| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Aug 04, 2026, 22:08:43 | ||||
|
vulnerable
|
Aug 05, 2026, 02:08:50 |
Min -
Max 1.0.7
|
The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any higher-privileged user who views the affected post. | |
|
vulnerable
|
Aug 05, 2026, 02:08:30 |
Min -
Max 2.5.17
|
The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves them as SVG, allowing a user permitted to upload SVGs (such as an Author once granted upload access) to store a script-bearing file that executes in the browser of anyone who later views it, including an administrator. | |
|
vulnerable
|
Aug 05, 2026, 01:08:01 |
Min -
Max 1.1.4
|
The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arbitrary HTML and JavaScript that executes in the session of any higher-privileged user (such as an administrator) who views the content. | |
|
Buckaroo Woocommerce Payments Plugin
vulnerable
|
Aug 05, 2026, 00:08:46 |
Min -
Max 4.9.0
|
The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured orders. | |
|
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer
vulnerable
|
Aug 05, 2026, 00:08:27 |
Min -
Max 2.4.3
|
The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment. | |
|
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
vulnerable
|
Aug 05, 2026, 00:08:23 |
Min -
Max 2.0.16
|
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15. | |
|
vulnerable
|
Aug 04, 2026, 23:08:15 |
Min -
Max 7.9.3
|
The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | |
|
vulnerable
|
Aug 04, 2026, 22:08:13 |
Min -
Max 4.5.5.3
|
The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying arbitrary record IDs. | |
|
Chat On Desk Order Notifications – WooCommerce
vulnerable
|
Aug 04, 2026, 21:08:13 |
Min -
Max 1.0.9
|
The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS one-time-password password reset is enabled. | |
|
vulnerable
|
Aug 04, 2026, 14:08:37 |
Min -
Max 23.6
|
The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled, the same action is reachable unauthenticated against any user's file. | |