{"resultsPerPage":32,"startIndex":0,"totalResults":32,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T15:41:00.154","vulnerabilities":[{"cve":{"id":"CVE-2025-14073","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:16:57.240","lastModified":"2026-08-01T09:16:57.240","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_order_received()` function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to obtain sensitive order information including order keys, which can then be leveraged to access full customer billing details (name, email, phone, address) via the WooCommerce Store API within a 10-minute grace period after order creation."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"woocommerce","product":"WooCommerce PayPal Payments","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/woocommerce-paypal-payments/tags/3.3.0/modules/ppcp-axo/src/AxoModule.php#L362","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3458079/woocommerce-paypal-payments/trunk/modules/ppcp-axo/src/AxoModule.php","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=%2Fwoocommerce-paypal-payments/tags/3.3.2&new_path=%2Fwoocommerce-paypal-payments/tags/3.4.0","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a2919bbc-c4c2-4b52-90ec-2471218cd7d1?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-10782","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:16:58.300","lastModified":"2026-08-01T09:16:58.300","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to grant themselves any premium membership tier without completing a PayPal transaction, generating a falsified active payment receipt and gaining unauthorized access to restricted property listing allowances."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"inspirythemes","product":"RealHomes Memberships","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.0.9","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/inspiry-memberships/tags/3.0.7/resources/payment-handler/class-paypal-payment-handler.php#L351","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/inspiry-memberships/tags/3.0.7/resources/payment-handler/class-paypal-payment-handler.php#L364","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/inspiry-memberships/tags/3.0.7/resources/payment-handler/payment-handler-init.php#L82","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/inspiry-memberships/tags/3.0.9/resources/payment-handler/class-paypal-payment-handler.php#L351","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/inspiry-memberships/tags/3.0.9/resources/payment-handler/class-paypal-payment-handler.php#L364","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/inspiry-memberships/tags/3.0.9/resources/payment-handler/payment-handler-init.php#L82","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3617226%40inspiry-memberships&new=3617226%40inspiry-memberships","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/16187b39-9b3a-4b1c-806c-37b62483a719?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-11995","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:16:58.447","lastModified":"2026-08-01T09:16:58.447","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.9.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the read/unread status of or permanently trash arbitrary form submission entries belonging to any form. The nonce issued by check_ajax_referer() does not function as an authorization barrier because the nonce action 'gutena_Forms' is emitted to unauthenticated visitors via wp_localize_script() on any public page that contains a Gutena Forms block, making it freely obtainable by anonymous attackers."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"saadiqbal","product":"Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.9.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/gutena-forms/tags/1.7.1/gutena-forms.php#L463","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gutena-forms/tags/1.7.1/includes/admin/class-manage-store.php#L38","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gutena-forms/tags/1.7.1/includes/admin/class-manage-store.php#L53","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gutena-forms/tags/1.7.1/includes/admin/class-manage-store.php#L62","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gutena-forms/tags/1.7.1/includes/admin/class-store.php#L130","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gutena-forms/tags/1.9.0/gutena-forms.php#L463","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gutena-forms/tags/1.9.0/includes/admin/class-manage-store.php#L38","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gutena-forms/tags/1.9.0/includes/admin/class-manage-store.php#L53","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gutena-forms/tags/1.9.0/includes/admin/class-manage-store.php#L62","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gutena-forms/tags/1.9.0/includes/admin/class-store.php#L130","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3624033%40gutena-forms&new=3624033%40gutena-forms","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/81557da6-c98a-4e71-ab88-e987a3650158?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-13458","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:16:58.610","lastModified":"2026-08-01T09:16:58.610","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Dynamic Tag Injection in HTML Attributes in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A Contributor-level attacker can store the malicious payload by placing a dynamic tag such as {{post_meta key:...}} in a non-URL HTML attribute (e.g., title, aria-label, alt, or data-* attributes) of a GenerateBlocks element block, then setting the corresponding unprotected post meta key via the Custom Fields metabox to a value containing a closing quote and an injected event-handler attribute."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"edge22","product":"GenerateBlocks","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.3.