| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Jan 29, 2026, 05:01:39 | ||||
|
APPExperts – Mobile App Builder for WordPress | WooCommerce to iOS and Android Apps
vulnerable
|
Jan 28, 2026, 05:01:45 |
Min -
Max 1.4.5
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal AppExperts appexperts allows SQL Injection.This issue affects AppExperts: from n/a through <= 1.4.5. | |
|
Simple Calendar – Google Calendar Plugin
vulnerable
|
Jan 28, 2026, 05:01:44 |
Min -
Max 3.5.9
|
Authorization Bypass Through User-Controlled Key vulnerability in SimpleCalendar Google Calendar Events google-calendar-events allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Google Calendar Events: from n/a through <= 3.5.9. | |
|
vulnerable
|
Jan 28, 2026, 05:01:43 |
Min -
Max 2.21.7
|
The Bit Form – Contact Form Plugin plugin for WordPress is vulnerable to unauthorized workflow execution due to missing authorization in the triggerWorkFlow function in all versions up to, and including, 2.21.6. This is due to a logic flaw in the nonce verification where the security check only blocks requests when both the nonce verification fails and the user is logged in. This makes it possible for unauthenticated attackers to replay form workflow executions and trigger all configured integrations includ... | |
|
vulnerable
|
Jan 28, 2026, 05:01:42 |
Min -
Max 2.3.12
|
Server-Side Request Forgery (SSRF) vulnerability in wbolt.com IMGspider imgspider allows Server Side Request Forgery.This issue affects IMGspider: from n/a through <= 2.3.12. | |
|
vulnerable
|
Jan 28, 2026, 05:01:41 |
Min -
Max 3.2.1
|
The NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via the 'nx-preview' POST parameter in all versions up to, and including, 3.2.0. This is due to insufficient input sanitization and output escaping when processing preview data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute when a user vi... | |
|
vulnerable
|
Jan 28, 2026, 05:01:40 |
Min -
Max 3.3.33
|
The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capability checks on the `wpdm_media_access` AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve passwords and access control settings for protected media attachments, which can then be used to bypass the intended media protection and download restricted f... | |
|
vulnerable
|
Jan 28, 2026, 05:01:40 |
Min -
Max 3.3.41
|
The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change user's passwords, except administrators, and leverage that to gain access to their account. | |
|
vulnerable
|
Jan 28, 2026, 05:01:37 |
Min -
Max 1.2.16
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets astra-widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through <= 1.2.16. | |
|
vulnerable
|
Jan 28, 2026, 05:01:32 |
Min -
Max 2.6.4
|
Missing Authorization vulnerability in Proptech Plugin Apimo Connector apimo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apimo Connector: from n/a through <= 2.6.4. | |
|
Recipe Card Blocks for Gutenberg & Elementor – Best WordPress Recipe Plugin
vulnerable
|
Jan 28, 2026, 05:01:30 |
Min -
Max 3.4.13
|
The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a SQL statement, allowing contributors and above to perform SQL injection attacks. | |