Vulnerabilities

Summary — last 7 days

New vulnerabilities2,731▼ 12 vs. last week
Critical / high1,272▼ 242 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)230▲ 212 vs. last week
–

1,862 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.4)0.16%—Bold-themes Bold Page BuilderAI9/30/20269/30/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the plugin's bt_bb_icon shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for…
DeferredMedium (6.4)0.16%—Bold-themes Bold Page BuilderAI9/30/20269/30/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'images' parameter of the plugin's bt_bb_css_image_grid shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible…
DeferredMedium (4.3)0.15%—Stylemixthemes Masterstudy LMSAI9/24/20269/24/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated user, such as a subscriber, to create course progress records for courses they have no access to.
DeferredMedium (5.3)0.18%—Stylemixthemes Masterstudy LMSAI9/24/20269/24/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated users to create accounts, and be logged into them, on sites where registration has…
DeferredHigh (7.2)0.33%—Niteothemes CMPAI9/22/20269/22/2026
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'cmp_ajax_import_settings' AJAX action in all versions up to, and including, 4.1.17. This makes it possible…
DeferredHigh (7.2)0.29%—Jegthemes JEG KITAI9/18/20269/18/2026
The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.2.16 due to insufficient input sanitization and output escaping. This makes it possible for…
DeferredMedium (6.1)0.37%—Hasthemes ShoplentorAI9/18/20269/19/2026
The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query-String Parameter Name in all versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping. This makes it possible for…
DeferredMedium (5.3)0.45%—Elegantthemes DiviAI9/18/20269/18/2026
The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.11.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to…
DeferredLow (2.7)0.28%—Stylemixthemes BookitAI9/18/20269/18/2026
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users with its low-privileged custom Staff role to delete arbitrary appointments.
DeferredHigh (7.6)0.38%—Sktthemes SKT Addons FOR ElementorAI9/17/20269/19/2026
Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.
DeferredMedium (6.5)0.20%—Catapultthemes Cookie ConsentAI9/16/20269/17/2026
The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk actions on its administration screens, and does not restrict the targeted items to its own records, allowing attackers to make a logged in admin permanently delete arbitrary posts and pages via a…
DeferredMedium (6.4)0.28%—Bold-themes Bold Page BuilderAI9/16/20269/16/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' parameter of the bt_bb_shortcode shortcode in all versions up to, and including, 5.9.6. This is due to a bypassable security filter (bt_bb_save_pre) that can be circumvented via null byte injection,…
DeferredMedium (5.3)0.34%—Stylemixthemes BookitAI9/13/20269/14/2026
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.
DeferredMedium (6.4)0.36%—Bold-themes Bold Timeline LiteAI9/11/20269/11/2026
The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
Awaiting AnalysisHigh (8.6)0.82%—Rarathemes Rara ONE Click Demo ImportAI9/9/20269/10/2026
Rara One Click Demo Import plugin for WordPress before 1.3.5 contains an arbitrary file upload vulnerability that allows authenticated attackers with Administrator privileges to upload arbitrary PHP files by passing a false value to wp_handle_upload() that disables WordPress core's file type validation checks across…
DeferredMedium (5.4)0.23%—Catapultthemes Cookie ConsentAI9/9/20269/9/2026
The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on several of its settings AJAX actions, allowing any authenticated user, such as a subscriber, to read and destroy scan data belonging to the administrator and to overwrite the WPLP Cookie Consent WordPress plugin before…
DeferredMedium (4.3)0.25%—Catapultthemes Cookie ConsentAI9/9/20269/9/2026
The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have capability or nonce checks on some of its A/B testing actions, allowing any authenticated user, such as a subscriber, to overwrite the cookie banner configuration shown to every visitor and to irreversibly reset the stored A/B test results.
DeferredMedium (5.3)0.16%—Catapultthemes Cookie ConsentAI9/9/20269/9/2026
The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing unauthenticated attackers to overwrite a site-wide option with arbitrary data.
DeferredMedium (6.8)0.43%—Bold-themes Bold Page BuilderAI9/6/20269/8/2026
The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.
DeferredHigh (8)0.41%—Hasthemes HT MenuAI9/5/20269/8/2026
The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those stored settings when the menu is rendered, allowing users with minimal permissions such as Subscribers to store JavaScript that executes in the…
DeferredMedium (6.8)0.43%—Bold-themes Bold Page BuilderAI9/5/20269/8/2026
The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML attributes, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.
DeferredMedium (6.8)0.43%—Bold-themes Bold Page BuilderAI9/5/20269/8/2026
The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a filter that can be evaded, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user clicks the affected link.
DeferredMedium (5)0.36%—Elegantthemes DiviAI9/5/20269/8/2026
The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` function using `wp_remote_get()` instead of `wp_safe_remote_get()` to fetch a remote image URL, which does not restrict requests to…
DeferredMedium (6.4)0.26%—Elegantthemes DiviAI9/5/20269/8/2026
The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider_item` shortcode in all versions up to, and including, 4.27.6. This is due to the `image_src` field not being included in the `$url_options` whitelist (which only contains `url`,…
DeferredMedium (5.3)0.18%—Stylemixthemes BookitAI9/3/20269/4/2026
Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.