CVE-2026-85198MPG <= 4.2.1 - Unauthenticated SQL Injection via URL Path Exploitation status Not confirmed Fix YesAffected product M MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO Published 09/12/2026 Severity Medium CVE-2026-4945Otter Blocks <= 3.1.7 - Missing Authorization to Unauthenticated Purchase Verification Bypass Exploitation status Not known exploited Fix YesAffected product O Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Published 09/07/2026 Severity Medium CVE-2026-61960WordPress WP Full Stripe Free plugin <= 8.5.0 - Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product W WP Full Stripe Free Published 08/13/2026 Severity High CVE-2026-66437WordPress Feedzy plugin <= 5.2.4 - Server Side Request Forgery (SSRF) vulnerability Exploitation status Not known exploited Fix YesAffected product F Feedzy Published 07/27/2026 Severity Medium CVE-2026-65563WordPress Orbit Fox by ThemeIsle plugin <= 3.0.7 - Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product O Orbit Fox by ThemeIsle Published 07/27/2026 Severity Medium CVE-2026-15653Visualizer <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'backend-title' Parameter Exploitation status Not known exploited Fix YesAffected product V Visualizer – Tables & Charts Manager with Built-in AI Generator Published 07/24/2026 Severity Medium CVE-2026-65537WordPress Cyr to Lat reloaded – transliteration of links and file names plugin <= 1.3.3 - Broken Access Control vulnerability Exploitation status Not known exploited Fix YesAffected product C Cyr to Lat reloaded – transliteration of links and file names Published 07/23/2026 Severity Medium CVE-2026-65526WordPress Visualizer plugin <= 4.0.1 - SQL Injection vulnerability Exploitation status Not known exploited Fix YesAffected product V Visualizer Published 07/23/2026 Severity High CVE-2026-61970WordPress Auto Featured Image (Auto Post Thumbnail) plugin <= 5.0.4 - Server Side Request Forgery (SSRF) vulnerability Exploitation status Not known exploited Fix YesAffected product A Auto Featured Image (Auto Post Thumbnail) Published 07/13/2026 Severity Medium CVE-2026-13252RSS Aggregator by Feedzy <= 5.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aspectRatio' Attribute Exploitation status Not known exploited Fix YesAffected product R RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Published 07/02/2026 Severity Medium CVE-2026-13468Visualizer <= 4.0.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via /visualizer/v1/action/{chart}/{type}/ REST Endpoint Exploitation status Not known exploited Fix YesAffected product V Visualizer – Tables & Charts Manager with Built-in AI Generator Published 07/01/2026 Severity High CVE-2026-12432Stripe Payment Forms by WP Full Pay <= 8.4.3 - Missing Authorization to Unauthenticated Payment Record Manipulation via 'paymentIntentId' Parameter Exploitation status Not known exploited Fix YesAffected product S Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions Published 06/27/2026 Severity Medium CVE-2026-57618WordPress Neve PRO theme <= 3.1.2 - Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product N Neve PRO Published 06/26/2026 Severity Medium CVE-2026-56050WordPress PPOM for WooCommerce plugin <= 33.0.18 - Broken Access Control vulnerability Exploitation status Not known exploited Fix YesAffected product P PPOM for WooCommerce Published 06/25/2026 Severity Medium CVE-2026-11358Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More <= 3.0.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu-item-icon' Parameter Exploitation status Not known exploited Fix YesAffected product O Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Published 06/18/2026 Severity Medium CVE-2026-42378WordPress WP Full Stripe Free plugin <= 8.4.1 - Broken Authentication vulnerability Exploitation status Not known exploited Fix YesAffected product W WP Full Stripe Free Published 06/15/2026 Severity Medium CVE-2026-39507WordPress Social Slider Feed plugin <= 2.3.2 - Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product S Social Slider Feed Published 06/15/2026 Severity High CVE-2026-23970WordPress Redirection for Contact Form 7 plugin <= 3.2.8 - Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product R Redirection for Contact Form 7 Published 06/15/2026 Severity High CVE-2017-20251WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API Exploitation status Public exploit Fix YesAffected product W Woody Code Snippets Published 06/09/2026 Severity Critical CVE-2026-8976RSS Aggregator by Feedzy <= 5.1.7 - Missing Authorization to Authenticated (Contributor+) Import Job Creation, Execution, Purge, Log Clearing, and Information Disclosure via Multiple AJAX Sub-Actions Exploitation status Not known exploited Fix YesAffected product R RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Published 06/05/2026 Severity Medium CVE-2025-53209WordPress Masteriyo LMS PRO plugin <= 2.20.0 - Privilege Escalation Vulnerability Exploitation status Not known exploited Fix YesAffected product M Masteriyo LMS PRO Published 06/02/2026 Severity Critical CVE-2026-8689Visualizer: Tables and Charts Manager for WordPress <= 3.11.