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.2.1/includes/dynamic-tags/class-dynamic-tag-callbacks.php#L388","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.2.1/includes/dynamic-tags/class-register-dynamic-tag.php#L196","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.2.1/includes/functions.php#L2145","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.2.1/includes/general.php#L689","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.3.0/includes/dynamic-tags/class-dynamic-tag-callbacks.php#L388","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.3.0/includes/dynamic-tags/class-register-dynamic-tag.php#L196","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.3.0/includes/functions.php#L2145","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/generateblocks/tags/2.3.0/includes/general.php#L689","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3625942%40generateblocks&new=3625942%40generateblocks","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/402e10b4-84f0-4f93-a85c-037876d26e58?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-15018","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:16:58.750","lastModified":"2026-08-01T09:16:58.750","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algorithm' parameter in all versions up to, and including, 1.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a trigger.txt file to be present in the plugin's directory (/wp-content/plugins/database-collation-fix/trigger.txt), a condition created by DesktopServer integration events such as site creation, copy, import, move, export, or deploy."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"davejesch","product":"Database Collation Fix","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.2.10","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/database-collation-fix/trunk/databasecollationfix.php#L131","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/database-collation-fix/trunk/databasecollationfix.php#L148","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/database-collation-fix/trunk/databasecollationfix.php#L251","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/database-collation-fix/trunk/databasecollationfix.php#L81","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3602218%40database-collation-fix&new=3602218%40database-collation-fix","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/874c1ba5-1bbd-43ac-bc5c-901638fa56ef?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-15052","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:16:58.893","lastModified":"2026-08-01T09:16:58.893","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"umarbajwa","product":"MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"4.3.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/mailchimp-subscribe-sm/tags/4.3.3/admin/classes/ajax-requests-class.php#L1224","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mailchimp-subscribe-sm/tags/4.3.3/admin/classes/ajax-requests-class.php#L2311","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mailchimp-subscribe-sm/tags/4.3.3/admin/classes/ajax-requests-class.php#L906","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mailchimp-subscribe-sm/tags/4.3.3/integrations/form-builder-database/extension.php#L127","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mailchimp-subscribe-sm/tags/4.3.3/integrations/form-builder-database/extension.php#L179","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3627272%40mailchimp-subscribe-sm&new=3627272%40mailchimp-subscribe-sm","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c3d2425e-69e5-4efe-bbc6-0ef121e74341?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-15450","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:16:59.023","lastModified":"2026-08-01T09:16:59.023","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from the database and passing it directly to unlink() with no validation (no realpath(), basename(), or allowlist check), combined with the insert_record() AJAX handler that lets the same authenticated user store an arbitrary value in the target 'location' column (wp_kses() only strips HTML tags and does not neutralize path traversal or absolute paths). This makes it possible for authenticated attackers, with admin-level access and above, to delete arbitrary files on the affected site's server, including wp-config. When the plugin's user-level option is configured to something else, this may be exploitable with lower privileges."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"webaways","product":"NEX-Forms – Ultimate Forms Plugin for WordPress","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"9.2.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.3/includes/classes/class.db.php#L269","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.3/includes/classes/class.db.php#L273","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.3/includes/classes/class.db.php#L805","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3625615%40nex-forms-express-wp-form-builder&new=3625615%40nex-forms-express-wp-form-builder","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bb5c8cb3-df67-4f2c-869a-48e34f5619ff?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-15601","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:16:59.173","lastModified":"2026-08-01T09:16:59.173","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zip Slip) in all versions up to, and including, 6.0.13 via the extract_zip_file function. This makes it possible for authenticated attackers, with custom-level access and above, to write arbitrary files on the server, which can allow for remote code execution. The install_app, update_app, and get_kirki_template_from_zip code paths accept a user-supplied app src value to construct the download URL, and no sanitization is applied to prevent a crafted ZIP from being fetched and extracted with path-traversing entry names that escape the intended destination directory."