| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. |
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. |
| Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. |
| Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions. |
| Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions. |
| Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. |
| Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. |
| Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions. |
| Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions. |
| Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions. |
| Subscriber SQL Injection in Reviewer <= 3.14.2 versions. |
| Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. |
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-13610. |
| Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. |
| Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. |
| Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions. |
| Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows PHP Local File Inclusion.
This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.12.1.1. |
| The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
| The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the Lazy Load Images feature of W3 Total Cache is enabled, as the unsafe re-emission occurs exclusively within the LazyLoad mutator's img tag rewriting step. |