Stay Protected with Vulnerability Alerts

    Updated automatically every hour

    Recent WordPress Vulnerabilities

    Latest WordPress security vulnerabilities affecting plugins, themes, and core.

    MEDIUM (6.8)
    Plugin

    Unauthorized Modification Vulnerability in AffiliateX Plugin

    Published Date: 1/15/2026

    The AffiliateX - Amazon Affiliate Plugin for WordPress contains a vulnerability in its AJAX action that allows unauthorized data modification. This issue affects versions 1.0.0 to 1.3.9.3 and permits attacker execution of arbitrary JavaScript by authenticated users with minimal privileges.

    MEDIUM (6.2)
    Plugin

    Arbitrary File Upload Vulnerability in Supreme Modules Lite WordPress Plugin

    Published Date: 1/15/2026

    The Supreme Modules Lite plugin version 2.5.62 and below is affected by an arbitrary file upload vulnerability due to inadequate validation of file types, particularly JSON files with double extensions. This allows authenticated users with author-level access to upload potentially malicious files, risking remote code execution.

    MEDIUM (5.3)
    Theme

    Unauthorized Email Sending in Kalium WordPress Theme

    Published Date: 1/15/2026

    The Kalium 3 theme for WordPress is susceptible to unauthorized email sending due to insufficient access control in its contact form. This flaw allows unauthenticated users to exploit the theme as an open mail relay.

    MEDIUM (6.2)
    Plugin

    Unauthorized File Deletion in Drag and Drop Multiple File Upload for Contact Form 7 Plugin

    Published Date: 1/15/2026

    The Drag and Drop Multiple File Upload for Contact Form 7 plugin up to version 1.3.9.2 is vulnerable to an unauthorized data modification issue. This vulnerability allows unauthenticated attackers to delete uploaded files due to a missing ownership check when the 'Send attachments as links' option is enabled.

    MEDIUM (5.1)
    Plugin

    Stored Cross-Site Scripting in WP-Members Membership Plugin

    Published Date: 1/15/2026

    The WP-Members Membership Plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability via the Multiple Checkbox and Multiple Select user profile fields. This issue affects all plugin versions up to and including 3.5.4.3, allowing authenticated attackers to inject malicious scripts.

    MEDIUM (5.6)
    Plugin

    Blind SQL Injection in Appointment Booking Calendar Plugin

    Published Date: 1/14/2026

    The Appointment Booking Calendar plugin for WordPress is vulnerable to a blind SQL Injection attack through the `order` and `append_where_sql` parameters. This vulnerability affects versions up to 1.6.9.9 and enables attackers to exploit the SQL queries due to inadequate input sanitization.

    MEDIUM (5.8)
    Plugin

    Unauthorized Data Modification in PayHere Payment Gateway Plugin for WooCommerce

    Published Date: 1/14/2026

    The PayHere Payment Gateway Plugin for WooCommerce versions up to 2.3.9 are susceptible to a vulnerability allowing unauthorized data modification. Unauthenticated attackers can exploit improper validation logic to alter the status of WooCommerce orders.

    MEDIUM (5.6)
    Plugin

    Cross-Site Request Forgery in Stopwords for Comments Plugin

    Published Date: 1/14/2026

    The Stopwords for Comments plugin up to version 1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw allows attackers to alter stopwords settings by tricking administrators into clicking a malicious link.

    MEDIUM (7.0)
    Plugin

    Missing Authorization in Perfit WooCommerce Plugin Logout Function

    Published Date: 1/14/2026

    The Perfit WooCommerce plugin for WordPress, up to version 1.0.1, suffers from a Missing Authorization vulnerability. This flaw allows unauthenticated attackers to delete arbitrary plugin settings through the `action` parameter, due to a lack of authorization checks on the `logout` function.

    MEDIUM (5.0)
    Plugin

    Cross-Site Request Forgery in SocialChamp WordPress Plugin

    Published Date: 1/14/2026

    The SocialChamp WordPress plugin is affected by a Cross-Site Request Forgery (CSRF) vulnerability in versions up to 1.3.3. This flaw allows unauthenticated users to alter plugin settings through forged requests if they trick an administrator into clicking on a malicious link.