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"themeum","product":"Kirki – Freeform Page Builder, Website Builder & Customizer","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"6.0.13","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.12/app/Http/Controllers/Api/AppsController.php#L27","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.12/app/Services/AppsService.php#L113","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.12/app/Services/AppsService.php#L186","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.12/app/Supports/FileHandler.php#L90","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.12/includes/Ajax/Apps.php#L176","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.12/routes/api.php#L77","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.13/app/Http/Controllers/Api/AppsController.php#L27","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.13/app/Services/AppsService.php#L113","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.13/app/Services/AppsService.php#L186","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.13/app/Supports/FileHandler.php#L90","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.13/includes/Ajax/Apps.php#L176","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.13/routes/api.php#L77","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3617070%40kirki&new=3617070%40kirki","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4ccd1314-b9b9-4f63-820c-2817a4932ee8?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-15644","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:16:59.333","lastModified":"2026-08-01T09:16:59.333","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"codesupplyco","product":"Powerkit – Supercharge your WordPress Site","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/powerkit/tags/3.0.9/modules/basic-elements/public/class-powerkit-basic-elements-public.php#L113","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/powerkit/tags/3.0.9/modules/basic-elements/public/class-powerkit-basic-elements-public.php#L126","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/powerkit/tags/3.0.9/modules/basic-elements/templates/separators.php#L67","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/powerkit/tags/3.1.0/modules/basic-elements/public/class-powerkit-basic-elements-public.php#L113","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/powerkit/tags/3.1.0/modules/basic-elements/public/class-powerkit-basic-elements-public.php#L126","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/powerkit/tags/3.1.0/modules/basic-elements/templates/separators.php#L67","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3629599/powerkit","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ae04e9f2-0260-44bd-9439-cabf9d00fc2c?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-15645","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:16:59.470","lastModified":"2026-08-01T09:16:59.470","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'nav' Shortcode Attribute in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"codesupplyco","product":"Powerkit – Supercharge your WordPress Site","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/powerkit/tags/3.0.9/modules/basic-elements/public/class-powerkit-basic-elements-public.php#L113","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/powerkit/tags/3.0.9/modules/basic-elements/templates/tabs.php#L133","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/powerkit/tags/3.0.9/modules/basic-elements/templates/tabs.php#L135","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/powerkit/tags/3.1.0/modules/basic-elements/public/class-powerkit-basic-elements-public.php#L113","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/powerkit/tags/3.1.0/modules/basic-elements/templates/tabs.php#L133","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/powerkit/tags/3.1.0/modules/basic-elements/templates/tabs.php#L135","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3629599/powerkit","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5b33aa60-ac20-42c3-a3ab-b29ddfe2284a?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-15649","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:16:59.603","lastModified":"2026-08-01T09:16:59.603","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"codesupplyco","product":"Powerkit – Supercharge your WordPress Site","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/powerkit/tags/3.0.9/modules/basic-elements/public/class-powerkit-basic-elements-public.php#L83","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/powerkit/tags/3.0.9/modules/basic-elements/templates/progressbars.php#L109","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/powerkit/tags/3.1.0/modules/basic-elements/public/class-powerkit-basic-elements-public.php#L83","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/powerkit/tags/3.1.0/modules/basic-elements/templates/progressbars.php#L109","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3629599/powerkit","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f86c6ada-112b-4b1f-b1ac-7dd4920953c8?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-15662","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:16:59.737","lastModified":"2026-08-01T09:16:59.737","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bg_color' parameter in all versions up to, and including, 2.48 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"mihail-barinov","product":"Advanced Woo Labels – Product Labels & Badges for WooCommerce","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.48","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/advanced-woo-labels.php#L231","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/includes/admin/class-awl-admin.php#L123","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/includes/awl-functions.php#L93","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/includes/class-awl-label-view.php#L332","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/includes/class-awl-label-view.php#L434","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/includes/class-awl-label-view.php#L449","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/includes/class-awl-label-view.php#L560","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3627180%40advanced-woo-labels&new=3627180%40advanced-woo-labels","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/50eef578-9094-47ac-a451-04ebd9e6e2f8?