & Leaflet <= 2.97.6 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65564 Patch Status Patched Published Jul 24, 2026 Affected Software MapPress – Google Maps, OpenStreetMap & Leaflet [mappress-google-maps-for-wordpress] Researcher Ananda Dhakal More Details > MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution <= 2.1.40 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-27399 Patch Status Patched Published Jul 21, 2026 Affected Software MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution [marketking-multivendor-marketplace-for-woocommerce] Researcher Legion Hunter More Details > miniOrange Discord Integration <= 2.2.4 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-59545 Patch Status Patched Published Jul 22, 2026 Affected Software miniOrange Discord Integration [miniorange-discord-integration] Researcher buitu More Details > MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.12 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65506 Patch Status Patched Published Jul 22, 2026 Affected Software MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] Researcher Ananda Dhakal More Details > Ninja Tables – Easy Data Table Builder <= 5.2.10 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65474 Patch Status Patched Published Jul 22, 2026 Affected Software Ninja Tables – Easy Data Table Builder [ninja-tables] Researcher Ananda Dhakal More Details > Participants Database <= 2.7.8.3 - Missing Authorization to Unauthenticated Arbitrary Record Update / Sensitive Information Exposure via 'id' Parameter 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-11354 Patch Status Patched Published Jul 23, 2026 Affected Software Participants Database [participants-database] Researcher Robert Hartinger More Details > Payment Gateway for PayPal on WooCommerce <= 9.1.4 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-59547 Patch Status Patched Published Jul 22, 2026 Affected Software Payment Gateway for PayPal on WooCommerce [woo-paypal-gateway] Researcher Ananda Dhakal More Details > Payment Plugins for Stripe WooCommerce <= 4.0.7 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-59530 Patch Status Patched Published Jul 23, 2026 Affected Software Payment Plugins for Stripe WooCommerce [woo-stripe-payment] Researcher timomangcut More Details > Payment Plugins for Stripe WooCommerce <= 4.0.7 - Missing Authorization to Unauthenticated Arbitrary Order Status Modification via Empty Webhook Secret 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-12654 Patch Status Patched Published Jul 23, 2026 Affected Software Payment Plugins for Stripe WooCommerce [woo-stripe-payment] Researcher gidget smith More Details > PayU CommercePro Plugin <= 3.8.9 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-61954 Patch Status Patched Published Jul 22, 2026 Affected Software PayU India [payu-india] Researcher Ananda Dhakal More Details > PeproDev Ultimate Invoice <= 2.2.6 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65499 Patch Status Unpatched Published Jul 23, 2026 Affected Software PeproDev Ultimate Invoice [pepro-ultimate-invoice] Researcher babyhack More Details > PeproDev Ultimate Invoice <= 2.2.6 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-27372 Patch Status Unpatched Published Jul 23, 2026 Affected Software PeproDev Ultimate Invoice [pepro-ultimate-invoice] Researcher Derrick Gilliland More Details > Photography <= 7.7.6 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65487 Patch Status Unpatched Published Jul 22, 2026 Affected Software photography [photography] Researcher Phat RiO More Details > Post My CF7 Form <= 6.2.0 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-59534 Patch Status Patched Published Jul 23, 2026 Affected Software Post My CF7 Form [post-my-contact-form-7] Researcher Mitchell More Details > Qubely – Advanced Gutenberg Blocks <= 1.8.14 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65531 Patch Status Unpatched Published Jul 23, 2026 Affected Software Qubely – Advanced Gutenberg Blocks [qubely] Researcher Ananda Dhakal More Details > Shiptastic for WooCommerce <= 5.1.0 - Unauthenticated Insecure Direct Object Reference 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65501 Patch Status Patched Published Jul 22, 2026 Affected Software Shiptastic for WooCommerce [shiptastic-for-woocommerce] Researcher Guillermo Álvarez More Details > Thrive Themes – Product Manager <= 10.9.2 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-59535 Patch Status Patched Published Jul 23, 2026 Affected Software Thrive Themes – Product Manager [thrive-product-manager] Researcher Austin Ginder More Details > Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor <= 3.0.5 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65505 Patch Status Patched Published Jul 22, 2026 Affected Software Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor [ultimate-store-kit] Researcher Bao - BlueRock More Details > WP Fast Total Search – The Power of Indexed Search <= 1.81.282 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-27418 Patch Status Unpatched Published Jul 22, 2026 Affected Software WP Fast Total Search – The Power of Indexed Search [fulltext-search] Researcher Que Thanh Tuan More Details > WP Go Maps – Google Map, OpenStreetMap, Leaflet Map <= 10.1.05 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-25466 Patch Status Patched Published Jul 22, 2026 Affected Software WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] Researcher Bao - BlueRock More Details > WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets <= 4.3.0 - Unauthenticated Information Exposure 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-65521 Patch Status Patched Published Jul 23, 2026 Affected Software WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets [wp-social-reviews] Researcher Ananda Dhakal More Details > YT Player – Embed and Customize Video Players <= 2.0.9 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-27422 Patch Status Unpatched Published Jul 22, 2026 Affected Software Video Player for YouTube – embed videos your visitors will love to watch [yt-player] Researcher Que Thanh Tuan More Details > Ziina <= 1.2.21 - Missing Authorization 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-59554 Patch Status Patched Published Jul 22, 2026 Affected Software Ziina [ziina] Researcher Mitchell More Details > Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' Key 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-15663 Patch Status Patched Published Jul 23, 2026 Affected Software Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] Researcher Wordfence PRISM More Details > Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 - Authenticated (Administrator+) SQL Injection 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-59537 Patch Status Patched Published Jul 23, 2026 Affected Software Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce [sender-net-automated-emails] Researcher Ananda Dhakal More Details > Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.3.2 - Authenticated (Administrator+) SQL Injection 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-65462 Patch Status Patched Published Jul 22, 2026 Affected Software Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin [uncanny-automator] Researcher Ananda Dhakal More Details > WPForms <= 2.0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-15782 Patch Status Patched Published Jul 20, 2026 Affected Software WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] Researcher Asaf Mozes More Details > افزونه پیامک ووکامرس Persian WooCommerce SMS <= 7.2.2 - Authenticated (Shop manager+) SQL Injection 4.9 CVSS Rating 4.9 (Medium) CVE-ID CVE-2026-65532 Patch Status Unpatched Published Jul 23, 2026 Affected Software افزونه پیامک ووکامرس Persian WooCommerce SMS [persian-woocommerce-sms] Researcher Ananda Dhakal More Details > Abandoned Cart Lite for WooCommerce <= 6.8.0 - Authenticated (Shop manager+) Stored Cross-Site Scripting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-65557 Patch Status Patched Published Jul 24, 2026 Affected Software Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] Researcher Ananda Dhakal More Details > Brands for WooCommerce <= 3.8.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-15647 Patch Status Patched Published Jul 22, 2026 Affected Software Brands for WooCommerce [brands-for-woocommerce] Researcher Wordfence PRISM More Details > Photo Gallery – Responsive Image Galleries by Supsystic <= 1.16.3 - Authenticated (Administrator+) Stored Cross-Site Scripting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-24628 Patch Status Unpatched Published Jul 22, 2026 Affected Software Photo Gallery – Responsive Image Galleries by Supsystic [gallery-by-supsystic] Researcher Mrreee More Details > Tabs Responsive – With WooCommerce Product Tabs Extension <= 2.5 - Authenticated (Shop manager+) Stored Cross-Site Scripting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-65550 Patch Status Unpatched Published Jul 22, 2026 Affected Software Tabs Responsive – With WooCommerce Product Tabs Extension [tabs-responsive] Researcher Ananda Dhakal More Details > WP Encryption <= 7.8.6.6 - Authenticated (Administrator+) Arbitrary File Write via 'imploded' Parameter 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2026-15786 Patch Status Patched Published Jul 22, 2026 Affected Software WP Encryption – Lifetime Free SSL Cert & HTTPS, Force SSL / HTTPS Redirect, SSL Security [wp-letsencrypt-ssl] Researcher Wordfence PRISM More Details > WP-Polls <= 2.77.3 - Authenticated (Administrator+) Stored Cross-Site Scripting 4.4 CVSS Rating 4.4 (Medium) CVE-ID CVE-2025-68081 Patch Status Unpatched Published Jul 22, 2026 Affected Software WP-Polls [wp-polls] Researcher japaneseknotweed More Details > Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… <= 3.8.11 - Authenticated (Subscriber+) Remote Code Execution 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-59543 Patch Status Patched Published Jul 22, 2026 Affected Software Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… [acf-views] Researcher Nguyen Ba Khanh More Details > Avada Core <= 5.15.6 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65471 Patch Status Patched Published Jul 22, 2026 Affected Software Avada Core [fusion-core] Researcher Luis Koleski More