| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Oct 05, 2026, 04:10:37 | ||||
|
Motors – Car Dealer, Classifieds & Listing
vulnerable
|
Oct 04, 2026, 23:10:48 |
Min -
Max 1.4.124
|
The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator. | |
|
vulnerable
|
Oct 04, 2026, 14:10:01 |
Min -
Max 4.3.12
|
The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers. | |
|
Wp Edit Password Protected – Create Member/User Only Page & Design Password Protected Form
vulnerable
|
Oct 04, 2026, 10:10:22 |
Min 2.0.0
Max 2.0.7
|
The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site's access mode was configured to hide. | |
|
vulnerable
|
Oct 04, 2026, 10:10:04 |
Min -
Max 2.5.6
|
The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published. | |
|
Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More
vulnerable
|
Oct 04, 2026, 09:10:50 |
Min -
Max 1.4.5
|
The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service. | |
|
Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More
vulnerable
|
Oct 04, 2026, 09:10:50 |
Min -
Max 1.4.5
|
The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker WordPress plugin through 1.4.5 option (the linked service account and API configuration) that should only be modifiable by administrators. | |
|
Tabs Responsive – With WooCommerce Product Tabs Extension
vulnerable
|
Oct 04, 2026, 08:10:38 |
Min -
Max 2.5
|
The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page. | |
|
vulnerable
|
Oct 04, 2026, 08:10:05 |
Min -
Max 11.8.4
|
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveraging Race Conditions.This issue affects Booking Calendar: from n/a through 11.8.4. | |
|
vulnerable
|
Oct 04, 2026, 07:10:28 |
Min 6.12.0
Max 6.17.5.1
|
The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. | |
|
vulnerable
|
Oct 04, 2026, 07:10:00 |
Min -
Max 2.10.7
|
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Output-Buffer Regex Rewrite in all versions up to, and including, 2.10.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the 'Remove query strings from static resources' option is enabled in W... | |
Warning
An error occurred: Call to a member function getItems() on null