| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Jul 23, 2026, 14:07:00 | ||||
|
vulnerable
|
Jul 23, 2026, 12:07:03 |
Min -
Max 4.0.0
|
The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Tutor LMS and Elementor plugins without proper authorization. | |
|
WordPress Online Booking and Scheduling Plugin – Bookly
vulnerable
|
Jul 23, 2026, 06:07:37 |
Min -
Max 27.8
|
Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.8 CVE-2026-61944 | |
|
WordPress Online Booking and Scheduling Plugin – Bookly
vulnerable
|
Jul 23, 2026, 06:07:37 |
Min -
Max 27.8
|
Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.8 CVE-2026-61949 | |
|
WP Travel – Best Travel Booking WordPress Plugin, Tour Management Engine
vulnerable
|
Jul 23, 2026, 05:07:19 |
Min -
Max 11.7.1
|
The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site. | |
|
vulnerable
|
Jul 23, 2026, 05:07:06 |
Min -
Max 8.2.2
|
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders. | |
|
vulnerable
|
Jul 23, 2026, 05:07:06 |
Min -
Max 8.2.2
|
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some configurations, to modify order statuses. | |
|
MailerSend – Official SMTP Integration
vulnerable
|
Jul 23, 2026, 04:07:59 |
Min -
Max 1.0.8
|
The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's SMTP configuration and deactivates the MailerSend WordPress plugin before 1.0.8, breaking the site's email delivery. | |
|
Elementor Header & Footer Builder
vulnerable
|
Jul 23, 2026, 04:07:04 |
Min -
Max 2.9.2
|
The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post, applied on save for users wi... | |
|
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress
vulnerable
|
Jul 22, 2026, 22:07:21 |
Min -
Max 3.14.8
|
Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe multisite migration defaults. Attackers can send a crafted POST request to the admin-ajax.php endpoint with the nf_delete_all_data action and a per-site nonce to invoke migration routines that unconditionally iterate all blogs via swit... | |
|
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress
vulnerable
|
Jul 22, 2026, 22:07:21 |
Min -
Max 3.10.4
|
Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without numeric validation, and admin_form_element() interpolates the index directly into HTML without escaping. An unauthenticated attacker can submit a public form with a crafted repeater child key containing malicious script payloads, which execute in an administ... | |