| CVE-2026-85414 | The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute in all | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-84937 | The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQ | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- None
SScope- Changed
CConfidentiality- High
IIntegrity- None
AAvailability- None
| — |
| CVE-2026-84936 | The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-84935 | The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item setting | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- Required
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-84934 | The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the req | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- Required
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-84931 | The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- Required
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-84930 | The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- Required
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-84927 | The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-84926 | The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- Low
IIntegrity- None
AAvailability- None
| — |
| CVE-2026-84901 | The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing us | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- High
AAvailability- None
| — |
| CVE-2026-84899 | The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline scri | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- Required
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-84898 | The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowin | — | 2026-09-05 | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- High
PRPrivileges Required- High
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-84896 | The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- Required
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-84745 | The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public RES | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- Low
IIntegrity- None
AAvailability- None
| — |
| CVE-2026-84225 | The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, a | — | 2026-09-05 | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- High
PRPrivileges Required- High
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-84221 | The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with edito | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- None
SScope- Changed
CConfidentiality- High
IIntegrity- None
AAvailability- None
| — |
| CVE-2026-84022 | The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- Required
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-84021 | The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- Required
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-83628 | The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite install | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-83627 | The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all ver | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-83625 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all versions up to, | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-83544 | The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it within an HTML attri | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- Required
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-83543 | The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with cont | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- None
AAvailability- None
| — |
| CVE-2026-82846 | The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- Required
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-82752 | Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary size in | — | 2026-09-05 | CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Local
ACAttack Complexity- Low
ATAttack Requirements- Present
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- Low
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-82304 | The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL i | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Changed
CConfidentiality- High
IIntegrity- None
AAvailability- None
| — |
| CVE-2026-81543 | The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7 | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-81424 | The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-81423 | The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unaut | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- Required
SScope- Unchanged
CConfidentiality- None
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-81404 | The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- Required
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- Low
| — |
| CVE-2026-81348 | The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read s | — | 2026-09-05 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
AVAttack Vector- Network
ACAttack Complexity- High
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- Low
IIntegrity- None
AAvailability- None
| — |
| CVE-2026-78438 | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-78362 | The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-78150 | The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing use | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- Low
IIntegrity- None
AAvailability- None
| — |
| CVE-2026-78149 | The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- Low
IIntegrity- None
AAvailability- None
| — |
| CVE-2026-77830 | The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-77826 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepti | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- Required
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-77263 | The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-77233 | The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-76573 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'not_found' Shortcode Attri | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |