In FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More component for WordPress versions 1.9.2 and earlier a high severity vulnerability CVE-2025-15028 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages. To address this issue, users should upgrade FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-15028.
Read more CMSIn Accelerate theme component for WordPress versions 1.5.3 and earlier a medium severity vulnerability CVE-2025-9266 was detected. This vulnerability allows authenticated attackers, with Subscriber-level access and above, to install and activate the ThemeGrill Demo Importer plugin. To address this issue, users should upgrade Accelerate theme to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-9266.
Read more CMSIn Ad Inserter – Ad Manager & AdSense Ads component for WordPress versions 2.8.16 and earlier a medium severity vulnerability CVE-2026-11983 was detected. This vulnerability allows unauthenticated attackers to view restricted ad block content. To address this issue, users should upgrade Ad Inserter – Ad Manager & AdSense Ads to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-11983.
Read more CMSIn Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX component for WordPress versions 5.0.13 and earlier a medium severity vulnerability CVE-2026-5158 was detected. This vulnerability allows authenticated attackers with Contributor-level access to inject arbitrary web scripts. To address this issue, users should upgrade Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-5158.
Read more CMSIn Nexter Blocks component for WordPress versions before 5.0.2 a medium severity vulnerability CVE-2025-15678 was detected. This vulnerability allows users to upload a file containing malicious JavaScript that executes when the file is accessed. To address this issue, users should upgrade Nexter Blocks to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-15678.
Read more CMSIn EONSR AEO Agent component for WordPress versions 3.7.9 and earlier a medium severity vulnerability CVE-2026-11588 was detected. This vulnerability allows unauthenticated attackers to create administrator-attributed published posts containing arbitrary web scripts. To address this issue, users should upgrade EONSR AEO Agent to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-11588.
Read more CMSIn Gutenberg Essential Blocks component for WordPress versions before 6.4.0 a high severity vulnerability CVE-2026-13154 was detected. This vulnerability allows unauthenticated users to read non-public published entries. To address this issue, users should upgrade Gutenberg Essential Blocks to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-13154.
Read more CMSIn WPCargo Track & Trace component for WordPress versions before 8.0.4 a critical severity vulnerability CVE-2026-12713 was detected. This vulnerability allows unauthenticated users to perform SQL injection attacks. To address this issue, users should upgrade WPCargo Track & Trace to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-12713.
Read more CMSIn Gutenberg Essential Blocks component for WordPress versions before 6.4.0 a high severity vulnerability CVE-2026-13153 was detected. This vulnerability allows unauthenticated users to read the lifetime number of units sold for any published product. To address this issue, users should upgrade Gutenberg Essential Blocks to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-13153.
Read more CMS