Vulnerabilities

Summary — last 7 days

New vulnerabilities2,629▼ 216 vs. last week
Critical / high1,378▲ 154 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)81▼ 449 vs. last week
–

14 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (4.3)0.25%—WP Full PAY Stripe Payment FormsAI8/29/20268/31/2026
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before cancelling it, allowing a user with a confirmed portal session to cancel subscriptions belonging to other customers. Exploitation…
DeferredMedium (4.3)0.25%—WP Full PAY Stripe Payment FormsAI8/26/20268/26/2026
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before acting on it, allowing a user with a confirmed portal session to cancel, reactivate or modify subscriptions belonging to other…
DeferredMedium (5.3)0.34%—WP Full PAY Stripe Payment FormsAI8/26/20268/26/2026
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a customer portal session has completed its confirmation step before returning data, allowing unauthenticated users to read another customer's subscription and billing information.
DeferredHigh (7.5)0.35%—WP Full PAY Stripe Payment FormsAI8/6/20268/26/2026
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor — using a nonce that is embedded in every public page containing a payment form — to…
DeferredHigh (7.2)0.32%—WP Cost Estimation Payment Forms BuilderAI7/9/20267/9/2026
The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter in all versions up to, and including, 10.5.97 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
DeferredHigh (7.5)0.38%—Loopus WP Cost Estimation AND Payment Forms BuilderAI3/25/20266/17/2026
Missing Authorization vulnerability in loopus WP Cost Estimation & Payment Forms Builder WP_Estimation_Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cost Estimation & Payment Forms Builder: from n/a through < 10.3.0.
DeferredHigh (7.5)0.35%—WP Full PAY Stripe Payment FormsAI10/25/20256/17/2026
The Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress is vulnerable to SQL Injection via the 'wpfs-form-name' parameter in all versions up to, and including, 8.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…
DeferredMedium (6.4)0.33%—Payment Forms FOR PaystackAI4/10/20256/17/2026
The Payment Forms for Paystack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'datepicker', 'textarea', and 'text' in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
DeferredHigh (7.6)0.88%—Kendysond Payment-forms-for-paystackAI3/27/20256/17/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kendysond Payment Forms for Paystack payment-forms-for-paystack allows SQL Injection.This issue affects Payment Forms for Paystack: from n/a through <= 4.0.1.
DeferredHigh (7.1)0.35%—Loopus WP Cost Estimation AND Payment Forms BuilderAI4/17/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Loopus WP Cost Estimation & Payment Forms Builder allows Reflected XSS.This issue affects WP Cost Estimation & Payment Forms Builder: from n/a through 10.1.75.
DeferredMedium (6.5)0.29%—Paystack Payment FormsAI4/17/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paystack Payment Forms for Paystack allows Stored XSS.This issue affects Payment Forms for Paystack: from n/a through 3.4.1.
DeferredMedium (6.5)0.44%—Loopus WP Cost Estimation & Payment Forms BuilderAI4/17/20246/17/2026
Missing Authorization vulnerability in Loopus WP Cost Estimation & Payment Forms Builder.This issue affects WP Cost Estimation & Payment Forms Builder: from n/a through 10.1.76.
DeferredHigh (8.5)0.49%—Loopus WP Cost Estimation AND Payment Forms BuilderAI3/31/20246/17/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Cost Estimation & Payment Forms Builder.This issue affects WP Cost Estimation & Payment Forms Builder: from n/a through 10.1.75.
ModifiedMedium (5.4)0.53%—Payment Forms FOR Paystack2/8/20246/17/2026
The Payment Forms for Paystack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…