CVE-2026-17149myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrapper' Shortcode Attribute Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred Ngày phát hành 09/09/2026 Mức độ nghiêm trọng Trung bình CVE-2026-15009Advanced File Manager <= 5.4.12 - Reflected Cross-Site Scripting via postMessage 'soundFile' Parameter Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng A Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution Ngày phát hành 16/08/2026 Mức độ nghiêm trọng Trung bình CVE-2026-6627WPFormify <= 1.1.1 - Missing Authorization Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng W WPFormify – Stripe Payments with Form and Checkout Ngày phát hành 05/08/2026 Mức độ nghiêm trọng Cao CVE-2026-11995Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification/Trash via process_bulk_action() Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng G Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Ngày phát hành 01/08/2026 Mức độ nghiêm trọng Trung bình CVE-2026-12144Wholesale for WooCommerce <= 2.0.5 - Authenticated (Author+) Privilege Escalation via 'user_role_set' Parameter Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng W Wholesale for WooCommerce Ngày phát hành 29/07/2026 Mức độ nghiêm trọng Cao CVE-2026-12738WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Status Modification via wpep_draft_confirm AJAX Action Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng W WP Easy Pay – Payment and Donation form Builder for Square Ngày phát hành 11/07/2026 Mức độ nghiêm trọng Trung bình CVE-2026-12097User Management <= 1.2 - Missing Authorization to Unauthenticated Plugin Settings Modification Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng U User Management Ngày phát hành 08/07/2026 Mức độ nghiêm trọng Trung bình CVE-2026-8607myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrap' Shortcode Attribute Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred Ngày phát hành 17/06/2026 Mức độ nghiêm trọng Trung bình CVE-2026-7430Post Snippets <= 4.0.19 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Post Snippets – Custom WordPress Code Snippets Customizer Ngày phát hành 29/05/2026 Mức độ nghiêm trọng Trung bình CVE-2024-13362Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Ngày phát hành 01/05/2026 Mức độ nghiêm trọng Trung bình CVE-2026-3090Post SMTP <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'event_type' Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Ngày phát hành 18/03/2026 Mức độ nghiêm trọng Cao CVE-2026-2559Post SMTP <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Office 365 OAuth Configuration Overwrite Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Ngày phát hành 18/03/2026 Mức độ nghiêm trọng Trung bình CVE-2026-1674Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.6.0 - Authenticated (Contributor+) Limited Options Update in save_gutena_forms_schema() Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng G Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Ngày phát hành 04/03/2026 Mức độ nghiêm trọng Trung bình CVE-2026-0550myCred <= 2.9.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'mycred_load_coupon' Shortcode Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred Ngày phát hành 14/02/2026 Mức độ nghiêm trọng Trung bình CVE-2026-0832New User Approve <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary User Approval, Denial, and Information Disclosure Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng N New User Approve Ngày phát hành 28/01/2026 Mức độ nghiêm trọng Cao CVE-2025-12718Quick Contact Form <= 8.2.6 - Unauthenticated Open Mail Relay Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng Q Quick Contact Form Ngày phát hành 17/01/2026 Mức độ nghiêm trọng Trung bình CVE-2025-12361myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program <= 2.9.7.1 - Missing Authorization to Sensitive Information Exposure Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred Ngày phát hành 19/12/2025 Mức độ nghiêm trọng Trung bình CVE-2025-12362myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program <= 2.9.7 - Missing Authorization to Unauthenticated Withdrawal Request Approval Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred Ngày phát hành 13/12/2025 Mức độ nghiêm trọng Trung bình CVE-2025-12887Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.1 - Missing Authorization to Authenticated (Subscriber+) OAuth Token Update Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Ngày phát hành 03/12/2025 Mức độ nghiêm trọng Trung bình CVE-2025-12770New User Approve <= 3.0.9 - Unauthenticated Sensitive Information Disclosure via Type Juggling Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng N New User Approve Ngày phát hành 19/11/2025 Mức độ nghiêm trọng Trung bình CVE-2025-11833Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Ngày phát hành 01/11/2025 Mức độ nghiêm trọng Nghiêm trọng CVE-2025-11244Password Protected <= 2.7.11 - Unauthenticated Authorization Bypass via IP Address Spoofing Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content Ngày phát hành 25/10/2025 Mức độ nghiêm trọng Thấp CVE-2025-9219Post SMTP <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Option Update Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Ngày phát hành 03/09/2025 Mức độ nghiêm trọng Trung bình CVE-2025-0818Multiple elFinder Plugins <= (Various Versions) - Directory Traversal to Arbitrary File Deletion Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng A Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution Ngày phát hành 13/08/2025 Mức độ nghiêm trọng Trung bình CVE-2025-3453Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products <= 2.7.7 - Unauthenticated Sensitive Information Exposure Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content Ngày phát hành 17/04/2025 Mức độ nghiêm trọng Trung bình CVE-2024-13844Post SMTP <= 3.1.2 - Authenticated (Administrator+) SQL Injection via columns Parameter Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Ngày phát hành 08/03/2025 Mức độ nghiêm trọng Trung bình CVE-2024-13805Advanced File Manager <= 5.2.