| 2026-10-01 |
WPSEC-2026-0041 |
Team – Team Members Showcase Plugin | Team – Team Members Showcase Plugin <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tlpteam' Shortcode |
Medium 6.4 |
6.0.3 |
| 2026-10-01 |
WPSEC-2026-0040 |
OMGF | OMGF <= 6.3.11 - Authenticated (Contributor+) Path Traversal via Font Family Name |
Low 3.1 |
6.3.12 |
| 2026-10-01 |
WPSEC-2026-0039 |
OMGF | OMGF <= 6.3.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Font Download Error Notices |
Medium 4.4 |
6.3.12 |
| 2026-10-01 |
WPSEC-2026-0038 |
OMGF | OMGF <= 6.3.11 - Authenticated (Contributor+) Server-Side Request Forgery via Font Stylesheet Link Processing |
Medium 4.9 |
6.3.12 |
| 2026-10-01 |
WPSEC-2026-0037 |
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution | Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.1.3 - Authenticated (Vendor+) Insecure Direct Object Reference to Commission Rate Disclosure via Commission Calculator REST Endpoint |
Medium 4.3 |
5.2.0 |
| 2026-10-01 |
WPSEC-2026-0036 |
Wp Social | Wp Social <= 3.2.1 - Cross-Site Request Forgery to Social Login Provider Settings Update |
Medium 4.3 |
3.2.2 |
| 2026-10-01 |
WPSEC-2026-0035 |
Wp Social | Wp Social <= 3.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Avatar Alt Attribute |
Medium 6.4 |
3.2.2 |
| 2026-10-01 |
WPSEC-2026-0034 |
Data Tables Generator by Supsystic | Data Tables Generator by Supsystic <= 1.15.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Table Cell Content and Custom CSS |
Medium 4.4 |
1.15.3 |
| 2026-10-01 |
WPSEC-2026-0033 |
Otter Blocks | Otter Blocks <= 3.2.6 - Authenticated (Subscriber+) Missing Authorization to Form Submission Email Disclosure via Dashboard Widget |
Medium 4.3 |
3.2.7 |
| 2026-10-01 |
WPSEC-2026-0032 |
Prime Slider – Addons For Elementor | Prime Slider – Addons For Elementor <= 4.6.1 - Authenticated (Contributor+) Sensitive Information Exposure via Query Control Dynamic Select Search |
Medium 4.3 |
4.6.2 |
| 2026-10-01 |
WPSEC-2026-0031 |
Prime Slider – Addons For Elementor | Prime Slider – Addons For Elementor <= 4.6.1 - Authenticated (Contributor+) Sensitive Information Exposure via Blog Widget Zinest Skin Featured Posts |
Medium 4.3 |
4.6.2 |
| 2026-10-01 |
WPSEC-2026-0030 |
Unlimited Elements For Elementor | Unlimited Elements For Elementor < 2.0.21 - Unauthenticated SQL Injection via AJAX Search 'ucs' Parameter |
Medium 5.9 |
2.0.21 |
| 2026-10-01 |
WPSEC-2026-0029 |
Unlimited Elements For Elementor | Unlimited Elements For Elementor < 2.0.21 - Authenticated (Contributor+) Information Exposure via Elementor Template and Layout Rendering |
Medium 4.3 |
2.0.21 |
| 2026-10-01 |
WPSEC-2026-0028 |
Unlimited Elements For Elementor | Unlimited Elements For Elementor < 2.0.21 - Authenticated (Contributor+) SQL Injection via Terms 'Direct Children of Selected Terms' Setting |
Medium 6.5 |
2.0.21 |
| 2026-10-01 |
WPSEC-2026-0027 |
Event Tickets and Registration | Event Tickets and Registration <= 5.29.5.1 - Unauthenticated Business Logic Error to Seat Overbooking via Duplicate Reservation IDs |
Medium 5.3 |
5.29.5.2 |
| 2026-10-01 |
WPSEC-2026-0026 |
Event Tickets and Registration | Event Tickets and Registration <= 5.29.5.2 - Authenticated (Contributor+) Missing Authorization to Ticket Creation and Modification via REST API |
Medium 4.3 |
5.30.0 |
| 2026-10-01 |
WPSEC-2026-0025 |
bbPress | bbPress <= 2.6.18 - Unauthenticated Sensitive Information Exposure via oEmbed Endpoint and Canonical Redirect |
Medium 5.3 |
2.6.19 |
| 2026-10-01 |
WPSEC-2026-0024 |
bbPress | bbPress <= 2.6.18 - Authenticated (Contributor+) Sensitive Information Exposure via Single Topic and Single Reply Shortcodes |
Medium 4.3 |
2.6.19 |
| 2026-10-01 |
WPSEC-2026-0023 |
bbPress | bbPress <= 2.6.18 - Unauthenticated Sensitive Information Exposure via Password-Protected Forum and Topic Bypass |
Medium 5.3 |
2.6.19 |
| 2026-10-01 |
WPSEC-2026-0022 |
hCaptcha for WP | hCaptcha for WP <= 5.3.0 - Unauthenticated hCaptcha Bypass via Passster REST Unlock Endpoint |
Low 3.7 |
5.4.0 |
| 2026-10-01 |
WPSEC-2026-0021 |
hCaptcha for WP | hCaptcha for WP <= 5.3.0 - Unauthenticated hCaptcha Bypass via Expired or Evicted Auto-Verification Registration |
