Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.3 CVE-2026-8976

RSS Aggregator by Feedzy <= 5.1.7 - Missing Authorization to Authenticated (Contributor+) Import Job Creation, Execution, Purge, Log Clearing, and Information Disclosure via Multiple AJAX Sub-Actions_CVE-2026-8976

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to authorizatio...

themeisle RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator CVE
MEDIUM 6.4 CVE-2026-8900

Simple SEO Slideshow <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes_CVE-2026-8900

The Simple SEO Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and incl...

spyrosvl Simple SEO Slideshow CVE
MEDIUM 6.4 CVE-2026-8893

Express Payment For Stripe <= 1.28.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes_CVE-2026-8893

The Express Payment For Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the [stripe-express] s...

payaddons Express Payment For Stripe CVE
MEDIUM 5.3 CVE-2026-8608

Event Monster <= 2.1.0 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via em_capture_payment AJAX Action_CVE-2026-8608

The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity...

awordpresslife Event Monster – Event Manager, Ticket Booking & Registration CVE
MEDIUM 4.3 CVE-2026-7047

Frontend User Notes <= 2.1.1 - Cross-Site Request Forgery to Note Content Modification via 'confirmEdit' Action_CVE-2026-7047

The Frontend User Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due t...

absikandar Frontend User Notes CVE
MEDIUM 4.9 CVE-2026-6448

Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters_CVE-2026-6448

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' ...

expresstech Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker CVE
MEDIUM 4.3 CVE-2026-10038

Charitable <= 1.8.11.1 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Attachment Deletion via 'avatar' Parameter_CVE-2026-10038

The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insecure Direct ...

smub Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More CVE
LOW 3.8 CVE-2025-12656

Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.128 - Authenticated (Admin+) Arbitrary Directory Deletion_CVE-2025-12656

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient ...

wpvividplugins WPvivid — Backup, Migration & Staging CVE
MEDIUM 6.8 CVE-2026-6242

Authenticated Format String Vulnerability in ONVIF Subscribe Service on TP-Link Tapo C520WS_CVE-2026-6242

An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper handling of externally supplie...

TP-Link Systems Inc. Tapo C520WS v2 CVE
MEDIUM 6.8 CVE-2026-6241

Authenticated Format String Vulnerability in ONVIF AddScopes Method on TP-Link Tapo C520WS_CVE-2026-6241

An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly passed ...

TP-Link Systems Inc. Tapo C520WS v2 CVE