Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 21 March 2026
RSS132 vulnerabilities published on 21 March 2026
Severity:
Twitter Feeds plugin for WordPress allows attackers to inject malicious scripts
CVE-2026-1911
Attackers with WordPress Contributor-level access can inject malicious scripts into pages containing Twitter feeds. This can happen when a user views a page with an injected script. To fix this, updat...
6.4
Hubspot Forms Plugin for WordPress: Malicious Code Injection
CVE-2026-1908
The Hubspot Forms plugin for WordPress allows attackers with high-level access to inject malicious code into pages, which can harm users when accessed. This affects all versions up to 1.2.2. Update to...
6.4
Any Post Slider plugin for WordPress: Stored Cross-Site Scripting
CVE-2026-1899
The Any Post Slider plugin for WordPress versions up to 1.0.4 has a security flaw that could allow attackers to inject malicious code into websites. If an attacker with Contributor-level access or abo...
6.4
Simple Football Scoreboard plugin allows attackers to inject malicious scripts
CVE-2026-1891
The Simple Football Scoreboard plugin for WordPress is at risk because an attacker with sufficient access can inject malicious code into pages, which can be triggered when users visit those pages. Thi...
6.4
Outgrow Plugin for WordPress: Malicious Scripts Can Be Injected
CVE-2026-1889
The Outgrow plugin for WordPress has a security flaw that allows attackers with contributor-level access or higher to inject malicious scripts into web pages. This can happen when a user accesses a pa...
6.4
Go Night Pro Plugin for WordPress allows attackers to inject malicious scripts
CVE-2026-1886
The Go Night Pro plugin for WordPress has a security weakness that lets attackers inject malicious code into web pages. This could allow them to take control of a website and steal sensitive informati...
6.4
WordPress Post Flagger Plugin Allows Malicious Code Injection
CVE-2026-1854
The Post Flagger plugin for WordPress can be exploited by authorized users with contributor-level access to inject malicious code into pages that will execute when visited, potentially allowing attack...
6.4
iVysilani Shortcode Plugin for WordPress Allows Malicious Scripts to Run
CVE-2026-1851
The iVysilani Shortcode plugin for WordPress has a security weakness that allows attackers to inject malicious code into pages. This can happen if an authenticated user with contributor-level access o...
6.4
WP NG Weather plugin for WordPress allows attackers to inject malicious scripts
CVE-2026-1822
The WP NG Weather plugin for WordPress is installed on many sites. If an attacker with contributor-level access or higher injects malicious code, it can execute on any page viewed by a user, potential...
6.4
WordPress TourCMS Plugin: Malicious Script Injection via Shortcode
CVE-2026-1806
An attacker with contributor-level access can inject malicious scripts into pages, which will be executed when users visit those pages. This affects all versions of the Tour & Activity Operator Plugin...
6.4
Schema Shortcode plugin for WordPress allows attackers to inject malicious code
CVE-2026-1575
The Schema Shortcode plugin for WordPress has a security flaw that allows attackers with contributor-level access or higher to inject malicious code into pages. This could lead to unexpected behavior ...
6.4
WordPress Plugin Allows Attackers to Inject Malicious Code
CVE-2026-1397
A security issue in the PQ Addons – Creative Elementor Widgets plugin for WordPress allows authenticated attackers to inject malicious code into web pages, which can be executed when a user visits the...
6.4
WordPress Multi Post Carousel plugin allows attackers to inject malicious scripts
CVE-2026-1275
The Multi Post Carousel plugin for WordPress is affected by a security weakness that could allow attackers to inject malicious code into pages. This could happen if an authorized user with contributor...
6.4
WPFAQBlock plugin for WordPress allows attackers to inject malicious scripts
CVE-2026-1093
The WPFAQBlock plugin for WordPress is vulnerable to a security threat that allows attackers to inject malicious scripts into website pages. This could happen if an attacker with Contributor-level acc...
6.4
WordPress Logo Slider Plugin Allows Malicious Code Injection
CVE-2026-0609
The Logo Slider WordPress plugin is affected by a security issue that lets attackers inject malicious code into websites. This can happen when an administrator or higher-level user adds an image with ...
6.4
OpenClaw versions prior to 2026.2.24 allow hackers to run secret commands
CVE-2026-32052
Some versions of OpenClaw are vulnerable to a security risk that lets hackers trick the system into running hidden commands. This can happen when the system is told to run a command from a misleading ...
5.8
Scoreboard for HTML5 Games Lite plugin allows malicious scripts to run on WordPress sites
CVE-2026-4083
The Scoreboard for HTML5 Games Lite plugin for WordPress has a security flaw that allows attackers with admin access to inject malicious code into web pages. This could allow them to take control of a...
6.4
Contact List plugin for WordPress: Malicious scripts can be injected via Google Maps field
CVE-2026-3516
The Contact List plugin for WordPress is at risk because an attacker with contributor-level access can inject malicious scripts into the plugin's Google Maps field. This could allow the attacker to ta...
6.4
Image Alt Text Manager plugin for WordPress allows attackers to inject malicious scripts into posts
CVE-2026-3350
The Image Alt Text Manager plugin for WordPress is vulnerable to a security risk that allows attackers to inject malicious scripts into posts. This could allow an attacker to take control of a website...
6.4
Autoptimize Plugin for WordPress Can Allow Malicious Code Injection
CVE-2026-2430
The Autoptimize plugin for WordPress has a security flaw that allows attackers to inject malicious code into web pages. This can happen if a user with sufficient access rights edits a page with an ima...
6.4
Autoptimize plugin for WordPress allows attackers to inject malicious scripts
CVE-2026-2352
The Autoptimize plugin for WordPress is vulnerable to a security threat that could allow attackers to inject malicious code into a website. This means that if an attacker has permission to edit the we...
6.4
PbootCMS File Upload Flaw Allows Remote Attackers to Upload Files
CVE-2026-4509
PbootCMS versions up to 3.2.12 contain a security flaw in their file upload system. This means that a hacker could potentially upload malicious files to your website, which could lead to unauthorized ...
5.3
Alfie – Feed Plugin for WordPress: Malicious Code Injection
CVE-2026-4069
The Alfie – Feed Plugin for WordPress is vulnerable to a security threat that allows hackers to inject malicious code into the plugin's database. This code can be triggered when an administrator click...
6.1
WordPress Post Snippits Plugin Allows Unauthenticated Settings Changes
CVE-2026-2723
The Post Snippits WordPress plugin is at risk because an attacker could trick an administrator into clicking a link, allowing them to change plugin settings and inject malicious scripts. This affects ...
6.1
Itsukaita Plugin for WordPress Can Execute Malicious Code
CVE-2026-2427
The Itsukaita plugin for WordPress has a security flaw that allows hackers to inject malicious code into the plugin. This could happen if an administrator clicks on a link sent by the hacker. To stay ...
6.1