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Chart Creation and Modification via renderChartPages() and uploadData() Functions Exploitation status Not known exploited Fix YesAffected product V Visualizer: Tables and Charts Manager for WordPress Published 05/28/2026 Severity Medium CVE-2026-42749WordPress Disable Comments for Any Post Types (Remove comments) plugin <= 1.3.0 - Broken Authentication vulnerability Exploitation status Not known exploited Fix YesAffected product D Disable Comments for Any Post Types (Remove comments) Published 05/27/2026 Severity High CVE-2026-24573WordPress Visualizer plugin < 4.0.0 - Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product V Visualizer Published 05/20/2026 Severity Medium CVE-2026-2892Otter Blocks <= 3.1.4 - Improper Authorization to Unauthenticated Purchase Verification Bypass via Forged Cookie Exploitation status Not known exploited Fix YesAffected product O Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Published 04/30/2026 Severity High CVE-2026-25366WordPress Woody ad snippets plugin <= 2.7.1 - Remote Code Execution (RCE) vulnerability Exploitation status Not known exploited Fix YesAffected product W Woody ad snippets Published 03/25/2026 Severity Critical CVE-2026-2410Disable Admin Notices – Hide Dashboard Notifications <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Update Exploitation status Not known exploited Fix YesAffected product D Disable Admin Notices – Hide Dashboard Notifications Published 02/25/2026 Severity Medium CVE-2026-1319Robin Image Optimizer <= 2.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via Image Alternative Text Field Exploitation status Not known exploited Fix YesAffected product R Robin Image Optimizer – Unlimited Image Optimization & WebP Converter Published 02/05/2026 Severity Medium CVE-2026-1755Menu Icons by ThemeIsle <= 0.13.20 - Authenticated (Author+) Stored Cross-Site Scripting Exploitation status Not known exploited Fix YesAffected product M Menu Icons by ThemeIsle Published 02/03/2026 Severity Medium CVE-2025-14800Redirection for Contact Form 7 <= 3.2.7 - Unauthenticated Arbitrary File Copy via move_file_to_upload Exploitation status Not known exploited Fix YesAffected product R Redirection for Contact Form 7 Published 12/21/2025 Severity High CVE-2025-13794Auto Featured Image <= 4.2.1 - Missing Authorization to Authenticated (Contributor+) Post Thumbnail Modification Exploitation status Not known exploited Fix YesAffected product A Auto Featured Image (Auto Post Thumbnail) Published 12/16/2025 Severity Medium CVE-2025-11467RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 5.1.1 - Unauthenticated Blind Server-Side Request Forgery Exploitation status Not known exploited Fix YesAffected product R RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Published 12/11/2025 Severity Medium CVE-2025-12483Visualizer: Tables and Charts Manager for WordPress <= 3.11.12 - Authenticated (Contributor+) SQL Injection Exploitation status Not known exploited Fix YesAffected product V Visualizer: Tables and Charts Manager for WordPress Published 12/02/2025 Severity Medium CVE-2025-66069WordPress PPOM for WooCommerce plugin <= 33.0.16 - Broken Access Control vulnerability Exploitation status Not known exploited Fix YesAffected product P PPOM for WooCommerce Published 11/21/2025 Severity Medium CVE-2025-12045Orbit Fox Companion <= 3.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via Post Taxonomy Exploitation status Not known exploited Fix YesAffected product O Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Published 11/04/2025 Severity Medium CVE-2025-10145Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 10/28/2025 Severity Unknown CVE-2025-9322Stripe Payment Forms <= 8.3.1 - Unauthenticated SQL Injection Exploitation status Not known exploited Fix YesAffected product S Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions Published 10/25/2025 Severity High CVE-2025-11128Feedzy RSS Feeds Lite <= 5.1.0 - Authenticated (Subscriber+) Server-Side Request Forgery Exploitation status Not known exploited Fix YesAffected product R RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Published 10/23/2025 Severity Medium CVE-2025-11691PPOM – Product Addons & Custom Fields for WooCommerce <= 33.0.15 - Unauthenticated SQL Injection Exploitation status Not known exploited Fix YesAffected product P PPOM – Product Addons & Custom Fields for WooCommerce Published 10/18/2025 Severity High CVE-2025-11391PPOM – Product Addons & Custom Fields for WooCommerce <= 33.0.15 - Unauthenticated Arbitrary File Upload Exploitation status Not known exploited Fix YesAffected product P PPOM – Product Addons & Custom Fields for WooCommerce Published 10/18/2025 Severity Critical CVE-2025-9562Redirection for Contact Form 7 <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via qs_date Shortcode Exploitation status Not known exploited Fix YesAffected product R Redirection for Contact Form 7 Published 10/18/2025 Severity Medium CVE-2025-58789WordPress WP Full Stripe Free Plugin <= 8.2.5 - SQL Injection Vulnerability Exploitation status Not known exploited Fix YesAffected product W WP Full Stripe Free Published 09/05/2025 Severity High CVE-2025-58593WordPress Orbit Fox by ThemeIsle Plugin <= 3.0.0 - Cross Site Scripting (XSS) Vulnerability Exploitation status Not known exploited Fix YesAffected product O Orbit Fox by ThemeIsle Published 09/03/2025 Severity Medium CVE-2025-55715WordPress Otter - Gutenberg Block Plugin <= 3.1.0 - Sensitive Data Exposure Vulnerability Exploitation status Not known exploited Fix YesAffected product O Otter - Gutenberg Block Published 08/20/2025 Severity High CVE-2025-8141Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated Arbitrary File Deletion Exploitation status Not known exploited Fix YesAffected product R Redirection for Contact Form 7 Published 08/20/2025 Severity High CVE-2025-8289Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated PHP Object Injection via PHAR Deserialization Exploitation status Not known exploited Fix YesAffected product R Redirection for Contact Form 7 Published 08/20/2025 Severity High CVE-2025-8145Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated PHP Object Injection Exploitation status Not known exploited Fix YesAffected product R Redirection for Contact Form 7 Published 08/20/2025 Severity High CVE-2025-53986WordPress Hestia theme <= 3.2.10 - Broken Access Control Vulnerability Exploitation status Not known exploited Fix YesAffected product H Hestia Published 07/16/2025 Severity Medium CVE-2025-53254WordPress Cyrlitera plugin <= 1.3.0 - Cross Site Request Forgery (CSRF) vulnerability Exploitation status Not known exploited Fix YesAffected product C Cyrlitera Published 06/27/2025 Severity Medium CVE-2025-22659WordPress Orbit Fox by ThemeIsle plugin <= 2.10.44 - Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product O Orbit Fox by ThemeIsle Published 03/27/2025 Severity Medium CVE-2025-1065Visualizer: Tables and Charts Manager for WordPress <= 3.11.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Import Data From File Exploitation status Not known exploited Fix YesAffected product V Visualizer: Tables and Charts Manager for WordPress Published 02/19/2025 Severity Medium CVE-2024-10705Multiple Page Generator Plugin – MPG <= 4.0.5 - Authenticated (Editor+) Server-Side Request Forgery via fileUrl Exploitation status Not known exploited Fix YesAffected product M Multiple Page Generator Plugin – MPG Published 01/26/2025 Severity Medium CVE-2025-24666WordPress Hyve Lite plugin <= 1.2.2 - Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product A AI Chatbot for WordPress – Hyve Lite Published 01/24/2025 Severity Medium CVE-2025-24668WordPress PPOM for WooCommerce plugin <= 33.0.8 - Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product P PPOM for WooCommerce Published 01/24/2025 Severity Medium CVE-2024-13183Orbit Fox by ThemeIsle <= 2.10.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag Parameter Exploitation status Not known exploited Fix YesAffected product O Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Published 01/10/2025 Severity Medium CVE-2025-0311Orbit Fox by ThemeIsle <= 2.10.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table Widget Exploitation status Not known exploited Fix YesAffected product O Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Published 01/10/2025 Severity Medium CVE-2024-37467WordPress Hestia theme <= 3.1.2 - Cross Site Request Forgery (CSRF) vulnerability Exploitation status Not known exploited Fix YesAffected product H Hestia Published 01/02/2025 Severity Medium CVE-2023-39920WordPress Redirection for Contact Form 7 plugin <= 2.9.2 - Broken Access Control vulnerability Exploitation status Public exploit Fix YesAffected product R Redirection for Contact Form 7 Published 12/13/2024 Severity High CVE-2024-11219Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.6 - Unauthetnicated Path Traversal to Arbitrary Image View Exploitation status Not known exploited Fix YesAffected product O Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Published 11/27/2024 Severity Medium CVE-2024-52420WordPress Disable Admin Notices individually plugin <= 1.4.0 - Cross Site Request Forgery (CSRF) vulnerability Exploitation status Not known exploited Fix YesAffected product D Disable Admin Notices individually Published 11/19/2024 