| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Sep 28, 2026, 21:09:24 | ||||
|
vulnerable
|
Sep 28, 2026, 22:09:13 |
Min -
Max 4.6.7
|
The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post. | |
|
vulnerable
|
Sep 28, 2026, 21:09:13 |
Min -
Max 1.7.31
|
The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks. | |
|
WP Delicious – Best WordPress Recipes Plugin (formerly Delicious Recipes)
vulnerable
|
Sep 28, 2026, 15:09:06 |
Min -
Max 1.10.8
|
The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied recipe block data before rendering it on the front end, allowing users with the Contributor role and above to inject arbitrary HTML tags, including script tags, which execute when the recipe page is viewed. | |
|
vulnerable
|
Sep 28, 2026, 06:09:23 |
Min 7.2.2
Max 8.0.5
|
The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a full database dump including every user's email address and password hash on servers that do not apply the directory's .htaccess file. | |
|
vulnerable
|
Sep 28, 2026, 06:09:23 |
Min -
Max 8.0.5
|
The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the site's own address, which allows an unauthenticated attacker to run arbitrary JavaScript in the session of a logged-in administrator who visits a page under their control. The defect is in t... | |
|
vulnerable
|
Sep 28, 2026, 05:09:31 |
Min -
Max 1.1.1
|
The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers in a SQL query, allowing unauthenticated attackers to append additional SQL and extract sensitive information from the database. | |
|
Team Member – Multi Language Supported Team Plugin
vulnerable
|
Sep 28, 2026, 05:09:26 |
Min -
Max 9.2
|
The Team Members WordPress plugin through 9.2 does not perform any authorization or visibility check in an unauthenticated AJAX action that returns full team member records by ID, allowing unauthenticated attackers to enumerate and disclose details, including email addresses and phone numbers, of team members the administrator has not published publicly. | |
|
File Manager Pro – Filester
vulnerable
|
Sep 28, 2026, 04:09:28 |
Min -
Max 1.9
|
Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file manager available to users. | |
|
File Manager Pro – Filester
vulnerable
|
Sep 28, 2026, 04:09:28 |
Min -
Max 2.1.3
|
The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the site's own address, which allows an unauthenticated attacker to run arbitrary JavaScript in the session of a logged-in administrator who visits a page under their control. The defect is in t... | |
|
Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF
vulnerable
|
Sep 28, 2026, 03:09:14 |
Min 4.0.0
Max 4.2.13
|
The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users with the Author role and above to store an event-handler attribute that executes scripts in the browser of any user, such as an administrator, who views the post. | |
Warning
An error occurred: Call to a member function getItems() on null