| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Jul 21, 2026, 23:07:18 | ||||
|
vulnerable
|
Jul 22, 2026, 03:07:21 |
Min -
Max 2.2.28
|
Autopay dla WooCommerce [pay-wp] < 2.2.28 CVE-2026-57425 | |
|
vulnerable
|
Jul 22, 2026, 02:07:27 |
Min -
Max 5.5.0
|
The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browser of an administrator who views the reports. Exploitation requires the SlimStat Analytics WordPress plugin before 5.5.0 to be configured to use the Cloudflare geolocation provider. | |
|
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
vulnerable
|
Jul 21, 2026, 21:07:47 |
Min -
Max 2.0.11
|
The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malicious review on the targeted business's Google listing to deliver Stored XSS to any visitor (including administrators) of any WP page displaying that Place ID's reviews. | |
|
vulnerable
|
Jul 21, 2026, 20:07:52 |
Min -
Max 7.106
|
The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations outside its intended storage directory. | |
|
Elementor Website Builder – More than Just a Page Builder
vulnerable
|
Jul 21, 2026, 20:07:23 |
Min -
Max 4.1.4
|
The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators). | |
|
vulnerable
|
Jul 21, 2026, 19:07:32 |
Min -
Max 6.0.12
|
The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment moderation. | |
|
vulnerable
|
Jul 21, 2026, 19:07:32 |
Min -
Max 6.0.12
|
The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivered to a registered user, which can be used for phishing. | |
|
vulnerable
|
Jul 21, 2026, 19:07:32 |
Min -
Max 6.0.12
|
The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery). | |
|
vulnerable
|
Jul 21, 2026, 19:07:15 |
Min -
Max 4.0.12
|
The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in wp_emsfb_temp_links, combined with a publicly-accessible nonce refresh endpoint (Emsfb/v1/nonce/refresh) that issues valid WordPress REST nonces to unauthenticated visitors. This makes it possible for unauthe... | |
|
All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic
vulnerable
|
Jul 21, 2026, 13:07:27 |
Min -
Max 4.9.9
|
The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state. | |