Severity Medium CVE-2024-51671WordPress Otter Blocks plugin <= 3.0.3 - Broken Access Control vulnerability Exploitation status Not known exploited Fix YesAffected product O Otter - Gutenberg Block Published 11/19/2024 Severity Low CVE-2024-10672Multiple Page Generator Plugin – MPG <= 4.0.2 - Authenticated (Editor+) Directory Traversal to Limited File Deletion Exploitation status Not known exploited Fix YesAffected product M Multiple Page Generator Plugin – MPG Published 11/12/2024 Severity Low CVE-2024-10367Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload Exploitation status Not known exploited Fix YesAffected product O Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Published 11/01/2024 Severity Medium CVE-2024-7424Multiple Page Generator Plugin – MPG <= 4.0.1 - Missing Authorization Exploitation status Not known exploited Fix YesAffected product M Multiple Page Generator Plugin – MPG Published 11/01/2024 Severity Medium CVE-2024-47325WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.7 - SQL Injection vulnerability Exploitation status Not known exploited Fix YesAffected product M MPG Published 10/20/2024 Severity High CVE-2022-4974Freemius SDK <= 2.4.2 - Missing Authorization Checks Exploitation status Not known exploited Fix YesAffected product Y YASR – Yet Another Star Rating Plugin for WordPress Published 10/16/2024 Severity Medium CVE-2024-7778Orbit Fox by ThemeIsle <= 2.10.36 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload Exploitation status Not known exploited Fix YesAffected product O Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Published 08/22/2024 Severity Medium CVE-2024-2484Orbit Fox by ThemeIsle <= 2.10.34 - Authenticated (Contributor+) Stored Cross-Site Scripting via Services and Post Type Grid Widgets Exploitation status Not known exploited Fix YesAffected product O Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Published 06/22/2024 Severity Medium CVE-2024-3105Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code Execution Exploitation status Not known exploited Fix YesAffected product W Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts Published 06/15/2024 Severity Critical CVE-2024-35728WordPress Product Addons & Fields for WooCommerce plugin <= 32.0.20 - Content Injection vulnerability Exploitation status Not known exploited Fix YesAffected product P PPOM for WooCommerce Published 06/10/2024 Severity Medium CVE-2024-35682WordPress Otter Blocks PRO plugin <= 2.6.11 - Authenticated Sensitive Data Exposure vulnerability Exploitation status Not known exploited Fix YesAffected product O Otter Blocks PRO Published 06/08/2024 Severity Medium CVE-2024-35736WordPress Visualizer plugin <= 3.11.1 - SQL Injection vulnerability Exploitation status Not known exploited Fix YesAffected product V Visualizer Published 06/08/2024 Severity High CVE-2023-7073Auto Featured Image (Auto Post Thumbnail) <= 4.1.7 - Authenticated (Author+) Server-Side Request Forgery Exploitation status Not known exploited Fix YesAffected product A Auto Featured Image (Auto Post Thumbnail) Published 05/31/2024 Severity Medium CVE-2024-4635Menu Icons by ThemeIsle <= 0.13.13 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload Exploitation status Not known exploited Fix YesAffected product M Menu Icons by ThemeIsle Published 05/16/2024 Severity Medium CVE-2024-3750Visualizer: Tables and Charts Manager for WordPress <= 3.10.15 - Missing Authorization to Arbitrary SQL Execution Exploitation status Not known exploited Fix YesAffected product V Visualizer: Tables and Charts Manager for WordPress Published 05/16/2024 Severity High CVE-2024-3725Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag' Exploitation status Not known exploited Fix YesAffected product O Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Published 05/02/2024 Severity Medium CVE-2024-3962Product Addons & Fields for WooCommerce <= 32.0.18 - Unauthenticated Arbitrary File Upload via ppom_upload_file Exploitation status Not known exploited Fix YesAffected product P PPOM – Product Addons & Custom Fields for WooCommerce Published 04/26/2024 Severity Critical CVE-2024-2729Otter Blocks < 2.6.6 - Contributor+ Stored XSS Exploitation status Public exploit Fix YesAffected product O Otter Blocks Published 04/18/2024 Severity Medium CVE-2023-6805RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Forgery (SSRF) Exploitation status Not known exploited Fix YesAffected product R RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Published 04/17/2024 Severity Medium CVE-2024-31301WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.0 - Cross Site Request Forgery (CSRF) vulnerability Exploitation status Not known exploited Fix YesAffected product M Multiple Page Generator Plugin – MPG Published 04/12/2024 Severity Medium CVE-2024-3344Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Author+) Limited