| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Oct 10, 2026, 21:10:25 | ||||
|
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce
vulnerable
|
Oct 11, 2026, 02:10:21 |
Min -
Max 3.4.1
|
Missing Authorization vulnerability in Ashok Dudhat WP Event Manager wp-event-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Manager: from n/a through 3.4.1. | |
|
Classified Listing – Classified ads & Business Directory Plugin
vulnerable
|
Oct 11, 2026, 02:10:07 |
Min -
Max 6.1.3
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mamunur Rashid Classified Listing classified-listing allows Stored XSS.This issue affects Classified Listing: from n/a through 6.1.2. | |
|
Social Sharing Plugin – Sassy Social Share
vulnerable
|
Oct 11, 2026, 02:10:03 |
Min -
Max 3.3.79
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Heateor Support Sassy Social Share sassy-social-share allows Reflected XSS.This issue affects Sassy Social Share: from n/a through 3.3.79. | |
|
Data Tables Generator by Supsystic
vulnerable
|
Oct 11, 2026, 01:10:30 |
Min -
Max 1.15.3
|
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell 'data' Value via updateRows Action in all versions up to, and including, 1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable by Subscriber-level users when an... | |
|
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
vulnerable
|
Oct 11, 2026, 00:10:38 |
Min -
Max 6.2.15
|
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'any attacker-chosen name matching the {get.NAME} placeholder (PoC uses 'proof')' parameter in all versions up to, and including, 6.2.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user in... | |
|
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin
vulnerable
|
Oct 10, 2026, 23:10:52 |
Min -
Max 2.3.13
|
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin [everest-backup] <= 2.3.13 (unfixed) CVE-2026-39802 | |
|
Tutor LMS – eLearning and online course solution
vulnerable
|
Oct 10, 2026, 23:10:36 |
Min -
Max 4.1.1
|
Tutor LMS – eLearning and online course solution [tutor] < 4.1.1 CVE-2026-42702 | |
|
vulnerable
|
Oct 10, 2026, 23:10:27 |
Min -
Max 1.2.63
|
Slider by 10Web – Responsive Image Slider [slider-wd] <= 1.2.63 (unfixed) CVE-2026-42711 | |
|
WordPress + Microsoft Office 365 / Azure AD | LOGIN
vulnerable
|
Oct 10, 2026, 23:10:22 |
Min -
Max 45.0
|
The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Authentication Bypass via OIDC Nonce Replay in all versions up to, and including, 44.1 This is due to `Id_Token_Service_Deprecated::process_openidconnect_token()` using the incompatible WordPress core `wp_verify_nonce()` function to validate a nonce produced by `Nonce_Service::create_nonce()` — a 64-character hex value that `wp_verify_nonce()` can never successfully verify — causing the nonce check... | |
|
WordPress + Microsoft Office 365 / Azure AD | LOGIN
vulnerable
|
Oct 10, 2026, 23:10:22 |
Min -
Max 45.0
|
The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id_token' parameter in all versions up to, and including, 44.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is stored in the wpo365_errors transient for up to three days by submittin... | |