    MEDIUM (5.6)
    Plugin

    Unauthorized WooCommerce Order Modification via Float Payment Gateway Plugin

    Published Date: 1/14/2026

    The Float Payment Gateway plugin for WordPress, up to version 1.1.9, has a vulnerability allowing unauthorized modifications of WooCommerce orders. An unauthorized attacker can exploit improper error handling in the verifyFloatResponse function to mark any order as failed.

    MEDIUM (5.8)
    Plugin

    Stored Cross-Site Scripting in Electric Studio Download Counter Plugin

    Published Date: 1/14/2026

    The Electric Studio Download Counter plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability in versions up to and including 2.4. This vulnerability arises due to improper sanitization and escaping of user inputs in the plugin settings, allowing authenticated Administrator-level users to inject malicious scripts.

    MEDIUM (6.4)
    Plugin

    Unauthorized Order Status Modification via Aplazo Payment Gateway

    Published Date: 1/14/2026

    The Aplazo Payment Gateway plugin for WordPress allows unauthenticated users to change WooCommerce order statuses to 'pending payment'. This is due to a missing capability check on the plugin's check_success_response() function.

    MEDIUM (6.4)
    Plugin

    Stored Cross-Site Scripting in Short Link Plugin via Title Parameters

    Published Date: 1/14/2026

    The Short Link plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to improper input sanitization and output escaping on specific parameters. Authenticated users with administrator-level access can inject malicious scripts, which execute when the contaminated page is viewed.

    MEDIUM (5.8)
    Plugin

    Stored Cross-Site Scripting Vulnerability in WP Allowed Hosts Plugin

    Published Date: 1/14/2026

    The WP Allowed Hosts plugin for WordPress contains a vulnerability that allows stored Cross-Site Scripting (XSS) via the 'allowed-hosts' parameter. This flaw affects versions up to 1.0.8 and can be exploited by authenticated users with administrative privileges in certain installations.

    MEDIUM (6.3)
    Plugin

    Stored Cross-Site Scripting in LinkedIn SC WordPress Plugin via Insufficient Input Sanitization

    Published Date: 1/14/2026

    The LinkedIn SC plugin for WordPress, up to and including version 1.1.9, is susceptible to Stored Cross-Site Scripting through parameters such as 'linkedin_sc_date_format', 'linkedin_sc_api_key', and 'linkedin_sc_secret_key'. This vulnerability allows authenticated users with administrator access or higher to inject malicious scripts that execute on user interaction with affected pages.

    MEDIUM (5.9)
    Plugin

    SQL Injection Vulnerability in Shipping Rate By Cities Plugin

    Published Date: 1/14/2026

    The Shipping Rate By Cities plugin for WordPress is vulnerable to SQL Injection through the 'city' parameter in versions up to 2.0.0. This vulnerability allows attackers to inject malicious SQL code, potentially leading to unauthorized data retrieval.

    MEDIUM (6.3)
    Plugin

    Stored Cross-Site Scripting Vulnerability in WMF Mobile Redirector Plugin for WordPress

    Published Date: 1/14/2026

    The WMF Mobile Redirector plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability due to insufficient input sanitization and output escaping in its settings. This vulnerability affects all versions up to and including 1.2 and can be exploited by authenticated users with Administrator privileges to inject malicious scripts into pages.

    MEDIUM (5.6)
    Plugin

    Kunze Law Plugin Stored XSS and Path Traversal Vulnerability

    Published Date: 1/14/2026

    The Kunze Law plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to improper handling of HTML content fetched from remote servers. It also contains a path traversal vulnerability within its shortcode functionality, which could allow an attacker to place malicious HTML files in arbitrary locations.

    MEDIUM (5.3)
    Plugin

    Local File Inclusion Vulnerability in News and Blog Designer Bundle Plugin

    Published Date: 1/14/2026

    The News and Blog Designer Bundle plugin for WordPress is affected by a Local File Inclusion (LFI) vulnerability in all versions up to and including 1.1. Unauthenticated attackers can exploit this vulnerability to include and execute arbitrary .php files on the server.

    MEDIUM (6.2)
    Plugin

    WP-CRM System Plugin Unauthorized Access Due to Missing Capability Checks

    Published Date: 1/14/2026

    The WP-CRM System plugin for WordPress allows unauthorized access due to inadequate capability checks on specific AJAX functions. This vulnerability affects all plugin versions up to 3.4.5, enabling low privilege users to access email addresses and alter tasks within the CRM.

    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More