Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 21 March 2026
RSS132 vulnerabilities published on 21 March 2026
Severity:
WordPress rexCrawler Plugin Allows Unauthenticated Script Injection
CVE-2026-2277
The WordPress rexCrawler plugin has a security flaw that allows attackers to inject malicious code into a website. This could happen if an administrator clicks on a link sent by an attacker, potential...
6.1
Comment Genius plugin for WordPress allows malicious scripts to be injected
CVE-2026-1647
The Comment Genius plugin for WordPress is not properly protecting against malicious code. This means that an attacker could trick a user into clicking on a link, allowing them to inject malicious scr...
6.1
WP-WebAuthn plugin for WordPress: Unauthenticated Attackers Can Inject Scripts
CVE-2025-13910
The WP-WebAuthn plugin for WordPress has a security flaw that allows attackers to inject malicious code into the plugin's log page, which will run when users view the log. This can happen even if you'...
6.1
iTracker360 Plugin for WordPress: Malicious Scripts Injected via Administrator Action
CVE-2026-3572
The iTracker360 plugin for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts if an administrator clicks on a link. This can happen if the plugin is version 2...
6.1
OpenClaw Control UI Pairing Bypass in Older Versions Allows Unauthorized Access
CVE-2026-32057
Older OpenClaw versions lack proper authentication checks for the Control UI pairing process, allowing a malicious user to gain unauthorized access to certain functions. This affects any organization ...
6.0
OpenClaw: Trusted Network Attackers Can Bypass Passwords on HTTP Gateway
CVE-2026-32045
Old versions of OpenClaw have a security mistake that lets attackers on trusted networks access sensitive areas of the HTTP gateway without the usual login requirements. This could let unauthorized pe...
8.2
Discourse: Private Messages Can Be Accessed by Unauthorized Users
CVE-2026-33424
The Discourse discussion platform had a security issue that allowed an attacker to access private messages after being removed from them. This was fixed in recent versions. If you're using an affected...
5.9
ARForms Plugin for WordPress Allows Unauthorized Code Execution
CVE-2024-13785
The ARForms plugin for WordPress allows attackers to execute arbitrary code without a password. This means that a hacker could potentially gain control of your website. Update the plugin to the latest...
5.6
WordPress Multi Functional Flexi Lightbox plugin allows hackers to inject malicious scripts
CVE-2026-3347
An attacker with Admin access can inject malicious scripts into WordPress pages or posts, which can be executed when users visit. This is a serious issue because it can be used to steal user data, ste...
5.5
OpenClaw tar.bz2 Installer Allows Malicious Archive Installation
CVE-2026-32044
Older versions of OpenClaw's tar.bz2 installer can be tricked into installing malicious files, potentially causing a local denial of service during installation. This affects OpenClaw versions prior t...
6.7
AVideo Scheduler Plugin Allows Internal Network Access
GHSA-v467-g7g7-hhfh
CVE-2026-33237
A security issue in the Scheduler plugin in AVideo allows administrators to access internal network services, potentially exposing sensitive data. This can happen when a scheduled task is configured w...
5.5
OpenClaw ACP Client Allows Unauthorized Access to Sensitive Data
CVE-2026-32898
Old versions of OpenClaw's ACP client don't properly check who is making requests, allowing attackers to access sensitive data without being authorized. This is a significant concern because it can le...
5.3
Slack's OpenClaw Fails to Authenticate System Event Senders, Allows Unauthorized Messages
CVE-2026-32895
OpenClaw, a Slack app, has a security issue that allows unauthorized users to send messages to direct messages and channels through system events. This means that attackers can bypass the usual securi...
5.3
Speedup Optimization Plugin for WordPress Can Be Hacked by Authorized Users
CVE-2026-4127
The Speedup Optimization plugin for WordPress is vulnerable to unauthorized actions by users with Subscriber-level access and above. This means that attackers can enable or disable the plugin's optimi...
5.3
Build App Online plugin for WordPress allows unauthorized post modifications
CVE-2026-3651
The Build App Online plugin for WordPress has a security issue that allows attackers to modify posts without permission. This could cause legitimate authors to lose ownership of their posts or allow a...
5.3
Punnel WordPress Plugin Exposes API Key, Allows Attackers to Create or Delete Content
CVE-2026-3645
The Punnel WordPress plugin for creating landing pages has a security flaw that lets attackers with basic access levels change the plugin's settings, including its API key. This can let attackers crea...
5.3
WordPress Appmax plugin allows attackers to manipulate orders and products
CVE-2026-3641
The Appmax WordPress plugin has a security flaw that lets hackers change order and product details. This plugin, used with WooCommerce, allows anyone to send fake requests that can create or alter ord...
5.3
Smarter Analytics plugin for WordPress allows unauthorized configuration changes
CVE-2026-3570
The Smarter Analytics plugin for WordPress is affected. If left unpatched, attackers can reset the plugin's configuration and delete analytics settings for all pages and posts without needing a passwo...
5.3
e-shot Form Builder Plugin Exposes Sensitive Info to All Authenticated Users
CVE-2026-3546
The e-shot form builder plugin for WordPress is vulnerable to unauthorized access to sensitive information. If an attacker is logged in with a subscriber account or above, they can extract the e-shot ...
5.3
WP-Chatbot for Messenger plugin authorization bypass in all versions up to 4.9
CVE-2026-3506
The WP-Chatbot for Messenger plugin has a bug that lets anyone change sensitive settings without logging in. This could allow hackers to take control of your chatbot and redirect conversations to thei...
5.3
WordPress REST API TO MiniProgram plugin allows attackers to modify user data
CVE-2026-3460
The REST API TO MiniProgram plugin for WordPress is vulnerable to an attack where an authenticated user, with a Subscriber-level account or higher, can modify arbitrary user data, such as store names ...
5.3
Canto Plugin for WordPress: Unauthorized File Uploads Possible
CVE-2026-3335
A weakness in the Canto WordPress plugin allows unauthenticated attackers to upload any file type, which could be used to spread malware or disrupt the site. This affects all versions of the plugin up...
5.3
AtomChat WordPress Plugin: Authenticated Users Can Change Settings
CVE-2026-1253
The AtomChat WordPress plugin is affected by a security issue that allows users with Subscriber-level access or higher to change sensitive settings, like API keys and authentication keys, without perm...
5.3
OpenClaw Browser Container Sandbox Bypass Exposes Host System to Attackers
CVE-2026-32046
Old versions of OpenClaw's browser container have a security weakness that allows hackers to run malicious code on your computer without needing to break out of the browser's sandbox. This can happen ...
4.8
RepairBuddy Plugin Allows Unauthorized Access to Admin Settings
CVE-2026-3567
The RepairBuddy plugin for WordPress has a security flaw that allows any authenticated user to change important settings. This is because the plugin doesn't properly check user permissions for making ...
5.3