| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Jun 17, 2026, 05:06:48 | ||||
|
vulnerable
|
Jun 17, 2026, 10:06:32 |
Min -
Max 2.2
|
The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2. This is due to the static_block_content() shortcode handler retrieving a post via get_post() using an attacker-supplied 'id' attribute and outputting its post_content without verifying the post's status (private, draft, pending) or the requesting user's capability to view it. This makes it possible for authenticated attackers, with contributor-level access and above, to read the... | |
|
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin
vulnerable
|
Jun 16, 2026, 22:06:17 |
Min -
Max 7.4
|
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables] < 7.4 CVE-2026-49080 | |
|
vulnerable
|
Jun 16, 2026, 18:06:49 |
Min -
Max 6.16.3
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2. | |
|
WooCommerce Stripe Payment Gateway
vulnerable
|
Jun 16, 2026, 17:06:52 |
Min -
Max 10.8.0
|
The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment for an order via the `wc_stripe_pay_for_order` WC-AJAX endpoint. The function only validates a nonce (which is publicly available on any WooCommerce page where Express Checkout is enabled), bu... | |
|
vulnerable
|
Jun 16, 2026, 11:06:20 |
Min -
Max 2.5.1
|
leenk.me [leenkme] < 2.5.1 (closed) WordPress leenk.me Plugin 2.5.0 - Multiple Vulnerabilities This WordPress leenk.me plugin is prone to cross-site request forgery and cross-site scripting vulnerabilities via vulnerable page: wp-content/plugins/leenkme/facebook.php. Also, there are vulnerable fields: "facebook_message", "facebook_description", "default_image", "facebook_linkname", etc. Upgrade the plugin. | |
|
vulnerable
|
Jun 16, 2026, 11:06:20 |
Min -
Max 2.0.0
|
Social Hashtags [social-hashtags] <= 2.0.0 (unfixed) Social Hashtags 2.0.0 - New Post Title Field Stored XSS The Social Hashtags WordPress plugin was affected by a New Post Title Field Stored XSS security vulnerability. | |
|
vulnerable
|
Jun 16, 2026, 11:06:20 |
Min -
Max 2.0.1
|
Social Hashtags [social-hashtags] < 2.0.1 WordPress Social Hashtags Plugin <= 2.0.0 is vulnerable to Cross Site Scripting (XSS) Update the plugin. Arsan discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Social Hashtags Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2.0.1. | |
|
vulnerable
|
Jun 16, 2026, 11:06:20 |
Min -
Max 3.0.0
|
Social Hashtags [social-hashtags] <= 3.0.0 (unfixed) Social Hashtags <= 3.0.0 - Cross-Site Scripting The Social Hashtags plugin for WordPress is vulnerable to Cross-Site Scripting via the new post title field in versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts that execute in a victim's browser. | |
|
Simple Calendar – Google Calendar Plugin
vulnerable
|
Jun 16, 2026, 11:06:20 |
Min -
Max 3.2.5
|
Simple Calendar – Google Calendar Plugin [google-calendar-events] < 3.2.5 Simple Calendar < 3.2.5 - Cross-Site Request Forgery via duplicate_feed The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 3.2.5 (exclusive). This is due to missing or incorrect nonce validation on the duplicate_feed function. This makes it possible for unauthenticated attackers to duplicate feeds via a forged request granted they can t... | |
|
Simple Calendar – Google Calendar Plugin
vulnerable
|
Jun 16, 2026, 11:06:20 |
Min -
Max 3.2.5
|
Simple Calendar – Google Calendar Plugin [google-calendar-events] < 3.2.5 Simple Calendar <= 3.2.4 - Cross-Site Request Forgery via duplicate_feed The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 3.2.5 (exclusive). This is due to missing or incorrect nonce validation on the duplicate_feed function. This makes it possible for unauthenticated attackers to duplicate feeds via a forged request granted they can trick a s... | |