| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-6443 | Essentialplugin Plugins (Various Versions) - Injected Backdoor | essentialplugin | Accordion and Accordion Slider | Critical | 9.8 | 2026-04-17 06:44:49 | Deep Dive |
| CVE-2026-5797 | Quiz and Survey Master (QSM) <= 11.1.0 - Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields | expresstech | Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker | Medium | 5.3 | 2026-04-17 05:29:27 | Deep Dive |
| CVE-2026-3330 | Form Maker by 10Web <= 1.15.40 - Authenticated (Administrator+) SQL Injection via 'ip_search' Parameter | 10web | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | Medium | 4.9 | 2026-04-17 03:36:44 | Deep Dive |
| CVE-2026-4388 | Form Maker by 10Web <= 1.15.40 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Text Box | 10web | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | High | 7.2 | 2026-04-14 02:25:48 | Deep Dive |
| CVE-2025-15441 | Form Maker < 1.15.38 - SQL Injection | Unknown | Form Maker by 10Web | 中危 | - | 2026-04-13 06:00:11 | Deep Dive |
| CVE-2018-25207 | Online Quiz Maker 1.0 SQL Injection via catid Parameter | Hscripts | Online Quiz Maker | High | 7.1 | 2026-03-26 11:39:54 | Deep Dive |
| CVE-2026-2412 | Quiz and Survey Master (QSM) <= 10.3.5 - Authenticated (Contributor+) SQL Injection via 'merged_question' Parameter | expresstech | Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker | Medium | 6.5 | 2026-03-23 22:25:40 | Deep Dive |
| CVE-2019-25565 | Magic Iso Maker 5.5 Buffer Overflow Denial of Service | Magiciso | Magic Iso Maker | Medium | 6.2 | 2026-03-21 12:47:06 | Deep Dive |
| CVE-2019-25561 | Lyric Maker 2.0.1.0 Denial of Service via Buffer Overflow | Jetaudio | Lyric Maker | Medium | 6.2 | 2026-03-21 12:47:02 | Deep Dive |
| CVE-2026-4302 | WowOptin: Next-Gen Popup Maker <= 1.4.29 - Unauthenticated Server-Side Request Forgery via 'link' Parameter in REST API | wpxpo | WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation | High | 7.2 | 2026-03-21 01:24:38 | Deep Dive |
| CVE-2026-3475 | Instant Popup Builder <= 1.1.7 - Unauthenticated Arbitrary Shortcode Execution via 'token' Parameter | instantpopupbuilder | Instant Popup Builder – Powerful Popup Maker for Opt-ins, Email Newsletters & Lead Generation | Medium | 5.3 | 2026-03-19 07:34:56 | Deep Dive |
| CVE-2026-32342 | WordPress Quiz Maker plugin <= 6.7.1.2 - Cross Site Request Forgery (CSRF) vulnerability | Ays Pro | Quiz Maker | 中危 | - | 2026-03-13 11:41:57 | Deep Dive |
| CVE-2026-1720 | WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation <= 1.4.24 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation | wpxpo | WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation | High | 8.8 | 2026-03-05 13:24:01 | Deep Dive |
| CVE-2026-1558 | WP Recipe Maker <= 10.3.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Metadata Modification via 'recipeId' Parameter | brechtvds | WP Recipe Maker | Medium | 5.3 | 2026-02-27 04:33:03 | Deep Dive |
| CVE-2025-14742 | WP Recipe Maker <= 10.2.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure | brechtvds | WP Recipe Maker | Medium | 4.3 | 2026-02-25 09:26:50 | Deep Dive |
| CVE-2026-26370 | WordPress plugin Survey Maker 跨站脚本漏洞 | Ays Pro | Survey Maker | - | - | 2026-02-20 07:42:15 | Deep Dive |
| CVE-2026-2384 | Quiz Maker <= 6.7.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | ays-pro | Quiz Maker | Medium | 6.4 | 2026-02-20 02:23:33 | Deep Dive |
| CVE-2026-1058 | Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via Hidden Field | 10web | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | High | 7.1 | 2026-02-03 06:38:06 | Deep Dive |
| CVE-2026-1065 | Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via SVG file | 10web | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | High | 7.2 | 2026-02-03 06:38:04 | Deep Dive |
| CVE-2026-24888 | Maker.js Vulnerable to Unsafe Property Copying in makerjs.extendObject | microsoft | maker.js | Medium | 6.5 | 2026-01-28 21:35:44 | Deep Dive |