Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-56048

WordPress Payment Gateway Based Fees and Discounts for WooCommerce plugin <= 3.0.0 - Insecure Direct Object References (IDOR) vulnerability_CVE-2026-56048

Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce

tychesoftwares Payment Gateway Based Fees and Discounts for WooCommerce n/a CVE
HIGH 7.1 CVE-2026-56047

WordPress perfmatters plugin <= 2.6.3 - Reflected Cross Site Scripting (XSS) vulnerability_CVE-2026-56047

Unauthenticated Cross Site Scripting (XSS) in perfmatters

Perfmatters, Powered Kinsta + GeneratePress Docs Changelog Feature requests Legal Affiliate Contact perfmatters n/a CVE
MEDIUM 6.5 CVE-2026-56046

WordPress ListingPro theme <= 2.9.11 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56046

Subscriber Cross Site Scripting (XSS) in ListingPro

CridioStudio ListingPro n/a CVE
HIGH 7.1 CVE-2026-56045

WordPress Automatic plugin < 3.135.1 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56045

Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.

ValvePress Automatic n/a CVE
HIGH 7.1 CVE-2026-56044

WordPress Blog2Social plugin <= 8.9.2 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56044

Unauthenticated Cross Site Scripting (XSS) in Blog2Social

Adenion Blog2Social n/a CVE
HIGH 7.1 CVE-2026-56043

WordPress Customer Reviews for WooCommerce plugin <= 5.110.1 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56043

Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce

CusRev Customer Reviews for WooCommerce n/a CVE
HIGH 7.1 CVE-2026-56041

WordPress Responsive Lightbox plugin <= 2.7.6 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56041

Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox

dFactory Responsive Lightbox n/a CVE
HIGH 7.1 CVE-2026-56040

WordPress Gutenverse Form plugin <= 2.4.7 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56040

Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form

WordPress.com Gutenverse Form n/a CVE
HIGH 7.1 CVE-2026-56039

WordPress Quick Interest Slider plugin <= 3.1.6 - Reflected Cross Site Scripting (XSS) vulnerability_CVE-2026-56039

Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider

WordPress.com Quick Interest Slider n/a CVE
HIGH 8.8 CVE-2026-56038

WordPress Frisbii Pay plugin <= 1.8.2 - Privilege Escalation vulnerability_CVE-2026-56038

Contributor Privilege Escalation in Frisbii Pay

Frisbii Frisbii Pay n/a CVE