| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Aug 29, 2026, 00:08:52 | ||||
|
Translate Multilingual sites – TranslatePress
vulnerable
|
Aug 29, 2026, 05:08:49 |
Min -
Max 3.3.4
|
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser in all versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation is possible because WordPress's comment KSES allowlist ... | |
|
vulnerable
|
Aug 29, 2026, 05:08:38 |
Min -
Max 2.7.6
|
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions. | |
|
vulnerable
|
Aug 29, 2026, 05:08:05 |
Min -
Max 7.8
|
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in all versions up to, and including, 7.7. This is due to a flawed regular expression that is used to strip `width` and `height` attributes from images when the "Lazy Load Images" and "Add Missing Sizes" features are enabled. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that execute whenever a user accesse... | |
|
vulnerable
|
Aug 29, 2026, 05:08:05 |
Min -
Max 7.9
|
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A comment payload crafted exclusively from decimal numeric character references (e.g. ", <, >) placed inside an allowed element such as... | |
|
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory
vulnerable
|
Aug 29, 2026, 05:08:01 |
Min -
Max 2.8.177
|
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions. | |
|
Contact Form builder with drag & drop for WordPress – Kali Forms
vulnerable
|
Aug 29, 2026, 04:08:25 |
Min -
Max 2.4.24
|
Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions. | |
|
CMP – Coming Soon & Maintenance Plugin by NiteoThemes
vulnerable
|
Aug 29, 2026, 03:08:41 |
Min -
Max 4.1.18
|
The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administrator. | |
|
CMP – Coming Soon & Maintenance Plugin by NiteoThemes
vulnerable
|
Aug 29, 2026, 03:08:41 |
Min -
Max 4.1.18
|
The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to inject arbitrary web scripts that execute when a visitor views the page. | |
|
CMP – Coming Soon & Maintenance Plugin by NiteoThemes
vulnerable
|
Aug 29, 2026, 03:08:41 |
Min -
Max 4.1.18
|
The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain (and exposed to anonymous visitors on others), allowing unauthenticated attackers to disable the site's maintenance/coming-soon mode under a non-default countdown configuration. | |
|
Forminator – Contact Form, Payment Form & Custom Form Builder
vulnerable
|
Aug 29, 2026, 03:08:36 |
Min -
Max 1.57.0.2
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that the targeted Textarea field has the Rich-Text editor opt... | |