File Upload to Stored Cross-Site Scripting Exploitation status Not known exploited Fix YesAffected product O Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Published 04/11/2024 Severity Medium CVE-2024-3343Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes Exploitation status Not known exploited Fix YesAffected product O Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Published 04/11/2024 Severity Medium CVE-2024-2226Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting Exploitation status Not known exploited Fix YesAffected product O Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Published 04/09/2024 Severity Medium CVE-2023-6877RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Error Message Exploitation status Not known exploited Fix YesAffected product R RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Published 04/07/2024 Severity Medium CVE-2024-27951WordPress Multiple Page Generator Plugin <= 3.4.0 - Auth. Remote Code Execution (RCE) vulnerability Exploitation status Not known exploited Fix YesAffected product M Multiple Page Generator Plugin – MPG Published 04/03/2024 Severity Critical CVE-2024-2841Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting Exploitation status Not known exploited Fix YesAffected product O Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Published 03/29/2024 Severity Medium CVE-2024-30235WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.0 - Broken Access Control vulnerability Exploitation status Not known exploited Fix YesAffected product M Multiple Page Generator Plugin – MPG Published 03/26/2024 Severity Medium CVE-2024-27958WordPress Visualizer plugin <= 3.10.5 - Reflected Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product V Visualizer Published 03/17/2024 Severity High CVE-2024-1499Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting Exploitation status Not known exploited Fix YesAffected product O Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Published 03/13/2024 Severity Medium CVE-2024-1497Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via form widget addr2_width attribute Exploitation status Not known exploited Fix YesAffected product O Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Published 03/13/2024 Severity Medium CVE-2024-1684Otter Blocks PRO <= 2.6.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via File Field CSS Exploitation status Not known exploited Fix YesAffected product O Otter Blocks PRO – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Published 03/13/2024 Severity Medium CVE-2024-1691Otter Blocks PRO <= 2.6.3 - Unauthenticated Stored Cross-Site Scripting via SVG Upload Exploitation status Not known exploited Fix YesAffected product O Otter Blocks PRO – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Published 03/13/2024 Severity Medium CVE-2024-2126Orbit Fox by ThemeIsle <= 2.10.32 - Authenticated (Contributor+) Stored Cross-Site Scripiting via Registration Form Widget Exploitation status Not known exploited Fix YesAffected product O Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Published 03/13/2024 Severity Medium CVE-2024-1323Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting Exploitation status Not known exploited Fix YesAffected product O Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Published 02/27/2024 Severity Medium CVE-2024-1317RSS Aggregator by Feedzy <= 4.4.2 - Authenticated(Contributor+) SQL Injection Exploitation status Not known exploited Fix YesAffected product R RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Published 02/20/2024 Severity High CVE-2024-1318RSS Aggregator by Feedzy <= 4.4.2 - Missing Authorization to Arbitrary Page Creation and Publication Exploitation status Not known exploited Fix YesAffected product R RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Published 02/20/2024 Severity Medium CVE-2024-0508Orbit Fox by ThemeIsle <= 2.10.27 - Authenticated(Contributor+) Stored Cross-site Scripting via Pricing Table Elementor Widget Exploitation status Not known exploited Fix YesAffected product O Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Published 02/05/2024 Severity Medium CVE-2024-1092RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.1 - Missing Authorization Exploitation status Not known exploited Fix YesAffected product R RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Published 02/05/2024 Severity Medium CVE-2024-1162Orbit Fox by ThemeIsle <= 2.10.29 - Cross-Site Request Forgery Exploitation status Not known exploited Fix YesAffected product O Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Published 02/02/2024 Severity Medium CVE-2024-1047ThemeIsle SDK <= Various Versions - Missing Authorization Exploitation status Not known exploited Fix YesAffected product M Menu Icons by ThemeIsle Published 02/02/2024 Severity Medium