Where
-Infinity
0

Saad Iqbal Post SMTP (WordPress plugin)WordPress Post SMTP plugin <= 3.2.0 - Account Takeover Vulnerability

Risk 83
Severity
8.8
First published (updated )

Post SMTP Post SMTPPost SMTP <= 3.1.2 - Authenticated (Administrator+) SQL Injection via columns Parameter

Risk 30
Severity
4.9
First published (updated )

Wpexperts Givewp Square WordpressWPExperts Square For GiveWP <= 1.3.1 - Authenticated (Subscriber+) SQL Injection

Risk 38
Severity
6.5
First published (updated )

Post SMTP Post SMTPPost SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting

Risk 44
Severity
7.2
First published (updated )

Wpexperts Wp Multi Store Locator WordpressWordPress WP Multi Store Locator Plugin <= 2.4.7 - Cross Site Scripting (XSS) vulnerability

Risk 27
Severity
7.1
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Post SMTP Post SMTPWordPress Post SMTP plugin <= 2.9.11 - Broken Access Control vulnerability

Risk 56
Severity
8.8
EPSS
0.04%
First published (updated )

Wpexperts Wp Multi Store Locator WordpressWP Multi Store Locator <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Risk 39
Severity
6.4
First published (updated )

Wpexperts Post Smtp WordpressWordPress Post SMTP plugin <= 2.9.9 - SQL Injection vulnerability

Risk 66
Severity
7.6
First published (updated )

Wpexperts WPExperts Square For GiveWPWordPress WPExperts Square For GiveWP plugin <= 1.3 - SQL Injection vulnerability

Risk 55
Severity
8.5
First published (updated )

Wpexperts Mycred WordpressWordPress myCred plugin <= 2.7.2 - Sensitive Data Exposure vulnerability

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Wpexperts Wp Secure Maintenance WordpressWP Secure Maintenance < 1.7 - Admin+ Stored XSS

Risk 40
Severity
5.9
First published (updated )

Wpexperts License Manager For Woocommerce WordpressLicense Manager for WooCommerce <= 3.0.6 - Improper Authorization to Authenticated(Contributor+) Sensitive Information Exposure

Risk 38
Severity
6.5
First published (updated )

Wpexperts Post Smtp WordpressWordPress POST SMTP Mailer plugin <= 2.8.6 - Broken Access Control on API vulnerability

Risk 86
Severity
9.8
First published (updated )

Wpexperts Post Smtp WordpressPOST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL Injection

Risk 49
Severity
7.2
EPSS
0.06%
First published (updated )

Wpexperts Wholesale For WooCommerceWordPress Wholesale For WooCommerce plugin <= 2.3.1 - Unauthenticated Arbitrary Post/Page vulnerability

Risk 31
Severity
7.5
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Wpexperts Wholesale For WooCommerceWordPress Wholesale For WooCommerce plugin <= 2.3.0 - Unauthenticated Sensitive Data Exposure vulnerability

Risk 19
Severity
5.3
EPSS
0.04%
First published (updated )

Post SMTP Post SMTPWordPress POST SMTP Mailer plugin <= 2.8.6 - Reflected Cross Site Scripting (XSS) vulnerability

Risk 36
Severity
7.1
EPSS
0.04%
First published (updated )

Wpexpertsio WC Shop Sync – Integrate Square and WooCommerce for Seamless Shop ManagementWordPress APIExperts Square for WooCommerce plugin <= 4.2.9 - Cross Site Scripting (XSS) vulnerability

Risk 36
Severity
7.1
EPSS
0.04%
First published (updated )

Ultimate Plugins Password Protected – Ultimate PluginPassword Protected <= 2.6.6 - Authenticated (Admin+) Stored Cross-Site Scripting

Risk 29
Severity
4.8
First published (updated )

Wpexperts Post Smtp WordpressPOST SMTP Mailer < 2.5.7 - Arbitrary Log Deletion via CSRF

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Wpexperts Post Smtp WordpressPost SMTP < 2.8.7 - Admin+ SQL Injection

Risk 49
Severity
7.2
EPSS
0.05%
First published (updated )

Wpexperts Post Smtp WordpressPOST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API

Risk 63
Severity
9.8
EPSS
4.26%
First published (updated )

Wpexperts Post Smtp WordpressPost SMTP < 2.8.7 - Reflected Cross-Site Scripting

Risk 27
Severity
6.1
EPSS
0.05%
First published (updated )

Wpexperts Post Smtp WordpressPOST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Unauthenticated Stored Cross-Site Scripting via device

Risk 32
Severity
7.2
EPSS
0.07%
First published (updated )

Wpexperts Post Smtp WordpressPOST SMTP Mailer <= 2.8.6 - Reflected Cross-Site Scripting via msg

Risk 27
Severity
6.1
EPSS
0.09%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Wpexperts New User Approve WordpressWordPress New User Approve Plugin <= 2.5.1 is vulnerable to Cross Site Request Forgery (CSRF)

Risk 77
Severity
8.8
First published (updated )

Wpexperts Rocket Maintenance Mode \& Coming Soon Page WordpressWordPress Rocket Maintenance Mode & Coming Soon Page Plugin <= 4.3 is vulnerable to Cross Site Scripting (XSS)

Risk 40
Severity
5.9
First published (updated )

Wpexperts Mycred WordpressWordPress myCred Plugin <= 2.6.1 is vulnerable to Cross Site Scripting (XSS)

Risk 46
Severity
6.5
First published (updated )

Wpexperts License Manager For Woocommerce WordpressWordPress License Manager for WooCommerce Plugin <= 2.2.10 is vulnerable to SQL Injection

Risk 47
Severity
7.6
First published (updated )

Wpexperts Post Smtp WordpressPOST SMTP Mailer < 2.7.1 - Unauthenticated Cross-site Scripting

Risk 27
Severity
6.1
EPSS
0.10%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203