Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 14 February 2026
RSS218 vulnerabilities published on 14 February 2026
Severity:
Citations Tools Plugin for WordPress Can Be Hacked Through User-Submitted Code
CVE-2026-1912
The Citations Tools plugin for WordPress is not properly checking code entered by users. This means that attackers could inject malicious code into pages, which could be triggered when a user visits t...
6.4
Simple Wp Colorfull Accordion Plugin Allows Malicious Scripts on WordPress Sites
CVE-2026-1904
The Simple Wp Colorfull Accordion plugin for WordPress has a security flaw that lets attackers inject malicious code into pages. This can happen when an attacker with contributor or higher access edit...
6.4
StyleBidet WordPress Plugin: Malicious Scripts Can Execute via URL
CVE-2026-1796
The StyleBidet WordPress plugin is vulnerable to a security flaw that allows attackers to inject malicious scripts into a website. This can happen if a user clicks on a link or visits a specific URL. ...
6.1
WordPress Address Bar Ads Plugin Allows Hackers to Inject Malware via Links
CVE-2026-1795
The Address Bar Ads plugin for WordPress is not properly filtering links, which means hackers can inject malicious code into websites. If a user clicks on a manipulated link, their computer could be i...
6.1
Geo Widget plugin for WordPress allows malicious code injection via URLs
CVE-2026-1792
Malicious code can be injected into WordPress sites using the Geo Widget plugin if all users visit a specially crafted URL. This could allow an attacker to steal sensitive information or take control ...
6.1
WordPress Personal Authors Category Plugin Allows Malicious Website Attacks
CVE-2026-1754
The Personal Authors Category plugin for WordPress has a security weakness that allows hackers to inject malicious code into websites. This means that visitors to the site may be tricked into performi...
6.1
Easy Voice Mail Plugin for WordPress Allows Attackers to Inject Malicious Scripts
CVE-2026-1164
An attacker with administrator access can inject malicious scripts into the WordPress site. This can happen when an administrator or user views a manipulated voice message. To fix, update the Easy Voi...
6.1
WordPress Scheduler Widget Plugin Allows Event Hijacking
CVE-2026-1987
The Scheduler Widget plugin for WordPress has a security flaw that allows hackers to take control of events. This means that attackers can modify or delete any event, even if they aren't the owner. Up...
5.4
Unauthorized access to file metadata in Accordion and Accordion Slider plugin
CVE-2026-0727
The Accordion and Accordion Slider plugin for WordPress, in versions 1.4.5 and earlier, allows attackers with contributor-level access to read and modify file metadata, including file paths and captio...
5.4
CallbackKiller Plugin Allows Unauthorized Site Settings Changes
CVE-2026-1944
The CallbackKiller plugin for WordPress can be exploited by attackers to change site settings without permission. This is because the plugin's security check was overlooked in earlier versions, making...
5.3
MailChimp Campaigns plugin for WordPress allows attackers to break email campaigns
CVE-2026-1303
A security issue in the MailChimp Campaigns plugin for WordPress lets attackers with Subscriber-level access or higher disconnect a website from its MailChimp integration, disrupting automated email c...
5.3
Unauthorized access to private chat messages in WPGuppy plugin
CVE-2025-6792
The WPGuppy plugin for WordPress allows unauthorized users to view private chat messages. This is because the plugin doesn't properly check who is making requests to its internal API. To fix this, upd...
5.3
WordPress Bookr Plugin Allows Hackers to Change Appointment Status
CVE-2026-1932
A security issue in the Bookr plugin for WordPress allows unauthorized users to change the status of appointments. This means that anyone can modify the status of any appointment, which could lead to ...
5.3
WP Last Modified Info plugin allows attackers to modify post metadata
CVE-2025-14608
The WP Last Modified Info plugin for WordPress is insecure, allowing an attacker with Author-level access to modify the last modified date of any post, including those created by Administrators. This ...
5.3
Easy Form Builder plugin for WordPress allows unauthorized data access
CVE-2025-14067
The Easy Form Builder plugin for WordPress contains a security flaw that lets attackers access sensitive user data, such as form responses and personal info, even if they don't have permission to do s...
5.3
StickEasy Protected Contact Form plugin leaks contact form data for 1.0.2 and earlier
CVE-2025-13973
An outdated version of the StickEasy Protected Contact Form plugin for WordPress stores sensitive information in a publicly accessible file. This means that anyone can download the file and see visito...
5.3
Sonaar WordPress Plugin Allows Attackers to Access Internal Services
CVE-2026-1249
The Sonaar WordPress plugin for music players has a security flaw that lets attackers with special permissions access sensitive information on your website. This could allow them to see or change data...
5.0
Mail Mint Plugin Vulnerable to Attackers with Admin Access
CVE-2026-1258
The Mail Mint plugin for WordPress is open to attacks by attackers with administrator access. If an attacker with admin rights uses the plugin's API, they can potentially inject malicious SQL code, le...
4.9
WordPress BFG Tools Extension Zipper Plugin Allows File Access
CVE-2025-13681
The BFG Tools – Extension Zipper plugin for WordPress has a security flaw that lets an attacker with administrator access read sensitive files. This can happen if an attacker knows the plugin's intern...
4.9
WordPress User Language Switch Plugin Allows Attackers to Inject Malicious Code
CVE-2026-0735
The User Language Switch plugin for WordPress has a security flaw that lets attackers with administrator access inject malicious code into pages. This only affects WordPress sites with multiple langua...
4.4
WordPress Allow HTML in Category Descriptions Plugin Allows Malicious Code in Category Descriptions
CVE-2026-0693
An attacker with admin-level access can inject malicious code into category descriptions, which can affect users who view those categories. This only applies to multi-site WordPress installations wher...
4.4
WordPress Link Hopper Plugin Allows Hackers to Inject Malicious Code
CVE-2025-15483
A security issue in the Link Hopper plugin for WordPress allows hackers to inject malicious code into sites running the plugin. This can happen if an attacker has administrator-level access and can ex...
4.4
WordPress AMP Plugin Allows Attackers to Inject Malicious Code
CVE-2026-2027
The WordPress AMP Plugin allows attackers to inject malicious code into web pages if they have Administrator-level access. This only happens on multi-site WordPress installations where certain securit...
4.4
WordPress Media Library Folders Plugin Allows Deleting Others' Files
CVE-2026-2312
An attacker with Author-level access or higher can delete or rename attachments owned by other users, including administrators, which can result in data loss. This affects all versions of the Media Li...
4.3
Modula Image Gallery plugin allows attackers to modify any WordPress post
CVE-2026-1254
The Modula Image Gallery plugin for WordPress has a security issue that allows authorized users to update posts they shouldn't be able to edit. This means users with contributor level access or higher...
4.3