| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: May 13, 2026, 11:05:41 | ||||
|
vulnerable
|
May 13, 2026, 13:05:39 |
Min -
Max 1.0.9
|
The BJ Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `filter_images()` function in all versions up to, and including, 1.0.9. This is due to the use of regex-based HTML processing (`preg_replace`) that does not properly handle HTML attribute boundaries when replacing `src` attributes, allowing crafted content inside a `class` attribute value to be promoted to real DOM attributes after processing. This makes it possible for authenticated attackers, with Contributor-level ... | |
|
WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress
vulnerable
|
May 13, 2026, 13:05:36 |
Min -
Max 1.5.7.3
|
WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wp_sap cookie parameter. Attackers can craft SQL payloads in the cookie to extract sensitive database information including usernames, passwords, and other confidential data from the WordPress database. | |
|
vulnerable
|
May 13, 2026, 13:05:25 |
Min -
Max 2.8.1
|
The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_kcseo_ative_tab` parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
|
vulnerable
|
May 13, 2026, 12:05:55 |
Min -
Max 5.5.71
|
WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards [wp-data-access] < 5.5.71 CVE-2026-42665 | |
|
Asset CleanUp: Page Speed Booster
vulnerable
|
May 13, 2026, 10:05:47 |
Min -
Max 1.4.0.4
|
Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster wp-asset-clean-up allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asset CleanUp: Page Speed Booster: from n/a through <= 1.4.0.3. | |
|
vulnerable
|
May 13, 2026, 09:05:11 |
Min -
Max 1.0.3
|
WordPress Plugin cab-fare-calculator 1.0.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the controller parameter in tblight.php. Attackers can supply path traversal sequences through the controller GET parameter to include and execute files outside the intended controllers directory. | |
|
vulnerable
|
May 13, 2026, 05:05:48 |
Min -
Max 2.0.6
|
WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers can upload PHP files with arbitrary names to the config_file endpoint to achieve remote code execution on the server. | |
|
Motors – Car Dealer, Classifieds & Listing
vulnerable
|
May 13, 2026, 03:05:14 |
Min -
Max 1.4.104
|
The Motors – Car Dealership & Classified Listings plugin for WordPress is vulnerable to Payment Bypass via insecure user meta update in all versions up to, and including, 1.4.103 This is due to the stm_save_user_extra_fields() function updating sensitive user meta fields from POST data without verifying that the current user should have permission to modify those fields. The function hooks into the 'personal_options_update' action and only checks current_user_can('edit_user', $user_id), which passes for any... | |
|
Advanced Product Search for WooCommerce – Motive Commerce Search
vulnerable
|
May 13, 2026, 02:05:15 |
Min -
Max 1.38.3
|
AI Product Search for WooCommerce – Motive Commerce Search [motive-commerce-search] < 1.38.3 CVE-2026-42664 | |
|
vulnerable
|
May 13, 2026, 01:05:31 |
Min -
Max 1.3.2
|
eMagicOne Store Manager for WooCommerce [store-manager-connector] <= 1.3.2 (unfixed) CVE-2026-42773 | |