Wp-feedstats
Wp-feedstats Wordpress Plugin: vulnerabilities and CVEs
Wp-feedstats Wordpress Plugin has 7 published vulnerabilities, 6 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs7
Last 12 months6
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84899 | Medium (6.8) | 0.43% | — | Sep 5, 2026 | The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that… |
| CVE-2025-15485 | High (8.2) | 0.20% | — | Sep 2, 2026 | The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc |
| CVE-2026-14333 | High (7.5) | 0.41% | — | Jul 31, 2026 | The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download… |
| CVE-2026-14322 | Medium (5.3) | 0.30% | — | Jul 22, 2026 | The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create… |
| CVE-2026-13156 | Medium (5.4) | 0.14% | — | Jul 20, 2026 | The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in… |
| CVE-2026-8163 | High (8.8) | 0.43% | — | Jun 23, 2026 | The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vulnerability exploitable by authenticated users… |
| CVE-2007-4104 | Medium (4.3) | 5.1% | — | Jul 31, 2007 | Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, one of which involves an… |