| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Sep 13, 2026, 05:09:12 | ||||
|
vulnerable
|
Sep 13, 2026, 10:09:12 |
Min -
Max 5.9.10
|
Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions. | |
|
Starter Templates — Elementor, WordPress & Beaver Builder Templates
vulnerable
|
Sep 13, 2026, 09:09:47 |
Min -
Max 4.7.6
|
Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions. | |
|
vulnerable
|
Sep 13, 2026, 09:09:43 |
Min -
Max 2.8.2
|
The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment authority obtained from a different transaction. | |
|
vulnerable
|
Sep 13, 2026, 09:09:38 |
Min -
Max 45.16.2
|
Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions. | |
|
SMS Alert Order Notifications – WooCommerce
vulnerable
|
Sep 13, 2026, 09:09:11 |
Min -
Max 4.0.0
|
Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions. | |
|
Slim SEO – Fast & Automated WordPress SEO Plugin
vulnerable
|
Sep 13, 2026, 08:09:49 |
Min -
Max 4.10.1
|
Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4.10.0 versions. | |
|
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress
vulnerable
|
Sep 13, 2026, 07:09:52 |
Min -
Max 11.2.6
|
Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions. | |
|
rtMedia for WordPress, BuddyPress and bbPress
vulnerable
|
Sep 13, 2026, 07:09:47 |
Min -
Max 4.7.12
|
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is explo... | |
|
Translate WordPress with GTranslate
vulnerable
|
Sep 13, 2026, 07:09:26 |
Min -
Max 3.0.10
|
The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site. | |
|
Metform Elementor Contact Form Builder
vulnerable
|
Sep 13, 2026, 07:09:26 |
Min -
Max 4.1.9
|
The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that are placed into notification email headers, allowing unauthenticated attackers to inject additional email headers, such as Bcc, into the emails the site sends when a submitted field value is configured to populate a header. | |