Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-9172

Devs Accounting <= 1.2.0 - Missing Authorization to Unauthenticated Account Deletion via /delete-account/ REST Endpoint_CVE-2026-9172

The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due...

ajitdas Devs Accounting – Simple Accounting and Invoicing Solution CVE
MEDIUM 6.1 CVE-2026-8905

Osiris Signature Banner <= 0.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'prepend_text' Parameter_CVE-2026-8905

The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due...

osiris8 Osiris Signature Banner CVE
MEDIUM 6.4 CVE-2026-8896

MIR blocks and shortcodes <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes_CVE-2026-8896

The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute (and other attributes suc...

mirsoftware MIR blocks and shortcodes CVE
MEDIUM 6.4 CVE-2026-8865

Avalon23 Products Filter for WooCommerce <= 1.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes_CVE-2026-8865

The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'avalon23_qr' shortcode in a...

paradigmatools Avalon23 Products Filter for WooCommerce CVE
HIGH 7.5 CVE-2026-8705

ClearSale Total <= 3.4.2 - Unauthenticated SQL Injection_CVE-2026-8705

The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of the `clearsale_total_push` AJ...

clearsale ClearSale Total <= 3.4.2 CVE
MEDIUM 5.3 CVE-2026-8690

RentMy Real-Time Rental Management Plugin <= 4.0.4.1 - Missing Authorization to Unauthenticated Settings Update via rentmy_cdn_request AJAX Action_CVE-2026-8690

The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0....

rentmy RentMy Real-Time Rental Management Plugin CVE
MEDIUM 4.3 CVE-2026-8688

Advance Nav Menu Manager <= 1.3 - Missing Authorization to Authenticated (Subscriber+) Nav Menu Item Modification via anmm_save_menu_data AJAX Action_CVE-2026-8688

The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to t...

krishaweb Advance Nav Menu Manager CVE
MEDIUM 6.1 CVE-2026-8628

EntreDroppers <= 1.1.2 - Reflected Cross-Site Scripting via PHP_SELF Parameter_CVE-2026-8628

The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including,...

owencutajar EntreDroppers CVE
MEDIUM 6.1 CVE-2026-8622

Image Sizes on Demand <= 1.3 - Reflected Cross-Site Scripting via PHP_SELF Server Variable_CVE-2026-8622

The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Variable in all versions up to, ...

pixelwelt Image Sizes on Demand CVE
MEDIUM 5.3 CVE-2026-8617

SearchPlus <= 1.7.1 - Missing Authorization to Unauthenticated Settings Modification and Deletion via searchplus_save_token & searchplus_reset_token AJAX Actions_CVE-2026-8617

The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, and including, 1.7.1. This i...

ailchev SearchPlus CVE