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng A Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution Ngày phát hành 07/03/2025 Mức độ nghiêm trọng Trung bình CVE-2024-13713WPExperts Square For GiveWP <= 1.3.1 - Authenticated (Subscriber+) SQL Injection Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng W WPExperts Square For GiveWP Ngày phát hành 21/02/2025 Mức độ nghiêm trọng Trung bình CVE-2025-0521Post SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Ngày phát hành 18/02/2025 Mức độ nghiêm trọng Cao CVE-2024-13333Advanced File Manager 5.2.12 - 5.2.13 - Authenticated (Subscriber+) Arbitrary File Upload Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng A Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin Ngày phát hành 17/01/2025 Mức độ nghiêm trọng Cao CVE-2024-11201myCred – Loyalty Points and Rewards plugin <= 2.7.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via mycred_send Shortcode Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred Ngày phát hành 06/12/2024 Mức độ nghiêm trọng Trung bình CVE-2024-11391Advanced File Manager <= 5.2.10 - Authenticated (Subscriber+) Arbitrary File Upload Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng A Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution Ngày phát hành 03/12/2024 Mức độ nghiêm trọng Cao CVE-2024-10187myCred <= 2.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via mycred_link Shortcode Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred Ngày phát hành 08/11/2024 Mức độ nghiêm trọng Trung bình CVE-2022-4974Freemius SDK <= 2.4.2 - Missing Authorization Checks Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng W WC Shop Sync – Square Payment Gateway and Product Synchronization for WooCommerce Ngày phát hành 16/10/2024 Mức độ nghiêm trọng Trung bình CVE-2024-8725Advanced File Manager <= 5.2.8 - Authenticated (Subscriber+) Limited File Upload Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng A Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution Ngày phát hành 26/09/2024 Mức độ nghiêm trọng Trung bình CVE-2024-8126Advanced File Manager <= 5.2.8 - Authenticated (Subscriber+) Arbitrary File Upload Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng A Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution Ngày phát hành 26/09/2024 Mức độ nghiêm trọng Cao CVE-2024-8704Advanced File Manager <= 5.2.8 - Authenticated (Administrator+) Local JavaScript File Inclusion via fma_locale Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng A Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution Ngày phát hành 26/09/2024 Mức độ nghiêm trọng Cao CVE-2024-8658myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification <= 2.7.3 - Missing Authorization to Unauthenticated Database Upgrade Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred Ngày phát hành 25/09/2024 Mức độ nghiêm trọng Trung bình CVE-2024-5861WP Easy Pay (Free) <= 4.2.3 - Missing Authorization to Unauthenticated Service Disconnection Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng W WP Easy Pay – Payment and Donation form Builder for Square Ngày phát hành 24/07/2024 Mức độ nghiêm trọng Trung bình CVE-2024-5598Advanced File Manager <= 5.2.4 - Sensitive Information Exposure via Directory Listing Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng A Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution Ngày phát hành 29/06/2024 Mức độ nghiêm trọng Cao CVE-2024-1639License Manager for WooCommerce <= 3.0.6 - Improper Authorization to Authenticated(Contributor+) Sensitive Information Exposure Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng L License Manager for WooCommerce Ngày phát hành 21/06/2024 Mức độ nghiêm trọng Trung bình CVE-2024-5207POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL Injection Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Ngày phát hành 30/05/2024 Mức độ nghiêm trọng Cao CVE-2024-0437Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease <= 2.6.6 - Missing Authorization to Sensitive Information Exposure Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content Ngày phát hành 14/05/2024 Mức độ nghiêm trọng Trung bình CVE-2024-0656Password Protected <= 2.6.6 - Authenticated (Admin+) Stored Cross-Site Scripting Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content Ngày phát hành 20/02/2024 Mức độ nghiêm trọng Trung bình CVE-2023-6875POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Ngày phát hành 11/01/2024 Mức độ nghiêm trọng Nghiêm trọng CVE-2023-7027POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Unauthenticated Stored Cross-Site Scripting via device Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Ngày phát hành 03/01/2024 Mức độ nghiêm trọng Cao CVE-2023-6629POST SMTP Mailer <= 2.8.6 - Reflected Cross-Site Scripting via msg Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Ngày phát hành 03/01/2024 Mức độ nghiêm trọng Trung bình CVE-2021-4422POST SMTP Mailer <= 2.0.20 - Cross-Site Request Forgery Bypass Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Ngày phát hành 12/07/2023 Mức độ nghiêm trọng Trung bình CVE-2023-3082Post SMTP <= 2.5.7 - Unauthenticated Stored Cross-Site Scripting via Email Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng P Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Ngày phát hành 12/07/2023 Mức độ nghiêm trọng Cao CVE-2021-4411WP EasyPay – Square for WordPress <= 3.2.0 - Cross-Site Request Forgery Bypass Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng W WP Easy Pay – Payment and Donation form Builder for Square Ngày phát hành 12/07/2023 Mức độ nghiêm trọng Trung bình CVE-2019-25150Email Templates <= 1.3 - HTML Injection Tình trạng khai thác Chưa ghi nhận bị khai thác Bản vá CóSản phẩm bị ảnh hưởng E Email Templates Customizer and Designer for WordPress and WooCommerce Ngày phát hành 07/06/2023 Mức độ nghiêm trọng Cao