| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Oct 02, 2026, 01:10:58 | ||||
|
vulnerable
|
Sep 30, 2026, 11:09:30 |
Min -
Max 1.0.0
|
The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate limited either. | |
|
vulnerable
|
Sep 30, 2026, 11:09:07 |
Min -
Max 1.4.0
|
The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks. | |
|
Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP
vulnerable
|
Sep 30, 2026, 04:09:17 |
Min 4.6.20
Max 4.6.26
|
The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it. | |
|
Contact Form by WPForms – Drag & Drop Form Builder for WordPress
vulnerable
|
Sep 30, 2026, 03:09:20 |
Min 1.5.0.1
Max 2.0.2.1
|
The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts. | |
|
vulnerable
|
Sep 30, 2026, 03:09:06 |
Min -
Max 2.8.27
|
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks. | |
|
vulnerable
|
Sep 30, 2026, 03:09:06 |
Min -
Max 2.8.27
|
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to internal-only resources and read the responses back. | |
|
vulnerable
|
Sep 30, 2026, 03:09:06 |
Min -
Max 2.8.27
|
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses back. | |
|
vulnerable
|
Sep 30, 2026, 03:09:06 |
Min -
Max 2.8.27
|
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing users with contributor-level access and above to publish posts live and set any registered user, including an administrator, as the post author. | |
|
Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks
vulnerable
|
Sep 29, 2026, 19:09:30 |
Min -
Max 2.10.3
|
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
|
Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal
vulnerable
|
Sep 29, 2026, 13:09:04 |
Min -
Max 19.9.7
|
The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution. | |
Warning
An error occurred: Call to a member function getItems() on null