I went for coffee and came back with 6 vulnerabilities in WordPress plugins
Related Vulnerabilities
- CVE-2026-2305: The AddFunc Head & Footer Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via MEDIUM
- CVE-2026-4162: The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and HIGH
- CVE-2026-5207: The LifterLMS plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all v MEDIUM
- CVE-2026-5809: The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and HIGH
- CVE-2026-4351: The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in HIGH
Related Coverage
Threat Actors