Stay Protected with Vulnerability Alerts

    Updated automatically every hour

    Recent WordPress Vulnerabilities

    Latest WordPress security vulnerabilities affecting plugins, themes, and core.

    MEDIUM (5.7)
    Plugin

    Stored Cross-Site Scripting in MediaPress Plugin via mpp-uploader Shortcode

    Published Date: 1/6/2026

    The MediaPress plugin for WordPress up to version 1.6.1 is susceptible to a stored cross-site scripting (XSS) vulnerability. An attacker with contributor-level access or higher can exploit this vulnerability to execute arbitrary scripts on affected pages by injecting code through the mpp-uploader shortcode.

    MEDIUM (5.6)
    Plugin

    Unauthorized Content Modification in LearnPress Plugin

    Published Date: 1/6/2026

    The LearnPress – WordPress LMS Plugin is exposed to unauthorized data modification due to missing capability checks in its AJAX handling function. This vulnerability allows attackers to alter course content without authentication in all versions up to and including 4.3.2.

    MEDIUM (6.8)
    Plugin

    Unauthorized Data Modification and Deletion in MasterStudy LMS Plugin REST API

    Published Date: 1/6/2026

    The MasterStudy LMS WordPress Plugin for Online Courses and Education is vulnerable to unauthorized modifications and deletions due to missing capability checks in its REST API endpoints up to version 3.7.6. This flaw allows subscribers and other low-privilege users to manipulate media files, posts, and course templates.

    MEDIUM (7.0)
    Plugin

    Unauthorized Data Access in GamiPress Plugin via Improper Capability Checks

    Published Date: 1/6/2026

    GamiPress – Gamification plugin for WordPress versions up to 7.6.1 is vulnerable to unauthorized data access due to missing capability checks. This vulnerability allows authenticated users with Subscriber-level access to enumerate users' email addresses and retrieve titles of private posts.

    MEDIUM (5.1)
    Plugin

    Stored Cross-Site Scripting Vulnerability in Table Field Add-on for ACF and SCF Plugin

    Published Date: 1/6/2026

    The Table Field Add-on for ACF and SCF plugin for WordPress contains a Stored Cross-Site Scripting vulnerability due to insufficient input sanitization and output escaping. This vulnerability allows potential attackers with at least Author-level privileges to inject arbitrary scripts into pages through table cell content.

    MEDIUM (5.6)
    Plugin

    Unauthorized Term Modification in AI Autotagger Plugin Due to Missing Capability Check

    Published Date: 1/6/2026

    The AI Autotagger plugin for WordPress is susceptible to unauthorized data modification. Users with Contributor-level access or higher can exploit this flaw to alter taxonomy terms on any post.

    MEDIUM (5.4)
    Plugin

    Information Exposure in Phlox Theme Plugin via auxels_ajax_search

    Published Date: 1/6/2026

    The Phlox theme plugin for WordPress contains a vulnerability that allows unauthenticated attackers to extract titles from draft posts. This is due to insufficient restrictions on the auxels_ajax_search function, affecting all versions up to 2.17.13.

    MEDIUM (6.2)
    Plugin

    BuddyPress Xprofile Custom Field Types Arbitrary File Deletion Vulnerability

    Published Date: 1/6/2026

    The BuddyPress Xprofile Custom Field Types plugin for WordPress suffers from a critical vulnerability that allows arbitrary file deletion. This flaw can potentially lead to remote code execution through the deletion of key files, such as wp-config.php.

    MEDIUM (6.0)
    Plugin

    Stored Cross-Site Scripting in URL Image Importer Plugin via SVG Uploads

    Published Date: 1/6/2026

    The URL Image Importer plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability due to inadequate sanitization of SVG files. This vulnerability affects all plugin versions up to 1.0.7, allowing authenticated users with at least Author-level privileges to execute arbitrary scripts when an SVG is accessed.

    MEDIUM (5.9)
    Plugin

    Server-Side Request Forgery in Xagio SEO Plugin's pixabayDownloadImage Function

    Published Date: 1/6/2026

    The Xagio SEO – AI Powered SEO plugin for WordPress contains a Server-Side Request Forgery (SSRF) vulnerability in its pixabayDownloadImage function. This affects versions up to and including 7.1.0.30, allowing authenticated users with at least Subscriber-level permissions to perform unauthorized web requests.

