Tag

#WordPress Plugin Vulnerability

newsHIGH 7.5

CVE-2026-15406: Local File Inclusion Vulnerability in Eventin WordPress Plugin

The Eventin WordPress plugin is vulnerable to Local File Inclusion (LFI) in versions up to 4.1.22. Authenticated attackers with custom-level access can exploit this flaw to execute arbitrary PHP code, bypass access controls, and obtain sensitive data. A CVSS score of 7.5 indicates a high severity level.

1 source
newsHIGH 8.8

CVE-2026-15312: Privilege Escalation in Propovoice: All-in-One Client Management System Plugin

The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8. Authenticated attackers with `ndpv_manager`-level access can create a new WordPress user account with the `administrator` role assigned, achieving full vertical privilege escalation. Immediate action is required to update the plugin to a patched version.

1 source
newsCRITICAL 9.8

Critical Unauthenticated Broken Authentication Vulnerability in OAuth Single Sign On – SSO (OAuth Client) Plugin

A critical vulnerability (CVE-2026-28008, CVSS score: 9.8) was discovered in the OAuth Single Sign On – SSO (OAuth Client) plugin, affecting versions up to 7.0.0. This vulnerability allows unauthenticated attackers to bypass authentication, potentially leading to unauthorized access and control. Immediate action is required to update the plugin to a secure version.

1 source
newsHIGH 8.8

CVE-2026-13609: Stored Cross-Site Scripting in Frontend Admin by DynamiApps WordPress Plugin

The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 is vulnerable to stored cross-site scripting. An unauthenticated attacker can submit a double-encoded payload that is stored and later output without escaping, allowing for XSS execution in the browser of any user who views the submitted value. This vulnerability has a CVSS score of 8.8, indicating high severity.

1 source
articleCRITICAL 9.1

Critical Vulnerability in Masteriyo LMS WordPress Plugin Allows Unauthenticated Session Termination (CVE-2026-13332)

A critical vulnerability (CVE-2026-13332, CVSS 9.1) exists in the Masteriyo LMS WordPress plugin prior to version 2.3.1. This flaw allows unauthenticated attackers to terminate the active sessions of any user, including administrators, via an unauthenticated AJAX action. Immediate patching is recommended to prevent potential exploitation.

1 source
articleHIGH 8.5

Critical SQL Injection Vulnerability in SALESmanago & Leadoo Plugin

A critical SQL injection vulnerability, CVE-2026-54822, has been discovered in the SALESmanago & Leadoo plugin versions up to 3.11.2. This vulnerability has a CVSS score of 8.5, indicating high severity. Although not actively exploited, it poses a significant risk due to its potential for unauthorized data access. Immediate patching to version 3.11.3 or later is recommended.

1 source
articleHIGH 8.1

CVE-2026-9843: Arbitrary File Deletion Vulnerability in Database for Contact Form 7, WPforms, Elementor forms Plugin

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation. This allows unauthenticated attackers to delete arbitrary files, potentially leading to remote code execution. The vulnerability has a CVSS score of 8.1 and affects all versions up to 1.5.1. Immediate patching is recommended.

1 source
articleMEDIUM 4.3

CVE-2024-32110: Cross-Site Request Forgery Vulnerability in WpEvently Plugin

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the WpEvently plugin, affecting versions from n/a through 4.1.2. This vulnerability, tracked as CVE-2024-32110, has a severity score of 4.3 and allows attackers to perform Cross-Site Request Forgery attacks.

1 source