| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Sep 16, 2026, 05:09:36 | ||||
|
vulnerable
|
Sep 16, 2026, 02:09:21 |
Min -
Max 1.5.27
|
The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page. | |
|
vulnerable
|
Sep 16, 2026, 02:09:10 |
Min -
Max 1.0.2
|
The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web scripts which will execute for anyone viewing the site, including administrators. The same request destroys the site's existing theme settings. | |
|
3D FlipBook – PDF Flipbook WordPress
vulnerable
|
Sep 16, 2026, 00:09:11 |
Min -
Max 1.16.21
|
The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the 'id' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including the full metadata payload of password-protected flipbooks — including title, outline, props, and the serialized data blob containing the underlying PDF file's direct URL — bypassing WordPress post-password co... | |
|
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution
vulnerable
|
Sep 15, 2026, 22:09:35 |
Min -
Max 4.9.6
|
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shopengine_product_title_header_size’ parameter in all versions up to, and including, 4.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a use... | |
|
vulnerable
|
Sep 15, 2026, 22:09:23 |
Min -
Max 3.7.8
|
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to access and retrieve the transcribed contents of private audio attachments belonging to other users, including Administrators, via a supplied attachment ID. This... | |
|
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors
vulnerable
|
Sep 15, 2026, 22:09:07 |
Min -
Max 4.16.0
|
The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up to, and including, 4.15.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user clicks on a link. | |
|
Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin
vulnerable
|
Sep 15, 2026, 22:09:01 |
Min -
Max 4.1.24
|
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter in all versions up to, and including, 4.1.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
|
Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin
vulnerable
|
Sep 15, 2026, 22:09:01 |
Min -
Max 4.1.24
|
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` function being registered as a callback on WordPress core's `map_meta_cap` filter and unconditionally returning the always-true `'exist'` primitive for every capability check whenever the evaluated user ID is 1, without scoping this behavior to plugin-specific capabiliti... | |
|
Ads by WPQuads – Adsense Ads, Banner Ads, Popup Ads
vulnerable
|
Sep 15, 2026, 13:09:30 |
Min -
Max 3.0.5
|
The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a paid ad placement without payment. | |
|
vulnerable
|
Sep 15, 2026, 12:09:53 |
Min -
Max 1.0.0
|
The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any user visiting the site. | |