| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Aug 01, 2026, 22:08:38 | ||||
|
Payment forms, Buy now buttons and Invoicing System | GetPaid
vulnerable
|
Aug 02, 2026, 03:08:32 |
Min -
Max 2.8.57
|
The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaid_payment_form_element function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code ex... | |
|
vulnerable
|
Aug 02, 2026, 03:08:01 |
Min -
Max 5.9.0
|
The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendering it into the image lightbox caption in the browser, allowing users with author-level access and above (who lack the unfiltered_html capability) to store JavaScript that runs when a visitor or administrator opens the lightbox. | |
|
Academy LMS – eLearning and online course solution for WordPress
vulnerable
|
Aug 02, 2026, 02:08:44 |
Min -
Max 3.8.2
|
The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing any authenticated user with subscriber-level access and above (enrolled in any single course) to read every user's quiz attempts across the whole site, including personal data such as IP addresses, names, registration dates and quiz results. | |
|
vulnerable
|
Aug 02, 2026, 02:08:34 |
Min -
Max 3.2
|
The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1. This is due to missing nonce validation on the ms_update AJAX action. This makes it possible for unauthenticated attackers to modify child theme CSS styles via a forged request granted they can trick an administrator into performing an action such as clicking on a link. | |
|
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
vulnerable
|
Aug 01, 2026, 22:08:26 |
Min -
Max 6.0.9.4
|
The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users' form submissions and the profile fields of the associated non-administrator WordPress accounts. | |
|
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
vulnerable
|
Aug 01, 2026, 22:08:26 |
Min -
Max 6.0.9.4
|
The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users' form submission data, including personal information. | |
|
vulnerable
|
Aug 01, 2026, 22:08:05 |
Min -
Max 1.9.3
|
The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the post-editing capability (such as a Contributor) can create, publish, and overwrite arbitrary Pages, including modifying content authored by higher-privileged users. | |
|
WP Real IP-based Access Control
vulnerable
|
Aug 01, 2026, 21:08:42 |
Min -
Max 1.3.1
|
The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks before storing one of its option values, and does not escape that value on output on its settings page, allowing unauthenticated users to store arbitrary JavaScript that executes in the context of any administrator who views the page. | |
|
PixelYourSite – Your smart PIXEL (TAG) Manager
vulnerable
|
Aug 01, 2026, 21:08:24 |
Min -
Max 11.2.2
|
The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.2.1 via the getWooPurchaseEventParams. This makes it possible for unauthenticated attackers to extract WooCommerce purchase metadata — including product names, product IDs, quantities, per-item prices, order totals, currency, and order/transaction IDs — for any existing order by supplying an invalid or arbitrary order key. This is exploitable ... | |
|
vulnerable
|
Aug 01, 2026, 20:08:31 |
Min -
Max 2.2.1
|
The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses into those lists using the owner's stored API credentials. | |