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-15950","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:16:59.870","lastModified":"2026-08-01T09:16:59.870","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'layoutCircle.alignment' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"cozythemes","product":"Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.2.11","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/blocks/progress-bar/render.php#L117","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cozy-addons/tags/2.2.11/blocks/progress-bar/render.php#L158","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3619461%40cozy-addons&new=3619461%40cozy-addons","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cc751980-987f-49c5-a9fb-16ba219c174a?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-15951","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:00.000","lastModified":"2026-08-01T09:17:00.000","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and including, 1.0.12. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the Icegram_Mailer_Logs_Table::get_logs() function, where each element of the `fields` array received from $_REQUEST['data'] is joined verbatim into the SELECT clause via implode() with no whitelist, escaping, or prepared-statement placeholder. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"icegram","product":"Icegram Mailer – Reliable Email Deliverability, No-code SMTP Replacement & Email logs","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.0.12","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/icegram-mailer/tags/1.0.12/includes/class-icegram-mailer-router.php#L44","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/icegram-mailer/tags/1.0.12/includes/controllers/class-icegram-mailer-dashboard-controller.php#L26","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/icegram-mailer/tags/1.0.12/includes/db/class-icegram-mailer-logs-table.php#L109","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3627122%40icegram-mailer&new=3627122%40icegram-mailer","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9e4cff1c-6a01-4725-9e37-f48b5de16d9b?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-15964","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:00.137","lastModified":"2026-08-01T09:17:00.137","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopriv_ssoprocess_ajax` and therefore reachable without authentication — accepting an attacker-supplied `email` parameter with the `setnewpassword` operation and calling `reset_password()` on the resolved account without any ownership token, email confirmation link, or capability check. The sole guard is a call to `check_ajax_referer()`, which provides no authorization barrier because the `ssoajaxnonce` nonce is publicly broadcast on every front-end page via `wp_localize_script()` into the `SSOPWDREQUIREMENT` JavaScript object; since WordPress computes nonces for logged-out visitors against a shared anonymous session context, any unauthenticated visitor can scrape a valid nonce from the homepage and use it to authenticate the request. This makes it possible for unauthenticated attackers to change the password of any WordPress account, including administrator accounts, enabling complete site takeover."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"britcoder","product":"Single Sign On For TNG","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-620"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/single-sign-on-for-tng/tags/2.0.0/single-sign-on-for-tng.php#L102","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/single-sign-on-for-tng/tags/2.0.0/single-sign-on-for-tng.php#L120","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/single-sign-on-for-tng/tags/2.0.0/single-sign-on-for-tng.php#L69","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/single-sign-on-for-tng/tags/2.0.0/single-sign-on-for-tng.php#L96","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3624827%40single-sign-on-for-tng&new=3624827%40single-sign-on-for-tng","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1d8d393e-764c-491d-8afb-7d4f8d0c387a?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-16087","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:00.290","lastModified":"2026-08-01T09:17:00.290","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL Injection via 'messages[][id]' Parameter in all versions up to, and including, 3.1.42 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The injection is second-order: the malicious id value is first persisted to post meta via the save_campaign_preview() AJAX action (gated by a nonce check and edit_post capability, requiring Editor-level access or above), and only executed as SQL when a subsequent preview request triggers get_message_data() to interpolate the stored value directly into a SQL IN() clause without $wpdb->prepare() or integer casting."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"icegram","product":"Icegram Engage – Popups, Optins, CTAs & Lead Generation","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.1.42","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/icegram/tags/3.1.42/lite/class-icegram.php#L1338","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/icegram/tags/3.1.42/lite/class-icegram.php#L1720","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/icegram/tags/3.1.42/lite/class-icegram.php#L1770","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/icegram/tags/3.1.42/lite/classes/class-icegram-campaign-admin.php#L1134","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3628434%40icegram&new=3628434%40icegram","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1543265e-dbbf-4d48-aaa9-353e2a5c3fe9?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-16090","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:00.423","lastModified":"2026-08-01T09:17:00.423","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'heading_size' Shortcode Attribute in 'gamipress_achievement' in all versions up to, and including, 7.9.