| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Sep 01, 2026, 02:09:08 | ||||
|
SOGO Add Script to Individual Pages Header Footer
vulnerable
|
Sep 01, 2026, 06:09:55 |
Min -
Max 3.9
|
The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restrict them to users with the unfiltered_html capability, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any administrator who reviews the post and of any visitor once the post is published. | |
|
vulnerable
|
Sep 01, 2026, 06:09:45 |
Min -
Max 5.1.6
|
The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allow users with a role as low as Editor to perform Stored Cross-Site Scripting attacks against high privilege users such as admin. | |
|
vulnerable
|
Sep 01, 2026, 06:09:10 |
Min -
Max 3.0.3
|
Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions. | |
|
vulnerable
|
Sep 01, 2026, 05:09:47 |
Min -
Max 3.29.11
|
The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans. | |
|
Rest Routes – Custom Endpoints for WordPress REST API
vulnerable
|
Sep 01, 2026, 05:09:40 |
Min -
Max 5.5.5
|
The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. | |
|
WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg
vulnerable
|
Sep 01, 2026, 03:09:07 |
Min -
Max 4.5.13
|
The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and outputting them back in an administrative area, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users. | |
|
Import CSV or XML Datafeed With Ease
vulnerable
|
Aug 31, 2026, 17:08:43 |
Min -
Max 9.0
|
The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks. | |
|
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
vulnerable
|
Aug 31, 2026, 16:08:10 |
Min -
Max 4.0.1
|
The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scripting attacks against any user viewing the affected content, including administrators. The shortcode is not enabled by default. | |
|
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
vulnerable
|
Aug 31, 2026, 16:08:10 |
Min -
Max 4.0.1
|
The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is disabled by default, and no POP chain is present in the User Profile Builder WordPress plugin before 4.0.1 itself, so further impact requires a suitable gadget from another installed User Profile Builder WordPress plugin before 4.... | |
|
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
vulnerable
|
Aug 31, 2026, 16:08:10 |
Min -
Max 4.0.1
|
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users. | |