Vulnerabilities
Summary — last 7 days
New vulnerabilities3,333▲ 343 vs. last week
Critical / high1,493▲ 121 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 117 vs. last week
1,059 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Received | Critical (10) | — | — | Backupsheep Wordpress Backup PluginAI | 10/1/2026 | 10/1/2026 | The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files… | |
| Deferred | High (7.5) | — | — | Wordpress Backup MigrationAI | 9/30/2026 | 9/30/2026 | Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions. | |
| Deferred | High (7.1) | — | — | Wordpress Persistent Login Persistent LoginAI | 9/30/2026 | 9/30/2026 | Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions. | |
| Deferred | Low (2.7) | 0.19% | — | MCP Server FOR WordpressAI | 9/26/2026 | 9/28/2026 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of its workflow REST routes, allowing users with the Contributor role to disclose the title and publication status of any post, page or custom post type, including other users' private, draft, pending… | |
| Deferred | Low (2.7) | 0.17% | — | MCP Server FOR WordpressAI | 9/26/2026 | 9/28/2026 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check on its workflow create, update and delete REST routes, allowing users with the Contributor role to modify, delete and create site-wide workflow configuration, including workflows created by… | |
| Deferred | High (8.8) | 0.14% | — | MCP Server FOR WordpressAI | 9/26/2026 | 9/28/2026 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator… | |
| Analyzed | High (8.1) | 20% | ⚠ Active exploitation | Wordpress | 9/22/2026 | 9/28/2026 | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE. | |
| Deferred | High (7.6) | 0.38% | — | Devitems Hashbar Wordpress Notification BARAI | 9/22/2026 | 9/22/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.3. | |
| Deferred | Low (3.7) | 0.24% | — | Tiktok Wordpress PluginAI | 9/20/2026 | 9/22/2026 | The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied in the URL, so any visitor can make the site redeem a code of their choosing against the advertising platform, using the site's own credentials. It matches that code loosely, so URLs that… | |
| Deferred | Low (3.1) | 0.21% | — | Photo Gallery Sliders Proofing AND WordpressAI | 9/20/2026 | 9/21/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an administrator to change settings that apply across the whole site. | |
| Deferred | Medium (4.2) | 0.19% | — | Photo Gallery Sliders Proofing AND WordpressAI | 9/20/2026 | 9/21/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to delete, copy and re-tag any image on the site, including images in galleries belonging… | |
| Deferred | Low (3.1) | 0.21% | — | Photo Gallery Sliders Proofing AND WordpressAI | 9/20/2026 | 9/21/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored settings of any gallery on the site, including its filesystem path, and including… | |
| Deferred | High (7.2) | 0.50% | — | Photo Gallery Sliders Proofing WordpressAI | 9/20/2026 | 9/21/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator… | |
| Deferred | High (7.1) | 0.38% | — | WordpressAI | 9/18/2026 | 9/19/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through… | |
| Deferred | High (7.1) | 0.16% | — | Dictionary Wordpress Plugin DictionaryAI | 9/17/2026 | 9/18/2026 | The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request. | |
| Deferred | Medium (5.3) | 0.27% | — | LoginwordpressAIWwbn AvideoAI | 9/16/2026 | 9/22/2026 | In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemption and unconditionally logs out… | |
| Deferred | High (7.1) | 0.34% | — | Multivendorx Wordpress PluginAI | 9/16/2026 | 9/17/2026 | The MultiVendorX WordPress plugin before 5.0.16 does not verify that a user owns the store they are acting on in one of its REST API routes, allowing any authenticated user, such as a subscriber, to overwrite any store's details and payout settings and to replace the record of who owns it. | |
| Deferred | High (8.7) | 0.54% | — | Wordpress Design Scuole ItaliaAI | 9/15/2026 | 9/18/2026 | A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible by the web server process. | |
| Deferred | High (7.2) | 0.46% | — | Multivendorx Wordpress PluginAI | 9/11/2026 | 9/11/2026 | The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site. | |
| Deferred | Low (3.5) | 0.14% | — | Translate Wordpress With GtranslateAI | 9/11/2026 | 9/11/2026 | The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site. | |
| Deferred | Medium (6.8) | 0.43% | — | Wp-feedstats Wordpress PluginAI | 9/5/2026 | 9/8/2026 | The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who… | |
| Deferred | Medium (6.5) | 0.33% | — | Mountdev AI MCP Connector FOR WordpressAI | 9/3/2026 | 9/4/2026 | Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MountDev AI MCP Connector for WordPress: from n/a through 1.6.5. | |
| Deferred | High (8.2) | 0.20% | — | Wp-feedstats Wordpress PluginAI | 9/2/2026 | 9/3/2026 | The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc | |
| Deferred | High (7.1) | 0.25% | — | Wordpress Social Login AND RegisterAI | 8/31/2026 | 9/1/2026 | Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions. | |
| Deferred | Medium (6.4) | 0.35% | — | Gutenverse Ultimate Wordpress FSE Blocks Addons EcosystemAI | 8/26/2026 | 8/26/2026 | The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… |