| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Aug 18, 2026, 18:08:30 | ||||
|
vulnerable
|
Aug 18, 2026, 22:08:38 |
Min -
Max 3.7.2
|
Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions. | |
|
vulnerable
|
Aug 18, 2026, 19:08:47 |
Min -
Max 5.7.1
|
The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
|
User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin
vulnerable
|
Aug 18, 2026, 18:08:53 |
Min -
Max 5.2.7
|
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder [user-registration] < 5.2.7 CVE-2026-73995 | |
|
vulnerable
|
Aug 18, 2026, 14:08:36 |
Min -
Max 1.5.58
|
The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_form_ajax handler, combined with unsanitized attacker-controlled options fully replacing saved query options and being passed directly to call_user_func_array() guarded only by function_exists(). This makes it possible for authenticated attackers, with subscriber-leve... | |
|
vulnerable
|
Aug 18, 2026, 14:08:23 |
Min -
Max 2.0.9
|
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). An attacker must first call the proSol_fileUploadModalProcess handler to poison their own session wi... | |
|
vulnerable
|
Aug 18, 2026, 14:08:23 |
Min -
Max 2.0.11
|
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which overrides the allow-listed multipart filename before the file is saved, and a post-save extension check that fails to delete the already-written file. This makes it possible for unauthenticated attackers to upload files that may be exe... | |
|
vulnerable
|
Aug 18, 2026, 14:08:20 |
Min -
Max 4.3.8
|
The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic repeater actions, relying only on a nonce available to any user who can open the page builder, allowing users with a contributor-level account or above to read, alter and delete the binding configuration of posts they do not own and to change the ECS WordPress plugin before 4.3.8's site-wide presets. | |
|
vulnerable
|
Aug 18, 2026, 14:08:20 |
Min -
Max 4.3.8
|
The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its Dynamic Repeater AJAX handlers (gated only by a capability-agnostic nonce that any edit_posts user obtains from the Elementor editor), so a Contributor can write a data-source binding into any post — including admin-authored pages — whose attacker-controlled values are rendered into a widget's repeater output without sanitization, executing JavaScript in the session of any visitor or administrator who views ... | |
|
vulnerable
|
Aug 18, 2026, 14:08:20 |
Min -
Max 4.3.10
|
The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater data sources reads custom field values from a user-supplied post identifier, allowing users with a contributor-level account or above to read custom field values and post metadata from posts they do not own, including private and draft ones. | |
|
vulnerable
|
Aug 18, 2026, 14:08:20 |
Min -
Max 4.3.8
|
The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elementor document requested through one of its AJAX actions, allowing unauthenticated users to retrieve the rendered content of unpublished (private, draft, pending) documents by supplying their identifier. | |