Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 14 February 2026
RSS218 vulnerabilities published on 14 February 2026
Severity:
Truelysell Core plugin allows unauthenticated attackers to gain admin access on WordPress sites
CVE-2025-8572
The Truelysell Core plugin for WordPress has a security issue that can allow attackers to create admin accounts without logging in. This is a concern for any site using the plugin, as it could give an...
9.8
WordPress midi-Synth Plugin Allows Malicious File Uploads
CVE-2026-1306
An attacker can upload any file to a WordPress site using the midi-Synth plugin, possibly allowing them to take control of the site. This is due to a lack of file checks in the plugin's export feature...
9.8
Magic Login Mail or QR Code plugin for WordPress allows attackers to hijack administrator accounts
CVE-2026-2144
The Magic Login Mail or QR Code plugin for WordPress stores login information in a publicly accessible location, allowing attackers to potentially take over administrator accounts. This affects all ve...
8.1
ImapEngine: Malicious Input Can Delete or Read Emails
CVE-2026-2469
GHSA-rfq9-4wcm-64gh
Older versions of ImapEngine are at risk of being tricked into deleting or reading emails by sending malicious input. This could also allow an attacker to end the user's email session or execute unaut...
5.7
PhotoStack Gallery plugin for WordPress risks exposing database secrets
CVE-2026-2024
The PhotoStack Gallery plugin for WordPress, used in websites with this plugin installed, is at risk of having its database contents exposed to unauthorized access. This is because the plugin does not...
7.5
WooCommerce Flexi Product Slider plugin allows attackers to load malicious files
CVE-2026-1988
The Flexi Product Slider and Grid for WooCommerce plugin has a security flaw that allows hackers to load any file on the server if they have contributor-level access and can add a special shortcode to...
7.5
BlueSnap Payment Gateway for WooCommerce plugin allows unauthorized order manipulation
CVE-2026-0692
The BlueSnap Payment Gateway plugin for WooCommerce is vulnerable. Attackers can pretend to be a trusted IP address and manipulate order statuses, such as making payments appear successful or failed. ...
7.5
Super Page Cache plugin for WordPress allows attackers to inject malicious scripts
CVE-2026-1843
The Super Page Cache plugin for WordPress has a security flaw that could allow hackers to inject malicious scripts into pages, which could be executed when users visit those pages. This could potentia...
7.2
Super Simple Contact Form Plugin Allows Malicious Scripts in WordPress
CVE-2026-0753
The Super Simple Contact Form plugin for WordPress has a security flaw that could allow hackers to inject malicious code into your site. If a user clicks on a link or performs a certain action, they c...
7.2
User Language Switch plugin for WordPress allows attackers to access internal data
CVE-2026-0745
The User Language Switch plugin for WordPress is used by many sites. If not updated, an attacker with high-level access can use this plugin to access sensitive internal data. To protect your site, upd...
7.2
Essential Addons for Elementor: Malicious Code Injected into Pages
CVE-2026-1512
The Essential Addons for Elementor plugin for WordPress has a security flaw that allows attackers to inject malicious code into certain pages. This can happen if an attacker with a certain level of ac...
6.4
myCred Plugin for WordPress Allows Malicious Code Injection via Coupons
CVE-2026-0550
The myCred plugin for WordPress can be exploited by authorized users with contributor access or higher to insert malicious code into web pages. This can happen when a user accesses a specific page wit...
6.4
Press3D Plugin for WordPress allows attackers to inject malicious scripts
CVE-2026-1985
The Press3D plugin for WordPress is affected by a security issue that could allow an attacker to inject malicious scripts into web pages. This could happen if an attacker with Author-level access or h...
6.4
Percent to Infograph Plugin for WordPress Allows Malicious Script Injection
CVE-2026-1939
The Percent to Infograph plugin for WordPress is at risk of allowing hackers to inject malicious scripts into certain pages. This could happen if a hacker with contributor-level access or higher edits...
6.4
Simple Plyr plugin for WordPress: Malicious scripts can be injected into pages
CVE-2026-1915
The Simple Plyr plugin for WordPress is not secure. Attackers with high-level access can inject malicious code into pages that users visit, allowing them to take control of the site or steal sensitive...
6.4
UpMenu plugin for WordPress allows hackers to inject malicious code
CVE-2026-1910
The UpMenu plugin for WordPress has a security flaw that lets authenticated users with contributor-level access or higher inject malicious code into web pages. This can happen when users access certai...
6.4
Sphere Manager Plugin for WordPress Allows Malicious Code Injection
CVE-2026-1905
The Sphere Manager plugin for WordPress may allow hackers to inject malicious code into websites, potentially allowing them to steal user data or take control of the site. This is a risk for sites usi...
6.4
Ravelry Designs Widget plugin for WordPress: Malicious Script Injection via Shortcode Attribute
CVE-2026-1903
The Ravelry Designs Widget plugin for WordPress is vulnerable to a security risk. An attacker with contributor-level access or higher can inject malicious scripts into pages, which can be executed whe...
6.4
QuestionPro Surveys plugin for WordPress: Malicious scripts can be injected into survey pages.
CVE-2026-1901
The QuestionPro Surveys plugin for WordPress has a security flaw that allows attackers to inject malicious code into survey pages. This can happen when an authenticated user with sufficient access edi...
6.4
ZoomifyWP WordPress Plugin: Malicious Code Can Run on Your Site
CVE-2026-1187
If you have the ZoomifyWP Free plugin installed, an attacker with contributor-level access or higher can inject malicious code into your website. This can happen if an attacker is able to add a specia...
6.4
Best-wp-google-map plugin lets attackers inject malicious scripts
CVE-2026-1096
The Best-wp-google-map plugin for WordPress is at risk if you have a contributor or above user with malicious intent. They can inject malicious scripts into your website that will run when users visit...
6.4
Payment Page Plugin for WordPress Allows Attackers to Inject Malicious Code
CVE-2026-0751
A security flaw in the Payment Page | Payment Form for Stripe plugin for WordPress allows attackers with certain permissions to inject malicious code into web pages. This could potentially allow them ...
6.4
WordPress Chatbot Plugin Allows Malicious Scripts to Run on Posts
CVE-2026-0736
The Chatbot for WordPress plugin, used to add chat functionality to websites, has a security flaw that lets attackers inject malicious code into posts. This could allow them to run scripts on your sit...
6.4
MasterStudy LMS Plugin Allows Attackers to Inject Malicious Code
CVE-2026-0559
The MasterStudy LMS WordPress Plugin for creating online courses is vulnerable to a security flaw that lets attackers inject malicious code into pages, potentially allowing them to take control of a s...
6.4
WP Data Access plugin for WordPress allows attackers to inject malicious scripts
CVE-2026-0557
The WP Data Access plugin for WordPress is affected by a security flaw that could allow attackers with contributor-level access to inject malicious scripts into pages. This could happen when a user vi...
6.4