Details > Avada Custom Branding <= 1.2 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65524 Patch Status Unpatched Published Jul 23, 2026 Affected Software Avada Custom Branding [fusion-white-label-branding] Researcher Bonds More Details > Cyr to Lat Reloaded – Transliteration of Links and File Names <= 1.3.3 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65537 Patch Status Patched Published Jul 23, 2026 Affected Software Cyr to Lat Reloaded – Transliteration of Links and File Names [cyr-and-lat] Researcher Ananda Dhakal More Details > Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-27392 Patch Status Unpatched Published Jul 22, 2026 Affected Software Directory Listings WordPress plugin – uListing [ulisting] Researcher daroo More Details > Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-27391 Patch Status Unpatched Published Jul 22, 2026 Affected Software Directory Listings WordPress plugin – uListing [ulisting] Researcher daroo More Details > eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams <= 1.7.1 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-25427 Patch Status Unpatched Published Jul 22, 2026 Affected Software eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams [eroom-zoom-meetings-webinar] Researcher Nabil Irawan More Details > GiveWP – Donation Plugin and Fundraising Platform <= 4.16.3 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65464 Patch Status Patched Published Jul 22, 2026 Affected Software GiveWP – Donation Plugin and Fundraising Platform [give] Researcher jh_hack More Details > Kwayy HTML Sitemap <= 4.0 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65539 Patch Status Unpatched Published Jul 23, 2026 Affected Software Kwayy HTML Sitemap [kwayy-html-sitemap] Researcher Ananda Dhakal More Details > LA-Studio Element Kit for Elementor <= 1.6.2 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65488 Patch Status Unpatched Published Jul 22, 2026 Affected Software LA-Studio Element Kit for Elementor [lastudio-element-kit] Researcher Steven Julian More Details > License Manager for WooCommerce <= 3.0.17 - Authenticated (Customer+) Arbitrary Content Deletion 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-61958 Patch Status Patched Published Jul 21, 2026 Affected Software License Manager for WooCommerce [license-manager-for-woocommerce] Researcher WiniS More Details > ListingPro Plugin <= 2.9.10 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65478 Patch Status Unpatched Published Jul 22, 2026 Affected Software ListingPro Plugin [listingpro-plugin] Researcher Phat RiO More Details > MailPoet – Newsletters, Email Marketing, and Automation 5.30.0-5.33.0 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57626 Patch Status Patched Published Jul 21, 2026 Affected Software MailPoet – Newsletters, Email Marketing, and Automation [mailpoet] Researcher Nguyen Ba Khanh More Details > Masteriyo LMS – LMS Course Builder, Quizzes & Certificates <= 2.3.1 - Authenticated (Subscriber+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65463 Patch Status Patched Published Jul 22, 2026 Affected Software Masteriyo LMS – LMS Course Builder, Quizzes & Certificates [learning-management-system] Researcher Celvex Group More Details > Mediavine Control Panel <= 2.10.10 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-25424 Patch Status Unpatched Published Jul 22, 2026 Affected Software Mediavine Control Panel [mediavine-control-panel] Researcher Nabil Irawan More Details > Nexter Blocks <= 5.0.0 - Authenticated (Subscriber+) Path Traversal to Arbitrary CSS/JS File Deletion via 'plus_name' Parameter 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-15420 Patch Status Patched Published Jul 23, 2026 Affected Software Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder [the-plus-addons-for-block-editor] Researcher Wordfence PRISM More Details > Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 3.0.7 - Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-59539 Patch Status Patched Published Jul 23, 2026 Affected Software Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction [paid-member-subscriptions] Researcher Ananda Dhakal More Details > Participants Database <= 2.7.8.4 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-27423 Patch Status Unpatched Published Jul 22, 2026 Affected Software Participants Database [participants-database] Researcher Legion Hunter More Details > Polylang <= 3.8.5 - Authenticated (Contributor+) Sensitive Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65458 Patch Status Patched Published Jul 22, 2026 Affected Software Polylang [polylang] Researcher Ananda Dhakal More Details > Popup for CF7 with Sweet Alert <= 1.6.5 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65540 Patch Status Unpatched Published Jul 23, 2026 Affected Software Popup for CF7 with Sweet Alert [cf7-sweet-alert-popup] Researcher testoun More Details > Product Slider, Product Grid, Product Masonry <= 1.13.62 - Authenticated (Contributor+) Insecure Direct Object Reference 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65456 Patch Status Patched Published Jul 22, 2026 Affected Software Product Slider, Product