tag
Wordpress-Plugin
Critical
WordPress Simple Link Directory Unauthenticated Password Reset to Admin Takeover (CVE-2025-49901)
CVE-2025-49901·
WordPress "Simple Link Directory" plugin (qc-simple-link-directory by quantumcloud)
patched
Critical
StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441)
CVE-2025-7441·
StoryChief WordPress plugin
unpatched
Critical
Simple Business Directory Pro Unauthenticated Password Reset to Admin Takeover (CVE-2025-53580)
CVE-2025-53580·
quantumcloud "Simple Business Directory Pro" WordPress plugin (simple-business-directory-pro)
patched
Critical
RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)
CVE-2025-9209·
RestroPress – Online Food Ordering System (WordPress plugin)
unpatched
Critical
GiveWP Unauthenticated PHP Object Injection via Weak Serialized-Data Regex Check (CVE-2025-22777)
CVE-2025-22777·
GiveWP – Donation Plugin and Fundraising Platform (WordPress plugin, 100,000+ active installs)
patched
Critical
Frontend Admin by DynamiApps — Unauthenticated Administrator Account Creation (CVE-2025-13342)
CVE-2025-13342·
Frontend Admin by DynamiApps (WordPress plugin built on Advanced Custom Fields / ACF frontend forms)
patched
High
WP Time Slots Booking Form Unauthenticated Stored XSS (CVE-2026-40791)
CVE-2026-40791·
WP Time Slots Booking Form (wp-time-slots-booking-form WordPress plugin)
patched
Medium
WordPress Download Manager 3.3.5.2 — Unauthenticated IDOR (CVE-2026-39676)
CVE-2026-39676·
Download Manager plugin for WordPress
unpatched
Critical
WordPress Breeze Cache Plugin — Unauthenticated Arbitrary File Upload (CVE-2026-3844)
CVE-2026-3844·
Breeze Cache plugin for WordPress
unpatched
Critical
User Registration Advanced Fields WordPress Plugin Unauthenticated Arbitrary File Upload (CVE-2026-4882)
CVE-2026-4882·
User Registration Advanced Fields plugin for WordPress
unpatched
Critical
Piotnet Addons for Elementor Pro Unauthenticated Arbitrary File Upload RCE (CVE-2026-4885)
CVE-2026-4885·
Piotnet Addons for Elementor Pro (WordPress plugin)
unpatched
High
Eventin (wp-event-solution) Broken Access Control / IDOR (CVE-2026-40776)
CVE-2026-40776 / Patchstack PSID 85de025d71e7·
Eventin — Events Calendar, Event Booking, Ticket & Registration (wp-event-solution WordPress plugin)
patched