Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.9 CVE-2026-7565

LearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file' Parameter_CVE-2026-7565

The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Traversal in all versions up to, a...

thimpress LearnPress – Backup & Migration Tool CVE
MEDIUM 4.4 CVE-2026-2500

Quick Playground <= 1.3.4 - Authenticated (Administrator+) Arbitrary File Read via 'filename' Parameter_CVE-2026-2500

The Quick Playground plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.4. This is due to the `qckply_d...

davidfcarr Quick Playground CVE
MEDIUM 4.3 CVE-2026-9719

LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action_CVE-2026-9719

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...

latepoint LatePoint – Calendar Booking Plugin for Appointments and Events CVE
MEDIUM 4.3 CVE-2026-8976

RSS Aggregator by Feedzy <= 5.1.7 - Missing Authorization to Authenticated (Contributor+) Import Job Creation, Execution, Purge, Log Clearing, and Information Disclosure via Multiple AJAX Sub-Actions_CVE-2026-8976

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to authorizatio...

themeisle RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator CVE
MEDIUM 6.4 CVE-2026-8900

Simple SEO Slideshow <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes_CVE-2026-8900

The Simple SEO Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and incl...

spyrosvl Simple SEO Slideshow CVE
MEDIUM 6.4 CVE-2026-8893

Express Payment For Stripe <= 1.28.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes_CVE-2026-8893

The Express Payment For Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the [stripe-express] s...

payaddons Express Payment For Stripe CVE
MEDIUM 5.3 CVE-2026-8608

Event Monster <= 2.1.0 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via em_capture_payment AJAX Action_CVE-2026-8608

The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity...

awordpresslife Event Monster – Event Manager, Ticket Booking & Registration CVE
MEDIUM 4.3 CVE-2026-7047

Frontend User Notes <= 2.1.1 - Cross-Site Request Forgery to Note Content Modification via 'confirmEdit' Action_CVE-2026-7047

The Frontend User Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due t...

absikandar Frontend User Notes CVE
MEDIUM 4.9 CVE-2026-6448

Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters_CVE-2026-6448

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' ...

expresstech Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker CVE
MEDIUM 4.3 CVE-2026-10038

Charitable <= 1.8.11.1 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Attachment Deletion via 'avatar' Parameter_CVE-2026-10038

The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insecure Direct ...

smub Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More CVE