| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-27057 | WordPress Penci Filter Everything plugin <= 1.7 - Cross Site Scripting (XSS) vulnerability | PenciDesign | Penci Filter Everything | - | - | 2026-02-19 08:27:10 | Deep Dive |
| CVE-2026-24371 | WordPress BA Book Everything plugin <= 1.8.16 - Broken Access Control vulnerability | bookingalgorithms | BA Book Everything | Medium | 4.3 | 2026-01-22 16:52:46 | Deep Dive |
| CVE-2025-14449 | BA Book Everything <= 1.8.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via babe-search-form Shortcode | bookingalgorithms | BA Book Everything | Medium | 6.4 | 2025-12-19 06:48:23 | Deep Dive |
| CVE-2025-12683 | NULL DACL assigned to Named Pipe communicating with SYSTEM Service | Voidtools | Everything | - | - | 2025-11-04 04:23:03 | Deep Dive |
| CVE-2025-59583 | WordPress Penci Filter Everything Plugin < 1.7 - Cross Site Scripting (XSS) Vulnerability | PenciDesign | Penci Filter Everything | Medium | 6.5 | 2025-09-22 18:25:52 | Deep Dive |
| CVE-2025-5084 | Post Grid Master <= 3.4.13 - Reflected Cross-Site Scripting via argsArray['read_more_text'] | mdshuvo | Post Grid Master — Post Grids & AJAX Filters | Medium | 6.1 | 2025-07-24 09:22:15 | Deep Dive |
| CVE-2025-53332 | WordPress Track Everything plugin <= 2.0.1 - Cross Site Request Forgery (CSRF) Vulnerability | ethoseo | Track Everything | High | 7.1 | 2025-06-27 13:21:43 | Deep Dive |
| CVE-2024-11642 | Post Grid Master <= 3.4.12 - Missing Authorization to Unauthenticated Local PHP File Inclusion | mdshuvo | Post Grid Master — Post Grids & AJAX Filters | Critical | 9.8 | 2025-01-09 11:11:04 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-47360 | WordPress BA Book Everything plugin <= 1.6.20 - Reflected Cross Site Scripting (XSS) vulnerability | bookingalgorithms | BA Book Everything | High | 7.1 | 2024-10-06 09:52:17 | Deep Dive |
| CVE-2024-8794 | BA Book Everything <= 1.6.20 - Unauthenticated Arbitrary User Password Reset | bookingalgorithms | BA Book Everything | Medium | 5.3 | 2024-09-24 02:31:01 | Deep Dive |
| CVE-2024-8795 | BA Book Everything <= 1.6.20 - Cross-Site Request Forgery to Email Address Update/Account Takeover | bookingalgorithms | BA Book Everything | High | 8.8 | 2024-09-24 01:56:47 | Deep Dive |
| CVE-2024-5485 | SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything! <= 1.0.46 - Authenticated (Contributor+) Stored Cross-Site Scripting via Trigger Link Shortcode | brainstormforce | OttoKit: All-in-One Automation Platform | Medium | 6.4 | 2024-06-04 06:41:46 | Deep Dive |
| CVE-2024-32576 | WordPress BA Book Everything plugin <= 1.6.8 - Cross Site Scripting (XSS) vulnerability | Booking Algorithms | BA Book Everything | Medium | 6.5 | 2024-04-18 09:34:42 | Deep Dive |
| CVE-2024-32598 | WordPress BA Book Everything plugin <= 1.6.8 - Cross Site Scripting (XSS) vulnerability | Booking Algorithms | BA Book Everything | Medium | 5.9 | 2024-04-18 08:26:04 | Deep Dive |
| CVE-2024-3672 | BA Book Everything <= 1.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | bookingalgorithms | BA Book Everything | Medium | 6.4 | 2024-04-16 12:51:47 | Deep Dive |
| CVE-2024-32125 | WordPress BA Book Everything plugin <= 1.6.4 - Auth. SQL Injection vulnerability | Booking Algorithms | BA Book Everything | High | 8.5 | 2024-04-15 07:38:00 | Deep Dive |
| CVE-2023-52151 | WordPress Uncanny Automator Plugin <= 5.1.0.2 is vulnerable to Sensitive Data Exposure | Uncanny Automator, Uncanny Owl | Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin | Medium | 5.3 | 2024-01-05 10:52:27 | Deep Dive |
| CVE-2023-49749 | WordPress SureTriggers Plugin <= 1.0.23 is vulnerable to Cross Site Request Forgery (CSRF) | SureTriggers | SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything! | Medium | 4.3 | 2023-12-15 15:45:01 | Deep Dive |
| CVE-2023-1871 | YourChannel <= 1.2.4 - Cross-Site Request Forgery to Plugin Language Translation Reset | pluginbuilders | YourChannel: Everything you want in a YouTube plugin. | Medium | 5.4 | 2023-04-05 13:25:28 | Deep Dive |