Grid, Product Masonry [woocommerce-products-slider] Researcher Ananda Dhakal More Details > Query Wrangler <= 1.5.57 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65491 Patch Status Unpatched Published Jul 22, 2026 Affected Software Query Wrangler [query-wrangler] Researcher Que Thanh Tuan More Details > QuickCal <= 1.0.16 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-27377 Patch Status Unpatched Published Jul 22, 2026 Affected Software QuickCal [quickcal] Researcher Phat RiO More Details > Reviewer <= 3.14.2 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65479 Patch Status Unpatched Published Jul 22, 2026 Affected Software reviewer [reviewer] Researcher Phat RiO More Details > ShipTime: Discount Shipping <= 1.1.1 - Authenticated (Subscriber+) Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-59528 Patch Status Patched Published Jul 23, 2026 Affected Software ShipTime: Discount Shipping [shiptime-discount-shipping] Researcher VuNBT More Details > Style Kits <= 2.6.5 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65484 Patch Status Unpatched Published Jul 22, 2026 Affected Software Style Kits for Elementor [analogwp-templates] Researcher Bao - BlueRock More Details > Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers <= 3.6.10.1 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57703 Patch Status Patched Published Jul 20, 2026 Affected Software Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers [sunshine-photo-cart] Researcher dutafi More Details > TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Builder <= 4.2.2 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65530 Patch Status Unpatched Published Jul 23, 2026 Affected Software TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Builder [templatespare] Researcher Ananda Dhakal More Details > TinyMCE Templates <= 4.8.1 - Authenticated (Contributor+) Sensitive Information Exposure 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65535 Patch Status Unpatched Published Jul 23, 2026 Affected Software TinyMCE Templates [tinymce-templates] Researcher Ananda Dhakal More Details > Tutor LMS Elementor Addons <= 4.0.0 - Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin Activation 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-1372 Patch Status Unpatched Published Jul 20, 2026 Affected Software Tutor LMS Elementor Addons [tutor-lms-elementor-addons] Researcher Supakiad S. (m3ez) More Details > Visual Composer Website Builder <= 45.15.0 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65568 Patch Status Patched Published Jul 24, 2026 Affected Software Visual Composer Website Builder [visualcomposer] Researcher Ananda Dhakal More Details > WP Accessibility Helper (WAH) <= 0.6.6 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-24537 Patch Status Unpatched Published Jul 22, 2026 Affected Software WP Accessibility Helper (WAH) [wp-accessibility-helper] Researcher Trương Hữu Phúc (truonghuuphuc) More Details > WP Activity Log <= 5.6.4 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65512 Patch Status Patched Published Jul 23, 2026 Affected Software WP Activity Log [wp-security-audit-log] Researcher Levon Balyan More Details > WP Easy Pay – Payment and Donation Form Builder for Square <= 4.5.0 - Authenticated (Subscriber+) Arbitrary Content Deletion 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-57808 Patch Status Patched Published Jul 21, 2026 Affected Software WP Easy Pay – Payment and Donation Form Builder for Square [wp-easy-pay] Researcher dodoh4t More Details > WP Ghost (Hide My WP Ghost) – Security & Firewall <= 7.0.06 - Two-Factor Authentication Bypass 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-59546 Patch Status Patched Published Jul 23, 2026 Affected Software WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] Researcher Ananda Dhakal More Details > ЮKassa для WooCommerce <= 2.16.1 - Missing Authorization 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65457 Patch Status Patched Published Jul 22, 2026 Affected Software ЮKassa для WooCommerce [yookassa] Researcher Ananda Dhakal More Details > افزونه پرداخت امن زرینپال برای ووکامرس (ZarinPal for WooCommerce) <= 5.1.0 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65460 Patch Status Patched Published Jul 22, 2026 Affected Software افزونه پرداخت امن زرینپال برای ووکامرس (ZarinPal for WooCommerce) [zarinpal-woocommerce-payment-gateway] Researcher Ananda Dhakal More Details > افزونه حمل و نقل ووکامرس | پست پیشتاز، تیپاکس و پیک موتوری <= 4.4.5 - Cross-Site Request Forgery 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-65536 Patch Status Unpatched Published Jul 23, 2026 Affected Software افزونه حمل و نقل ووکامرس | پست پیشتاز، تیپاکس و پیک موتوری [persian-woocommerce-shipping] Researcher Ananda Dhakal More Details > As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence. This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program , and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can. Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published. The post Wordfence Intelligence Weekly WordPress Vulnerability Report (July 20, 2026 to July 26, 2026) appeared first on Wordfence .