| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Sep 04, 2026, 18:09:03 | ||||
|
vulnerable
|
Sep 04, 2026, 22:09:37 |
Min -
Max 2.5.2
|
Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions. | |
|
vulnerable
|
Sep 04, 2026, 22:09:27 |
Min -
Max 8.7.7
|
Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions. | |
|
All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic
vulnerable
|
Sep 04, 2026, 22:09:20 |
Min -
Max 5.0.0.1
|
The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise and escape some content stored in posts before rendering it back in the post editor, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks that trigger when a higher privileged user edits the post. | |
|
vulnerable
|
Sep 04, 2026, 21:09:54 |
Min -
Max 3.15.2
|
Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions. | |
|
vulnerable
|
Sep 04, 2026, 21:09:49 |
Min -
Max 1.3.5
|
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions. | |
|
vulnerable
|
Sep 04, 2026, 21:09:33 |
Min -
Max 2.7.8
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking and Rental Manager: from n/a through 2.7.7. | |
|
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss
vulnerable
|
Sep 04, 2026, 21:09:19 |
Min -
Max 2.15.28
|
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions. | |
|
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
vulnerable
|
Sep 04, 2026, 21:09:02 |
Min -
Max 1.8.44
|
The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting them into input-attribute values on its admin pages (one on the Shortcode page, one on the Galleries/Albums list page), so an unauthenticated attacker can craft a link that, when opened by a logged-in administrator (or, for the first sink, a contributor), executes arbitrary JavaScript in the victim's authenticated session via an auto-firing onfocus handler. The Galleries/Albums sink renders on... | |
|
vulnerable
|
Sep 04, 2026, 21:09:00 |
Min -
Max 7.9.1
|
Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions. | |
|
WP EasyPay – Square for WordPress
vulnerable
|
Sep 04, 2026, 21:09:00 |
Min -
Max 4.5.4
|
Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions. | |