| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Jun 05, 2026, 01:06:08 | ||||
|
EmergencyWP – Dead Man's switch & legacy deliverance
vulnerable
|
Jun 04, 2026, 22:06:59 |
Min -
Max 1.4.2
|
The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorrect nonce validation on the form_settings_ui (settings save handler, procedural include scope) function. This makes it possible for unauthenticated attackers to modify plugin settings including the minimum access role (altering WordPress role capabilities via add_cap/remove_cap), the data-erasure-on-uninstall fl... | |
|
Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin
vulnerable
|
Jun 04, 2026, 22:06:25 |
Min -
Max 5.3.4
|
Event Booking Manager for WooCommerce [mage-eventpress] < 5.3.4 CVE-2026-45441 | |
|
Job Manager and Recruitment Board for Employers and Candidates – Crew HRM
vulnerable
|
Jun 04, 2026, 21:06:20 |
Min -
Max 1.2.3
|
Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Crew HRM: from n/a through 1.2.2. | |
|
vulnerable
|
Jun 04, 2026, 19:06:13 |
Min -
Max 1.4.8
|
CloudSecure WP Security [cloudsecure-wp-security] < 1.4.8 CVE-2026-42411 | |
|
vulnerable
|
Jun 04, 2026, 18:06:35 |
Min -
Max 3.5.0
|
AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.5.0 CVE-2026-27407 | |
|
vulnerable
|
Jun 04, 2026, 13:06:33 |
Min -
Max 2.4.1
|
The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.4.1. This is due to missing capability checks and nonce verification on the admin_post_settings_save_woo-jtl-connector action (handled by JtlConnectorAdmin::save()) and on the wp_ajax_downloadJTLLogs and wp_ajax_clearJTLLogs AJAX actions (handled by the global downloadJTLLogs() and clearJTLLogs() functions). This makes it possible for authenticated attackers, with Subscriber-leve... | |
|
vulnerable
|
Jun 04, 2026, 12:06:46 |
Min -
Max 1.1.1
|
The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callout' shortcode in all versions up to, and including, 1.1.1. This is due to insufficient input sanitization and output escaping on the 'width' and 'align' shortcode attributes within the st_callout() function, which concatenates the attribute values directly into an HTML style attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject ar... | |
|
Content Visibility for Divi Builder
vulnerable
|
Jun 04, 2026, 10:06:36 |
Min -
Max 4.02
|
The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.02 via the 'et_pb_text' shortcode 'cvdb_content_visibility_check' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. | |
|
Paid Videochat Turnkey Site – HTML5 PPV Live Webcams
vulnerable
|
Jun 04, 2026, 08:06:43 |
Min -
Max 7.3.24
|
Paid Videochat Turnkey Site – HTML5 PPV Live Webcams [ppv-live-webcams] < 7.3.24 CVE-2026-27333 | |
|
Elementor Website Builder – More than Just a Page Builder
vulnerable
|
Jun 04, 2026, 06:06:37 |
Min -
Max 4.1.1
|
Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Elementor Website Builder: from n/a through 4.1.0. | |