Vulnerabilities

Summary — last 7 days

New vulnerabilities2,744▼ 111 vs. last week
Critical / high1,254▼ 280 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)244▲ 208 vs. last week
–

128 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.2)0.32%—Magic Tooltips FOR Contact Form 7AI10/3/202610/6/2026
The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 1.0.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
DeferredHigh (7.5)0.25%—Tipsandtricks-hq WP Express CheckoutAI9/30/20269/30/2026
Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.
DeferredMedium (5.3)0.16%—Tipsandtricks-hq WP Express CheckoutAI9/9/20269/9/2026
The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.
DeferredMedium (5.3)0.16%—Tipsandtricks-hq WP Express CheckoutAI9/2/20269/3/2026
The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.
DeferredCritical (9.3)0.40%—Tipsandtricks-hq WP EmemberAI6/17/20266/17/2026
Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.
DeferredHigh (8.1)0.43%—TipsyAI6/17/202610/6/2026
Unauthenticated Local File Inclusion in Tipsy <= 1.1 versions.
DeferredMedium (5.3)0.33%—Tips AND Tricks HQ WP EmemberAI6/4/20267/22/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue affects WP eMember: from n/a through v10.2.2.
DeferredHigh (7.1)0.25%—Tips AND Tricks HQ WP EmemberAI3/19/20266/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tips and Tricks HQ WP eMember allows Reflected XSS.This issue affects WP eMember: from n/a through v10.2.2.
DeferredMedium (5.3)0.31%—Tips AND Tricks HQ WP EmemberAI3/19/20266/17/2026
Missing Authorization vulnerability in Tips and Tricks HQ WP eMember allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP eMember: from n/a through v10.2.2.
DeferredMedium (6.5)0.16%—Wordpress TooltipsAI12/31/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomas WordPress Tooltips wordpress-tooltips allows Stored XSS.This issue affects WordPress Tooltips: from n/a through <= 10.9.3.
DeferredMedium (6.4)0.18%—Tips ShortcodeAI11/21/202510/7/2026
The Tips Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tip' shortcode in all versions up to, and including, 0.2.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to…
AnalyzedMedium (4.8)0.31%—Deluxeblogtips MB Custom Post Types & Custom Taxonomies5/15/20256/17/2026
The MB Custom Post Types & Custom Taxonomies WordPress plugin before 2.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AnalyzedMedium (5.4)0.28%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart5/1/20256/17/2026
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_cart_button' shortcode in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AnalyzedMedium (5.3)0.36%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart5/1/20256/17/2026
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 via the 'process_payment_data' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the quantity of a…
AnalyzedMedium (6.5)0.41%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart5/1/20256/17/2026
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 due to lack of randomization of a user controlled key. This makes it possible for unauthenticated attackers to access customer shopping carts and edit product links, add…
DeferredHigh (7.1)0.29%—Novium Wowhead TooltipsAI4/24/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Novium WoWHead Tooltips wowhead-tooltips allows Stored XSS.This issue affects WoWHead Tooltips: from n/a through <= 2.0.1.
DeferredHigh (7.1)0.24%—Grimdonkey Magic THE Gathering Card TooltipsAI2/22/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in grimdonkey Magic the Gathering Card Tooltips magic-the-gathering-card-tooltips allows Stored XSS.This issue affects Magic the Gathering Card Tooltips: from n/a through <= 3.5.0.
DeferredMedium (6.5)0.37%—Grimdonkey Magic THE Gathering Card TooltipsAI1/24/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in grimdonkey Magic the Gathering Card Tooltips magic-the-gathering-card-tooltips allows Stored XSS.This issue affects Magic the Gathering Card Tooltips: from n/a through <= 3.4.0.
DeferredMedium (6.4)0.30%—Tipsandtricks-hq Compact WP Audio PlayerAI1/7/20256/17/2026
Server-Side Request Forgery (SSRF) vulnerability in mra13 Compact WP Audio Player compact-wp-audio-player allows Server Side Request Forgery.This issue affects Compact WP Audio Player: from n/a through <= 1.9.14.
DeferredMedium (6.4)0.34%—Tipsandtricks-hq Compact WP Audio PlayerAI10/24/20246/17/2026
The Compact WP Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_embed_player shortcode in all versions up to, and including, 1.9.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AnalyzedMedium (5.4)0.23%—Tipsandtricks-hq WP Estore8/12/20246/17/2026
The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
AnalyzedMedium (5.4)0.40%—Tipsandtricks-hq WP Estore8/12/20246/17/2026
The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AnalyzedMedium (6.5)0.45%—Tipsandtricks-hq WP Estore8/12/20246/17/2026
The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AnalyzedMedium (6.1)0.19%—Tipsandtricks-hq WP Emember8/5/20246/17/2026
The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
AnalyzedMedium (5.5)0.21%—Tipsandtricks-hq WP Affiliate Platform7/29/20246/17/2026
The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change delete them via a CSRF attack