Where
-Infinity
0

Vendor Risk Score

See how wordpress compares to other vendors in security performance

View Risk Score →

Software

Severity
7.2
EPSS
0.24%
XSS
AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phonenumber' parameter in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

First published (updated )
Severity
6.4
XSS
AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shapesvalues Parameter in all versions up to, and including, 4.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The fc-call-nonce nonce required by the endpoint is exposed to all frontend visitors who view a map page via window.wpgmplocal.nonce, enabling any authenticated subscriber to read the nonce and craft a valid request; additionally, the secondary wpnonce check in the drawing handler can be bypassed by simply omitting the wpnonce parameter from the request.

First published (updated )
Severity
7.2
EPSS
0.24%
XSS
AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

First published (updated )
Severity
9
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and above to obtain a validly signed identity assertion for another user, including an administrator, and authenticate as them at any application that uses the site for single sign-on.

First published (updated )
Severity
5.3
EPSS
0.24%
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.

First published (updated )
Severity
7.1
EPSS
0.18%
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions.

First published (updated )
Severity
5.3
EPSS
0.25%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.

First published (updated )
Severity
7.6
EPSS
0.29%
SQL Injection
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.

First published (updated )
Severity
6.5
EPSS
0.17%
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions.

First published (updated )
Severity
7.1
EPSS
0.19%
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions.

First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions.

First published (updated )
Severity
7.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions.

First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Contributor Broken Access Control in WSP MCP &#8211; AI Agents Connector <= 2.7.0 versions.

First published (updated )
Severity
7.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions.

First published (updated )
Severity
8.5
SQL Injection
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L

Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.

First published (updated )
Severity
5.3
EPSS
0.22%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.

First published (updated )
Severity
7.6
EPSS
0.29%
SQL Injection
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

Administrator SQL Injection in Email Log <= 2.63 versions.

First published (updated )
Severity
6.5
EPSS
0.17%
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions.

First published (updated )
Severity
7.5
EPSS
0.33%
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.

First published (updated )
Severity
6.5
EPSS
0.34%
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.

First published (updated )
Severity
7.6
EPSS
0.29%
SQL Injection
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

Editor SQL Injection in Ultimeter <= 3.0.8 versions.

First published (updated )
Severity
6.5
EPSS
0.16%
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.

First published (updated )
Severity
3.3
EPSS
0.18%
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy.

First published (updated )
Severity
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Missing Authorization vulnerability in extendthemes Vireo vireo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vireo: from n/a through <= 1.0.24.

First published (updated )
Severity
5.1
XSS
AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

WordPress 3dady Real-Time Web Stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by exploiting unsanitized input fields. Attackers can insert JavaScript payloads in the dadyinputtext or dady2inputtext fields via the plugin options panel to execute arbitrary code when the page is viewed.

First published (updated )
Severity
8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

An unauthenticated attacker can make getpagetemplate() page-template resolution include a chosen readable local .php file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

First published (updated )
Severity
6.8
XSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values before outputting them within a front-end style block, and does not verify that a user may edit the target post, allowing users with contributor-level access or above to store JavaScript that executes in the browser of anyone viewing the affected post, including administrators.

First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization checks in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to modify arbitrary API keys (Pixabay, Unsplash, Pixels) configured by site administrators via the 'pixabayapi', 'unsplashapi', or 'pixelsapi' parameters.

First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.8 via the editmetavalue due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to delete arbitrary media attachments site-wide by supplying any numeric attachment ID in the file-field parameter alongside the corresponding delete flag, causing content loss and broken pages. Exploitation requires that the attacker's post is governed by a Custom Field Template containing at least one file-type field with the mediaRemove option not enabled, which is the default configuration for file fields.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203