Low 3.7 |
5.4.0 |
| 2026-10-01 |
WPSEC-2026-0020 |
hCaptcha for WP | hCaptcha for WP <= 5.3.0 - Unauthenticated Denial of Service via Unbounded Failed Login Data |
Medium 5.3 |
5.4.0 |
| 2026-10-01 |
WPSEC-2026-0019 |
hCaptcha for WP | hCaptcha for WP <= 5.3.0 - Unauthenticated hCaptcha Bypass via LearnPress Checkout Account Creation |
Low 3.7 |
5.4.0 |
| 2026-10-01 |
WPSEC-2026-0018 |
WP Statistics – Simple, privacy-friendly Google Analytics alternative | WP Statistics – Simple, privacy-friendly Google Analytics alternative <= 14.16.14 - Reflected Cross-Site Scripting via Report Filter Dropdown URLs |
Medium 6.1 |
14.16.15 |
| 2026-10-01 |
WPSEC-2026-0017 |
Kadence Blocks | Kadence Blocks <= 3.7.11.1 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload in Advanced Form |
Medium 6.1 |
3.7.12 |
| 2026-10-01 |
WPSEC-2026-0016 |
MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor | MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor <= 4.3.0 - Unauthenticated reCAPTCHA v3 Bypass |
Medium 5.3 |
4.3.1 |
| 2026-10-01 |
WPSEC-2026-0015 |
MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor | MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor <= 4.3.0 - Unauthenticated Sensitive Information Exposure via REST API |
Medium 5.3 |
4.3.1 |
| 2026-10-01 |
WPSEC-2026-0014 |
MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor | MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor <= 4.3.0 - Unauthenticated HTML Injection via Form Submission Notification Emails |
Medium 5.3 |
4.3.1 |
| 2026-10-01 |
WPSEC-2026-0013 |
MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor | MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor <= 4.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Settings |
Medium 6.4 |
4.3.1 |
| 2026-10-01 |
WPSEC-2026-0012 |
MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor | MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor <= 4.3.0 - Authenticated (Contributor+) Information Exposure via 'metform' Shortcode |
Medium 4.3 |
4.3.1 |
| 2026-10-01 |
WPSEC-2026-0011 |
Smash Balloon Social Post Feed | Smash Balloon Social Post Feed <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via Facebook Post Content in Feed Builder Preview |
High 7.2 |
4.14.0 |
| 2026-10-01 |
WPSEC-2026-0010 |
Ultimate Member | Ultimate Member <= 2.13.1 - Unauthenticated Sensitive Information Exposure via Private Profile Fields |
Medium 5.3 |
2.14.0 |
| 2026-10-01 |
WPSEC-2026-0009 |
Ultimate Member | Ultimate Member <= 2.13.1 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover |
High 7.5 |
2.14.0 |
| 2026-10-01 |
WPSEC-2026-0008 |
Ultimate Member | Ultimate Member <= 2.13.1 - Authenticated (Administrator+) SQL Injection via Directory Search-Field Identifiers |
Medium 4.9 |
2.14.0 |
| 2026-10-01 |
WPSEC-2026-0007 |
Fluent Forms | Fluent Forms <= 6.2.14 - Unauthenticated Payment Bypass via Zero or Invalid Payment Values |
Medium 5.3 |
6.2.15 |
| 2026-10-01 |
WPSEC-2026-0006 |
Fluent Forms | Fluent Forms <= 6.2.14 - Unauthenticated Reflected Cross-Site Scripting via 'get' Smartcode |
Medium 6.1 |
6.2.15 |
| 2026-10-01 |
WPSEC-2026-0005 |
Fluent Forms | Fluent Forms <= 6.2.14 - Authenticated (Fluent Forms Manager+) Stored Cross-Site Scripting via Payment Item 'price_label' and Payment Summary 'cart_empty_text' Settings |
Medium 4.8 |
6.2.15 |
| 2026-10-01 |
WPSEC-2026-0004 |
Fluent Forms | Fluent Forms <= 6.2.14 - Authenticated (Fluent Forms Manager+) Sensitive Information Exposure via User Search |
Low 2.7 |
6.2.15 |
| 2026-10-01 |
WPSEC-2026-0003 |
TranslatePress | TranslatePress <= 3.3.6 - Unauthenticated Stored Cross-Site Scripting via trp-gettext Markers in URL Attributes |
High 7.2 |
3.3.7 |
| 2026-10-01 |
WPSEC-2026-0002 |
Wordfence Security – Firewall & Malware Scan | Wordfence Security – Firewall & Malware Scan <= 9.0.1 - Unauthenticated Author Information Disclosure via REST API Username Enumeration Protection Bypass |
Medium 5.3 |
9.0.2 |
| 2026-10-01 |
WPSEC-2026-0001 |
Essential Addons for Elementor – Popular Elementor Templates & Widgets | Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Woo Product Grid Pagination |
Medium 6.4 |
6.8.5 |