    MEDIUM (6.3)
    Plugin

    Unauthorized Subscriber Data Deletion in Popupkit Plugin

    Published Date: 1/6/2026

    The Popupkit plugin for WordPress is vulnerable to unauthorized deletion of subscriber data through its REST API. This vulnerability affects all versions up to 2.2.0, allowing users with Subscriber-level access to delete subscriber records.

    MEDIUM (6.9)
    Plugin

    FS Registration Password Plugin Privilege Escalation via Account Takeover

    Published Date: 1/6/2026

    The FS Registration Password plugin for WordPress allows privilege escalation due to inadequate identity validation, enabling attackers to change user passwords, including those of administrators. This vulnerability affects all plugin versions up to and including 1.0.1.

    MEDIUM (5.3)
    Plugin

    Privilege Escalation in AS Password Field In Default Registration Form Plugin

    Published Date: 1/6/2026

    The AS Password Field In Default Registration Form plugin for WordPress is susceptible to privilege escalation via account takeover, affecting versions up to 2.0.0. This vulnerability arises from insufficient identity validation when updating passwords, potentially allowing attackers to change user passwords without authentication.

    MEDIUM (6.5)
    Plugin

    Stored Cross-Site Scripting Vulnerability in ForumWP User Display Name

    Published Date: 1/6/2026

    The ForumWP plugin up to version 2.1.6 has a stored cross-site scripting vulnerability affecting user display names. This flaw allows authenticated users with minimal access (Subscriber level or higher) to inject malicious scripts.

    MEDIUM (5.2)
    Plugin

    Unauthorized Ticket Modification in ilGhera Support System for WooCommerce Plugin

    Published Date: 1/6/2026

    The ilGhera Support System for WooCommerce plugin allows users with Subscriber-level access and above to delete or modify support tickets due to insufficient capability checks. This vulnerability affects versions up to and including 1.2.6.

    MEDIUM (5.2)
    Plugin

    Unauthorized Data Modification in Popup and Slider Builder Plugin

    Published Date: 1/6/2026

    The Popup and Slider Builder by Depicter plugin for WordPress is vulnerable to unauthorized data modification. This occurs due to a missing capability check allowing unauthenticated attackers to alter the pop-up display settings in versions up to and including 4.0.7.

    MEDIUM (5.2)
    Plugin

    Time-Based SQL Injection in Page Expire Popup/Redirection Plugin

    Published Date: 1/6/2026

    The Page Expire Popup/Redirection plugin for WordPress has a time-based SQL injection vulnerability in versions up to and including 1.0. This vulnerability allows authenticated users with at least Author-level permissions to execute arbitrary SQL commands, potentially leading to the exposure of sensitive data.

    MEDIUM (5.0)
    Plugin

    Path Traversal Vulnerability in FastDup – Fastest WordPress Migration & Duplicator Plugin

    Published Date: 1/6/2026

    The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress suffers from a path traversal vulnerability. This security flaw allows authenticated users with at least Contributor-level access to read the contents of arbitrary directories on the server through the 'dir_path' parameter in the 'njt-fastdup/v1/template/directory-tree' REST API endpoint.

    MEDIUM (6.3)
    Plugin

    SQL Injection Vulnerability in CBX Bookmark & Favorite WordPress Plugin

    Published Date: 1/6/2026

    The CBX Bookmark & Favorite plugin for WordPress up to version 2.0.4 is susceptible to a SQL Injection vulnerability. This issue stems from inadequate escaping of the 'orderby' parameter, allowing authenticated users with at least Subscriber access to manipulate SQL queries and potentially access sensitive database information.

    MEDIUM (6.4)
    Plugin

    Sensitive Information Exposure in Appointment Booking Calendar Plugin

    Published Date: 1/6/2026

    The Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to sensitive information exposure due to a hardcoded fall-back salt used in token generation. This flaw exists in versions up to 1.6.9.5, allowing attackers to potentially access and modify booking information without authentication.

    MEDIUM (6.5)
    Plugin

    SQL Injection in Form Vibes – Database Manager for Forms via 'params' Parameter

    Published Date: 1/6/2026

    The Form Vibes – Database Manager for Forms plugin for WordPress is affected by an SQL Injection vulnerability in versions up to 1.4.13. This issue allows authenticated users with Administrator access to manipulate SQL queries by exploiting insufficient escaping and input validation on the 'params' parameter.

    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More