Where
-Infinity
0

WordPressCustomer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Injection via 'path' Parameter

Risk 86
Severity
9.8
First published (updated )

Squirrly SEO SEO Plugin by Squirrly SEOSEO Plugin by Squirrly SEO <= 14.0.0 - Unauthenticated Arbitrary Post Creation and Stored Cross-Site Scripting via savePost()

Risk 44
Severity
7.2
First published (updated )

Backstage - Customizer Demo Access plugin for WordPressBackstage <= 1.4.2 - Unauthenticated Privilege Escalation via Permissive Demo Role Capabilities

Risk 31
Severity
7.5
EPSS
0.26%
First published (updated )

WordPress DIGITSDigits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing

Risk 99
Severity
9.8
First published (updated )

BabelZ Google Translate WidgetBabelZ – Google Translate Widget <= 1.1.5 - CSRF to Stored XSS

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

WordPress WordPress连接微博WordPress连接微博 <= 2.5.6 - Stored XSS via CSRF

Risk 38
Severity
6.1
First published (updated )

BleepingComputerWordPress plugin disguised as a security tool injects backdoor

First published (updated )

BleepingComputerWooCommerce admins targeted by fake security patches that hijack sites

First published (updated )

WP-Syntax WP-SyntaxWP-Syntax <= 1.2 - Author+ Potential ReDoS

Risk 43
Severity
7.5
First published (updated )

WP MultiTaskingWP MultiTasking <= 0.1.12 - Permalink Suffix Update via CSRF

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

WP MultiTasking WP MultiTasking pluginWP MultiTasking <= 0.1.12 - Header/Footer/Body Script Update via CSRF

Risk 22
Severity
4.3
First published (updated )

The RegisterMobsters now overlap with cybercrime gangs, says Europol

First published (updated )

BleepingComputerMalware campaign 'DollyWay' breached 20,000 WordPress sites

First published (updated )

NextGen GalleryNextGEN Gallery < 3.59.9 - Admin+ Stored XSS

Risk 24
Severity
3.5
First published (updated )

Categorized Gallery PluginCategorized Gallery Plugin <= 2.0 - Authenticated (Contributor+) SQL Injection

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Wordquest Guten Free Options WordpressGuten Free Options <= 0.9.5 - Reflected XSS

Risk 38
Severity
6.1
First published (updated )

aklamator INfeedaklamator-infeed <= 2.0.0 - Admin+ Stored XSS

Risk 29
Severity
4.8
First published (updated )

Androidbubble Wp Docs WordpressWordPress WP Docs plugin <= 2.2.1 - Cross Site Scripting (XSS) vulnerability

Risk 29
Severity
5.9
First published (updated )

WordPress Auction PluginWordPress Auction <= 3.7 - Editor+ SQL Injection

Risk 86
Severity
9.8
First published (updated )

WordPress Auction PluginWordPress Auction <= 3.7 - Editor+ Stored XSS

Risk 29
Severity
4.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/mwdelaney/wp-enable-svgWP Enabled SVG <= 0.7 - Author+ Stored XSS via SVG

Risk 29
Severity
4.8
First published (updated )

코드엠샵 소셜톡코드엠샵 소셜톡 <= 1.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Risk 39
Severity
6.4
First published (updated )

NextGen GalleryNextGEN Gallery < 3.59.5 - Admin+ Stored XSS

Risk 29
Severity
4.8
First published (updated )

Quotes llama Quotes llamaQuotes llama <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Risk 39
Severity
6.4
First published (updated )

Alphabetical List WordPress pluginAlphabetical List <= 1.0.3 - Settings Update via CSRF

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

WordPress Media File RenameMedia Library Tools < 1.5.0 - Author+ Stored XSS via SVG

Risk 34
Severity
5.4
First published (updated )

Total-Soft Ts Poll WordpressTS Poll – Survey, Versus Poll, Image Poll, Video Poll < 2.4.0 - Admin+ SQL Injection

Risk 49
Severity
7.2
EPSS
0.05%
First published (updated )

WordPressWordPress Core < 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via use of the_meta(); function

Risk 34
Severity
5.4
First published (updated )

Vladyslavbondarenko Adstxt Wordpressadstxt Plugin <= 1.0.0 - Settings Update via CSRF

Risk 16
Severity
4.3
EPSS
0.05%
First published (updated )

Rubayathasan Infolinks Ad Wrap Wordpressinfolinks Ad Wrap <= 1.0.2 - Settings Update via CSRF

Risk 27
Severity
6.5
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203