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress save-time wp_kses_post does not neutralize this payload because the injected value is stored inside a shortcode attribute rather than as a raw HTML tag, and is only emitted into HTML at render time without escaping."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"rubengc","product":"GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7.9.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/gamipress/tags/7.9.9/includes/filters.php#L542","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gamipress/tags/7.9.9/includes/shortcodes/gamipress_achievement.php#L229","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3619577%40gamipress&new=3619577%40gamipress","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/77727d02-796b-4c5b-ad5d-d1c366760abc?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-16091","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:00.557","lastModified":"2026-08-01T09:17:00.557","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gamipress_rank' Shortcode in all versions up to, and including, 7.9.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"rubengc","product":"GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7.9.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/gamipress/tags/7.9.9/includes/filters.php#L1899","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gamipress/tags/7.9.9/includes/shortcodes/gamipress_rank.php#L197","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gamipress/tags/7.9.9/includes/shortcodes/gamipress_rank.php#L203","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gamipress/tags/7.9.9/includes/template-functions.php#L74","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gamipress/tags/7.9.9/templates/rank.php#L162","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3619577%40gamipress&new=3619577%40gamipress","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d9f257a9-d447-407c-83ae-3cc99254be3f?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-16144","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:00.690","lastModified":"2026-08-01T09:17:00.690","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder, allowing attacker-controlled strings to reach call_user_func() in _save_data(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires the target form to define a field with a name matching one of the reserved placeholder keys ('thisPermalink', 'entryCounter', or 'submission_link'), as check_if_placeholders_changed() only processes POST keys present in the form's field_type_map."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"wpchill","product":"Kali Forms — Contact Form & Drag-and-Drop Builder","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.4.20","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.19/Inc/Frontend/class-form-processor.php#L1033","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.19/Inc/Frontend/class-form-processor.php#L172","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.19/Inc/Frontend/class-form-processor.php#L277","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.19/Inc/Frontend/class-form-processor.php#L90","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.19/Inc/Frontend/class-form-processor.php#L976","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.20/Inc/Frontend/class-form-processor.php#L1033","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.20/Inc/Frontend/class-form-processor.php#L172","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.20/Inc/Frontend/class-form-processor.php#L277","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.20/Inc/Frontend/class-form-processor.php#L90","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.20/Inc/Frontend/class-form-processor.php#L976","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3623024%40kali-forms&new=3623024%40kali-forms","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9d692aff-8bb2-45bb-9caf-bc33d3ed5b10?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-16614","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:00.833","lastModified":"2026-08-01T09:17:00.833","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 5.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. wp_unslash() strips magic-quote protection and sanitize_text_field() does not escape SQL metacharacters, leaving single quotes and other SQL metacharacters intact before the value is interpolated into the query."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"westerndeal","product":"GSheetConnector – CF7 Google Sheets Connector","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"5.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/cf7-google-sheets-connector/tags/5.1.7/includes/pages/class-gs-cf7db-formEntryList.php#L34","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cf7-google-sheets-connector/tags/5.1.7/includes/pages/class-gs-cf7db-formEntryList.php#L64","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cf7-google-sheets-connector/tags/5.1.7/includes/pages/gs-cf7db.php#L340","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3628480%40cf7-google-sheets-connector&new=3628480%40cf7-google-sheets-connector","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/83455de5-4fb2-4782-8063-646d3daf29e5?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-16635","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:00.970","lastModified":"2026-08-01T09:17:00.970","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed->user_role_field_id]`) directly into `WP_User::set_role()` without any allowlist validation, capability comparison, or permission check to constrain which roles can be assigned. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their own WordPress account to Administrator by tampering with the role field value in a form submission. Exploitation requires that an administrator has already configured a Pronamic Pay payment feed in Gravity Forms with the **Update User Role** option enabled and mapped to a form field; once that configuration is in place, no further preconditions exist to prevent an authenticated attacker from exploiting this vulnerability."