Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.4 CVE-2026-4081

ZeM STL <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes_CVE-2026-4081

The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [zemstl] shortcode in all versions up to and including 1.0. T...

jhdscript ZeM STL CVE
MEDIUM 6.4 CVE-2026-4080

Easy Cart <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes_CVE-2026-4080

The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all versions up to and including...

zeshanb Easy Cart CVE
MEDIUM 4.3 CVE-2026-4071

BirdSeed <= 2.2.0 - Cross-Site Request Forgery via BirdSeed Token Change_CVE-2026-4071

The BirdSeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing n...

birdseedapp BirdSeed CVE
MEDIUM 4.4 CVE-2026-3620

Word Replacer <= 0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Replacement' Parameter_CVE-2026-3620

The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'replacement' parameter in all versions up to, and incl...

takien Word Replacer CVE
MEDIUM 6.1 CVE-2026-2425

hiWeb Migration Simple <= 2.0.0.1 - Reflected Cross-Site Scripting via 'new_domain' Parameter_CVE-2026-2425

The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' parameter in all versions up t...

den-media hiWeb Migration Simple CVE
MEDIUM 6.4 CVE-2026-2382

FPW Category Thumbnails <= 1.9.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'id' Parameter_CVE-2026-2382

The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'fpw_fs_get_file' AJAX ...

frankpw FPW Category Thumbnails CVE
MEDIUM 6.1 CVE-2026-1451

rognone <= 0.6.2 - Reflected Cross-Site Scripting via 'a' Parameter_CVE-2026-1451

The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to, and including, 0.6.2 due ...

federicocarrara rognone CVE
MEDIUM 6.1 CVE-2026-1450

rognone <= 0.6.2 - Reflected Cross-Site Scripting via 'mode' Parameter_CVE-2026-1450

The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up to, and including, 0.6.2 d...

federicocarrara rognone CVE
MEDIUM 5.5 CVE-2025-5085

wp-nano-ad <= 1.31 - Authenticated (Administrator+) Stored Cross-Site Scripting via blogrole_link Parameter_CVE-2025-5085

The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter in all versions up to, and inclu...

ariyes WP Nano AD CVE
MEDIUM 6.8 CVE-2026-5422

Path Traversal in jupyter/jupyter_CVE-2026-5422

A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() func...

jupyter jupyter/jupyter unspecified CVE