A vulnerability, which was classified as critical, was found in Administrative Shortcodes Plugin up to 0.3.4 on WordPress. The affected element is the function get_template_part. Such manipulation leads to file inclusion.
This vulnerability is uniquely identified as CVE-2026-1257. The attack can be launched remotely. No exploit exists.
A vulnerability identified as critical has been detected in AIKTP Plugin up to 5.0.04 on WordPress. This affects the function verify_user_logged_in of the file /aiktp/getToken of the component REST API Endpoint. Performing a manipulation results in missing authorization.
This vulnerability is cataloged as CVE-2026-1103. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as problematic, was found in Canto Testimonials Plugin up to 1.0 on WordPress. Affected by this issue is the function fx of the component Shortcode Handler. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2026-1095. It is possible to launch the attack remotely. No exploit is available.
A vulnerability described as problematic has been identified in SurveyJS Plugin up to 1.12.20 on WordPress. Affected by this vulnerability is the function SurveyJS_RenameSurvey. Executing a manipulation can lead to cross-site request forgery.
This vulnerability is registered as CVE-2025-13194. It is possible to launch the attack remotely. No exploit is available.
A vulnerability classified as problematic was found in SurveyJS Plugin up to 1.12.20 on WordPress. This affects the function SurveyJS_CloneSurvey. The manipulation results in cross-site request forgery.
This vulnerability is reported as CVE-2025-13205. The attack can be launched remotely. No exploit exists.
A vulnerability was found in SurveyJS Plugin up to 1.12.20 on WordPress and classified as problematic. This vulnerability affects the function SurveyJS_AddSurvey. Such manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-13139. The attack can be launched remotely. No exploit exists.
A vulnerability has been found in AdminQuickbar Plugin up to 1.9.3 on WordPress and classified as problematic. This affects an unknown part of the component Setting Handler. This manipulation causes cross-site request forgery.
This vulnerability is handled as CVE-2025-14630. The attack can be initiated remotely. There is not any exploit available.
A vulnerability categorized as problematic has been discovered in All-in-One Video Gallery Plugin up to 4.1.0/4.6.4 on WordPress. Affected by this issue is the function ajax_callback_store_user_meta of the component User Meta Update Handler. Such manipulation leads to missing authorization.
This vulnerability is listed as CVE-2025-15516. The attack may be performed from remote. There is no available exploit.
A vulnerability described as problematic has been identified in Moderate Selected Posts Plugin up to 1.4 on WordPress. This affects the function msp_admin_page of the component Setting Handler. Such manipulation leads to cross-site request forgery.
This vulnerability is documented as CVE-2025-14907. The attack can be executed remotely. There is not any exploit available.
A vulnerability classified as problematic was found in Login Page Editor Plugin up to 1.2 on WordPress. Affected is the function devotion_loginform_process. Executing a manipulation can lead to cross-site request forgery.
This vulnerability appears as CVE-2026-1088. The attack may be performed from remote. There is no available exploit.
A vulnerability, which was classified as problematic, has been found in Administrative Shortcodes Plugin up to 0.3.4 on WordPress. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. The manipulation of the argument login/logout leads to cross site scripting.
This vulnerability is traded as CVE-2026-1099. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability has been found in ThemeRuby Multi Authors Plugin up to 1.0.0 on WordPress and classified as problematic. The impacted element is an unknown function of the component Shortcode Handler. Performing a manipulation of the argument before/after results in cross site scripting.
This vulnerability was named CVE-2026-1097. The attack may be initiated remotely. There is no available exploit.