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"pronamic","product":"Pronamic Pay","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"10.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/pronamic-ideal/tags/10.1.0/packages/wp-pay-extensions/gravityforms/src/Extension.php#L144","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pronamic-ideal/tags/10.1.0/packages/wp-pay-extensions/gravityforms/src/Extension.php#L376","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pronamic-ideal/tags/10.1.0/packages/wp-pay-extensions/gravityforms/src/Extension.php#L379","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pronamic-ideal/tags/10.1.0/packages/wp-pay-extensions/gravityforms/src/Extension.php#L988","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3630401/pronamic-ideal/trunk/packages/wp-pay-extensions/gravityforms/src/Extension.php","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=%2Fpronamic-ideal/tags/10.1.0&new_path=%2Fpronamic-ideal/tags/10.2.0","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d42b8856-e5d0-4122-98a4-8c959832b271?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-16684","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:01.117","lastModified":"2026-08-01T09:17:01.117","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact Method in all versions up to, and including, 3.5.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"mervb1","product":"Easy Property Listings","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.5.24","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/easy-property-listings/tags/3.5.24/lib/includes/class-epl-author.php#L198","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/easy-property-listings/tags/3.5.24/lib/includes/class-epl-author.php#L680","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/easy-property-listings/tags/3.5.24/lib/includes/user.php#L31","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3627878%40easy-property-listings&new=3627878%40easy-property-listings","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/02103a32-4fac-401a-b995-e86dd734484b?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-16685","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:01.250","lastModified":"2026-08-01T09:17:01.250","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in all versions up to, and including, 3.3.66 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post() does not neutralize the payload because it operates on post content at save time and does not process shortcode attribute values that are emitted unescaped at render time."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"codename065","product":"Download Manager","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.3.66","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.64/src/Category/Shortcodes.php#L18","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.64/src/Package/views/category-shortcode-toolbar.php#L17","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.64/src/Package/views/category-shortcode-toolbar.php#L36","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.64/src/__/UI.php#L81","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.66/src/Category/Shortcodes.php#L18","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.66/src/Package/views/category-shortcode-toolbar.php#L17","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.66/src/Package/views/category-shortcode-toolbar.php#L36","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/download-manager/tags/3.3.66/src/__/UI.php#L81","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3628015%40download-manager&new=3628015%40download-manager","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7a32393e-f233-4ab6-addc-9dd1e04c0e0a?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-17555","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:01.397","lastModified":"2026-08-01T09:17:01.397","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in versions up to, and including, 0.9.131. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The values are received in prepare_export_post(), passed through sanitize_text_field() and stripslashes(), JSON-decoded, and the attacker-controlled JSON object keys are collected as $posts_ids without integer casting. They are stored in the export task options and later joined with commas and interpolated directly into a `WHERE ID IN (...)` clause inside a $wpdb->get_results() call in export_post_to_xml() (unquoted, numeric context), with no $wpdb->prepare() or esc_sql(). This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"wpvividplugins","product":"WPvivid — Backup, Migration & Staging","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"0.9.131","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/wpvivid-backuprestore/tags/0.9.131/includes/class-wpvivid-export-import.php#L1129","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wpvivid-backuprestore/tags/0.9.131/includes/class-wpvivid-exporter.php#L1398","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wpvivid-backuprestore/tags/0.9.131/includes/class-wpvivid-exporter.php#L1409","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3627791%40wpvivid-backuprestore&new=3627791%40wpvivid-backuprestore","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7130f325-a0c4-479d-ac85-94542bdb5a79?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-17571","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:01.540","lastModified":"2026-08-01T09:17:01.540","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'param' in all versions up to, and including, 6.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"wpmanageninja","product":"Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"6.2.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.8/app/Modules/Component/Component.php#L1452","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.8/app/Modules/Component/Component.php#L1456","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3625751/fluentform/trunk/app/Modules/Component/Component.php","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=%2Ffluentform/tags/6.2.8&new_path=%2Ffluentform/tags/6.2.9","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/547008fe-2585-4089-a710-71a83ae3d829?