CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-47247 - libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in lib
CVE-2026-65052 - Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerab
CVE-2026-65051 - Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side securi
CVE-2026-65050 - Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability
CVE-2026-65049 - Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorizat
CVE-2026-65048 - Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored c
CVE-2026-1771 - The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val
CVE-2026-1372 - The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all ve
CVE-2026-15145 - The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is v
CVE-2026-8082 - The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter bef
CVE-2026-14185 - The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its
CVE-2026-14184 - The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user iden
CVE-2026-14183 - The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its
CVE-2026-13694 - The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token on
CVE-2026-13693 - The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path
CVE-2026-11767 - The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact f
CVE-2026-15782 - The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More
CVE-2026-13439 - The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege
CVE-2026-15156 - The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is v
CVE-2026-12900 - The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerab
CVE-2026-9833 - The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does
CVE-2026-8825 - The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permission
CVE-2026-13432 - The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX
CVE-2026-13156 - The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-de
CVE-2026-13147 - The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it
CVE-2026-13142 - The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce r
CVE-2026-12973 - The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ow
CVE-2026-12972 - The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ow
CVE-2026-12970 - The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting i
CVE-2026-12898 - The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a us
CVE-2026-12724 - The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body val
CVE-2026-12723 - The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its RES
CVE-2026-11868 - The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its
CVE-2026-11349 - The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress
CVE-2026-10755 - The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its
CVE-2026-10724 - The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained i
CVE-2026-57857 - The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site
CVE-2026-9734 - The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in a
CVE-2026-63030 - WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route c
CVE-2026-60137 - WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise
CVE-2026-9656 - The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Se
CVE-2026-9810 - The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user,
CVE-2026-13402 - The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of m
CVE-2026-12393 - The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order
CVE-2026-11966 - The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability chec
CVE-2026-11961 - The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the members
CVE-2026-11575 - The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticit
CVE-2026-10525 - The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data b
CVE-2026-15094 - The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'c
CVE-2026-15759 - The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordP
CVE-2026-15457 - The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t
CVE-2026-15349 - The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerabl
CVE-2026-15161 - The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in
CVE-2026-14503 - The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all ver
CVE-2026-13765 - The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vul
CVE-2026-13352 - The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict C
CVE-2026-8616 - The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of dat
CVE-2026-15395 - The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored C
CVE-2026-15160 - The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all vers
CVE-2026-15159 - The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Referenc
CVE-2026-11324 - The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerab
CVE-2026-2594 - The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version
CVE-2026-14956 - The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, an
CVE-2026-14782 - The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL
CVE-2026-7543 - The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' pa
CVE-2026-15727 - The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_
CVE-2026-15651 - The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the
CVE-2026-15610 - The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulner
CVE-2026-15407 - The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to
CVE-2026-15350 - The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up t
CVE-2026-15324 - The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress
CVE-2026-15106 - The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulner
CVE-2026-15103 - The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress
CVE-2026-15099 - The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ste
CVE-2026-15022 - The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic S
CVE-2026-15021 - The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Pr
CVE-2026-15008 - The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for
CVE-2026-15005 - The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions
CVE-2026-13767 - The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data i
CVE-2026-13755 - The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site S
CVE-2026-13754 - The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injecti
CVE-2026-13741 - The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege
CVE-2026-12979 - The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleti
CVE-2026-12978 - The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before ref
CVE-2026-12907 - The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -b
CVE-2026-12906 - The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX acti
CVE-2026-12869 - The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administra
CVE-2026-12684 - The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication
CVE-2026-12585 - The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity
CVE-2026-12525 - The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be wri
CVE-2026-12510 - The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversati
CVE-2026-12492 - The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-ti
CVE-2026-12395 - The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter b
CVE-2026-11866 - The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on seve
CVE-2026-11371 - The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summar
CVE-2026-15458 - The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' par
CVE-2026-15445 - The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' par
CVE-2026-15306 - The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is
CVE-2026-15013 - The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via
CVE-2026-13042 - The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Con
CVE-2026-15652 - The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerab
CVE-2026-15336 - The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions
CVE-2026-14987 - The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored C
CVE-2026-13005 - The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Sto
CVE-2026-12941 - The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is
CVE-2026-12753 - The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable t
CVE-2026-12434 - The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all
CVE-2026-12409 - The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages pl
CVE-2026-12997 - The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, a
CVE-2026-12512 - The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied
CVE-2026-12281 - The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode
CVE-2026-11580 - The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perfor
CVE-2026-11579 - The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify
CVE-2026-13001 - The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to mi
CVE-2026-9341 - The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulne
CVE-2026-12988 - The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during t
CVE-2026-12583 - The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input tha
CVE-2026-12511 - The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using
CVE-2026-11567 - The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms
CVE-2026-11563 - The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file
CVE-2025-15665 - The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the
CVE-2026-7640 - The WP Customer Area plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type
CVE-2026-11802 - The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Author
CVE-2026-11390 - The News Kit Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting
CVE-2026-12536 - The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
CVE-2026-12385 - The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi
CVE-2026-57815 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPMU
CVE-2026-57814 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-57407 - Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-genera
CVE-2026-12582 - The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supp
CVE-2026-12397 - The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employe
CVE-2026-12396 - The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks bef
CVE-2026-12275 - The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integrat
CVE-2026-12274 - The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to
CVE-2026-12273 - The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target vali
CVE-2026-12271 - The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt
CVE-2026-12081 - The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not res
CVE-2026-11964 - The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity o
CVE-2026-11963 - The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization
CVE-2026-10551 - The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Sc
CVE-2026-1359 - The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modifi
CVE-2026-9282 - The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to,
CVE-2026-9017 - The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorizat
CVE-2026-6939 - The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Sc
CVE-2026-6801 - The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions
CVE-2026-4661 - The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to
CVE-2026-1382 - The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fresh
CVE-2026-15155 - The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is v
CVE-2026-15010 - The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up
CVE-2026-12994 - The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypa
CVE-2026-12738 - The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to
CVE-2026-12126 - The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to
CVE-2026-12103 - The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all version
CVE-2026-11901 - The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authent
CVE-2026-11898 - The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin sett
CVE-2026-10865 - The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in
CVE-2026-10041 - The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Ob
CVE-2025-6784 - The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, a
CVE-2025-5017 - The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Inj
CVE-2026-7655 - The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in vers
CVE-2026-13378 - The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site
CVE-2026-9738 - The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scrip
CVE-2026-7620 - The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all vers
CVE-2026-7559 - The Affilia – Affiliate Program & Referral Tracking for WordPress plugin for WordPress is vulnerable
CVE-2026-6804 - The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization byp
CVE-2026-6803 - The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authoriza
CVE-2026-3576 - The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forge
CVE-2026-3552 - The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modific
CVE-2026-2354 - The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed
CVE-2026-1832 - The ThriveDesk – Live Chat, AI Chatbot, Helpdesk & Knowledge Base plugin for WordPress is vulnerable
CVE-2026-15335 - The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Par
CVE-2026-15097 - The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_sl
CVE-2026-15096 - The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module
CVE-2026-14262 - The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable t
CVE-2026-13250 - The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, a
CVE-2026-13116 - The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Dire
CVE-2026-12141 - The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vu
CVE-2025-13968 - The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Sc
CVE-2026-8678 - The MyParcel plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i
CVE-2026-7544 - The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all v
CVE-2026-5743 - The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scriptin
CVE-2026-3367 - The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scri
CVE-2026-15338 - The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion i
CVE-2026-15073 - The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generi
CVE-2026-15072 - The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generi
CVE-2026-13353 - The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress i
CVE-2026-13262 - The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is
CVE-2026-13114 - The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Store
CVE-2026-10628 - The Points and Rewards for WooCommerce plugin for WordPress is vulnerable to authorization bypass in
CVE-2026-13756 - The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to
CVE-2026-11426 - The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versi
CVE-2026-13039 - The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPres
CVE-2026-15295 - The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Si
CVE-2026-1667 - The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Sto
CVE-2026-9857 - The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and
CVE-2026-13710 - The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin
CVE-2026-13247 - The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPr
CVE-2026-13010 - The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerabl
CVE-2026-12918 - The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPr
CVE-2026-11990 - The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to author
CVE-2026-9838 - The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmlt
CVE-2026-6802 - The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in a
CVE-2026-3907 - The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book'
CVE-2026-1946 - The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data du
CVE-2026-15104 - The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPres
CVE-2026-15026 - The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Informatio
CVE-2026-14475 - The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generi
CVE-2026-12955 - The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due
CVE-2026-12924 - The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPres
CVE-2026-12400 - The FlowForms – Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Ob
CVE-2026-12108 - The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad
CVE-2026-11992 - The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up
CVE-2025-11977 - The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipur
CVE-2026-13347 - The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and
CVE-2026-12685 - The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscat
CVE-2026-12276 - The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user re
CVE-2026-12123 - The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in al
CVE-2026-15302 - The ARMember plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and in
CVE-2026-15301 - The BuddyHolis TableSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
CVE-2026-15300 - The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'l
CVE-2026-15299 - The Animation Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting
CVE-2026-15298 - The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all versions u
CVE-2026-15297 - The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for W
CVE-2026-15296 - The affiliate-toolkit – WP Affiliate Plugin with Amazon plugin for WordPress is vulnerable to Stored
CVE-2026-15293 - The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all
CVE-2026-15292 - The Sudoku Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'back
CVE-2026-15291 - The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Informat
CVE-2026-15290 - The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Mem
CVE-2026-15289 - The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to time-based SQ
CVE-2026-15288 - The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Impro
CVE-2026-15287 - The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based S
CVE-2026-15286 - The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerabl
CVE-2026-15285 - The Plus Addons for Elementor plugin for WordPress was vulnerable to Authenticated (Contributor+) St
CVE-2026-15284 - The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
CVE-2026-15283 - The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
CVE-2026-15282 - The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing
CVE-2026-5069 - The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription
CVE-2026-15070 - The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request For
CVE-2026-14894 - The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Uplo
CVE-2026-13430 - The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all
CVE-2026-11818 - The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vu
CVE-2026-11392 - The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'c
CVE-2026-12598 - The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and
CVE-2026-12597 - The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth
CVE-2026-12595 - The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth
CVE-2026-13492 - The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and inc
CVE-2026-9253 - The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Sto
CVE-2026-9240 - The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable t
CVE-2026-9237 - The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable
CVE-2026-9235 - The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modif
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.