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-17580","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:01.680","lastModified":"2026-08-01T09:17:01.680","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.1 via the register_rest_routes. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive admin-authored editor content — including template markup, CSS code, JavaScript code, and PHP controller variables — for any Layout or Post Selection post on the site."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"wplakeorg","product":"Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver…","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/acf-views/tags/3.9.0/src/Cpt/Base/Cpt/Cpt_Interactive_Fields.php#L77","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/acf-views/tags/3.9.0/src/Cpt/Base/Cpt/Cpt_Interactive_Fields.php#L98","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/acf-views/tags/3.9.0/src/Cpt/Layouts/Cpt/Layout_Interactive_Fields.php#L74","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/acf-views/tags/3.9.0/src/Cpt/Post_Selections/Cpt/Selection_Interactive_Fields.php#L30","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/acf-views/tags/3.9.1/src/Cpt/Base/Cpt/Cpt_Interactive_Fields.php#L77","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/acf-views/tags/3.9.1/src/Cpt/Base/Cpt/Cpt_Interactive_Fields.php#L98","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/acf-views/tags/3.9.1/src/Cpt/Layouts/Cpt/Layout_Interactive_Fields.php#L74","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/acf-views/tags/3.9.1/src/Cpt/Post_Selections/Cpt/Selection_Interactive_Fields.php#L30","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3626967%40acf-views&new=3626967%40acf-views","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d352e4d1-92ab-482b-8fce-90ee3e22ba3c?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-17605","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:01.820","lastModified":"2026-08-01T09:17:01.820","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaid_payment_form_element function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"stiofansisland","product":"Payment forms, Buy now buttons, and Invoicing System | GetPaid","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.8.56","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.7,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-98"}]}],"references":[{"url":"https://github.com/AyeCode/invoicing/commit/80625ba90241840e46b0bc5400f100e6d38ee85c","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/invoicing/tags/2.8.54/includes/admin/class-getpaid-metaboxes.php#L257","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/invoicing/tags/2.8.54/includes/admin/meta-boxes/class-getpaid-meta-box-payment-form.php#L131","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/invoicing/tags/2.8.54/includes/wpinv-template-functions.php#L1432","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/invoicing/tags/2.8.54/includes/wpinv-template-functions.php#L1458","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/invoicing/tags/2.8.56/includes/admin/class-getpaid-metaboxes.php#L257","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/invoicing/tags/2.8.56/includes/admin/meta-boxes/class-getpaid-meta-box-payment-form.php#L131","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/invoicing/tags/2.8.56/includes/wpinv-template-functions.php#L1432","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/invoicing/tags/2.8.56/includes/wpinv-template-functions.php#L1458","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/baca279b-0c42-48a9-930a-8d0525066e0a?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-18059","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:01.963","lastModified":"2026-08-01T09:17:01.963","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.2.1 via the getWooPurchaseEventParams. This makes it possible for unauthenticated attackers to extract WooCommerce purchase metadata — including product names, product IDs, quantities, per-item prices, order totals, currency, and order/transaction IDs — for any existing order by supplying an invalid or arbitrary order key. This is exploitable against any known or enumerated order ID, as the plugin resolves the order from the URL path variable alone and emits the full woo_purchase tracking payload into the page HTML via the pysOptions JavaScript object across its Facebook, Google Analytics, and Google Tag Manager integrations regardless of key validity."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"pixelyoursite","product":"PixelYourSite – Your smart PIXEL (TAG) & API Manager","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"11.2.1","versionType":"semver","status":"affected"}]},{"vendor":"pixelyoursite","product":"PixelYourSite Pro – Your smart PIXEL (TAG) Manager","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"12.6.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/pixelyoursite/tags/11.2.0.5/includes/class-pys.php#L1112","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pixelyoursite/tags/11.2.0.5/includes/functions-woo.php#L244","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pixelyoursite/tags/11.2.0.5/modules/facebook/facebook.php#L696","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pixelyoursite/tags/11.2.0.5/modules/google_analytics/ga.php#L843","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pixelyoursite/tags/11.2.0.5/modules/google_gtm/gtm.php#L1083","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pixelyoursite/tags/11.2.1/includes/class-pys.php#L1112","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pixelyoursite/tags/11.2.1/includes/functions-woo.php#L244","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pixelyoursite/tags/11.2.1/modules/facebook/facebook.php#L696","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pixelyoursite/tags/11.2.1/modules/google_analytics/ga.php#L843","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pixelyoursite/tags/11.2.1/modules/google_gtm/gtm.php#L1083","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3629756%40pixelyoursite&new=3629756%40pixelyoursite","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca14ec54-0864-47f7-9653-1fe04e2875de?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-18062","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:02.100","lastModified":"2026-08-01T09:17:02.100","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Identity Block Inner Image Content in all versions up to, and including, 3.7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only triggerable when the block's urlTransparent attribute is set to a non-empty value, as this is a required precondition for the vulnerable code path in build_html() to be reached."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"stellarwp","product":"Kadence Blocks — Page Builder Toolkit for Gutenberg Editor","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.7.8.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.2/includes/blocks/class-kadence-blocks-identity-block.php#L108","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.2/includes/blocks/class-kadence-blocks-identity-block.php#L117","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.2/includes/blocks/class-kadence-blocks-identity-block.php#L162","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.8/includes/blocks/class-kadence-blocks-identity-block.php#L108","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.8/includes/blocks/class-kadence-blocks-identity-block.php#L117","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.8/includes/blocks/class-kadence-blocks-identity-block.php#L162","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3627652%40kadence-blocks&new=3627652%40kadence-blocks","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/620bd934-327e-4509-a5e0-b910654af29b?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-18344","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:02.237","lastModified":"2026-08-01T09:17:02.237","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and excluding, 1.1.53. This is due to insufficient input sanitization and output escaping in the responsive_thumbnail_image_management() function, which echoes $_GET['id'] directly into a double-quoted HTML attribute with no esc_attr() call. The only guard is a loose PHP numeric comparison ($_GET['id']>0) that a string beginning with a numeric prefix trivially satisfies, and the addslashes() applied by wp_magic_quotes() is inert in HTML-attribute context because backslash is not an HTML escape character. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"nik00726","product":"Responsive Thumbnail Slider","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.1.53","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/wp-responsive-thumbnail-slider/trunk/wp-responsive-images-thumbnail-slider.php#L1274","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-responsive-thumbnail-slider/trunk/wp-responsive-images-thumbnail-slider.php#L1275","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c7370cbc-f681-49d7-9330-762443202529?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-18435","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:02.383","lastModified":"2026-08-01T09:17:02.383","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'toggleIcon' Block Attribute in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"stellarwp","product":"Kadence Blocks — Page Builder Toolkit for Gutenberg Editor","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.7.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.8/includes/blocks/class-kadence-blocks-table-of-contents-block.php#L293","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.7.8/includes/class-kadence-blocks-table-of-contents.php#L936","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3624906%40kadence-blocks&new=3624906%40kadence-blocks","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5f346cc7-92ad-4f76-a71c-864c22ed56b5?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-6453","sourceIdentifier":"security@wordfence.com","published":"2026-08-01T09:17:02.530","lastModified":"2026-08-01T09:17:02.530","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. This is due to insufficient input sanitization in the cubewp_remove_relation() AJAX function, specifically the use of wp_unslash() on the relation_id parameter before interpolating it directly into a raw SQL query without using $wpdb->prepare(). The wp_unslash() call explicitly removes the backslash escaping that WordPress's wp_magic_quotes() adds to all $_POST data, neutralizing the only layer of SQL injection protection. The sanitize_text_field() function applied afterward offers no SQL protection. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries to the existing query."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"cubewp1211","product":"CubeWP Framework","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.1.30","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/cubewp-framework/tags/1.1.29/cube/functions/admin-functions.php#L2655","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cubewp-framework/tags/1.1.29/cube/modules/custom-fields/class-cubewp-relationships.php#L251","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cubewp-framework/tags/1.1.29/cube/modules/custom-fields/class-cubewp-relationships.php#L261","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cubewp-framework/trunk/cube/functions/admin-functions.php#L2655","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cubewp-framework/trunk/cube/modules/custom-fields/class-cubewp-relationships.php#L251","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cubewp-framework/trunk/cube/modules/custom-fields/class-cubewp-relationships.php#L261","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3627740%40cubewp-framework&new=3627740%40cubewp-framework","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a4647620-e06a-49d5-8f9d-a59cb5a999b1?source=cve","source":"security@wordfence.com"}]}}]}