Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 21 March 2026

RSS

152 vulnerabilities published on 21 March 2026

Severity:
RepairBuddy Plugin Allows Unauthorized Access to Admin Settings
CVE-2026-3567
The RepairBuddy plugin for WordPress has a security flaw that allows any authenticated user to change important settings. This is because the plugin doesn't properly check user permissions for making ...
5.3
EmailKit Plugin for WordPress Allows Attackers to Read Server Files
CVE-2026-3474
A security flaw in the EmailKit plugin for WordPress allows attackers with Administrator-level access to read sensitive files on the server, such as passwords and configuration settings. This is due t...
4.9
Discourse: Users with elevated permissions can see deleted posts
CVE-2026-33428
Non-staff users with extra privileges can view posts that have been deleted by others. This affects users of certain Discourse versions and can be fixed by updating to a patched version.
4.9
OpenClaw BlueBubbles Webhook Bypass in Older Versions
CVE-2026-32896
Versions of OpenClaw's BlueBubbles plugin before 2026.2.21 have a security flaw that allows attackers to send fake messages without logging in. This can happen when the plugin is set up behind certain...
6.3
OpenClaw Approval Bypass Vulnerability Allows Unexpected Command Execution
CVE-2026-32065
Old versions of OpenClaw may allow a malicious user to trick an approver into running a different command than what they thought they approved. This could happen if the attacker can influence the comm...
5.7
Stored Cross-Site Scripting in RevuKangaroo Plugin for WordPress
CVE-2026-4161
The Review Map by RevuKangaroo plugin for WordPress has a security flaw that allows attackers to inject malicious code into website pages. This can happen when an administrator with elevated access ed...
4.4
Wikilookup plugin for WordPress allows attackers to inject malicious code
CVE-2026-3354
An attacker with admin access can inject malicious code into a WordPress site's pages, potentially allowing them to take control of the site. To fix this, update the Wikilookup plugin to a version hig...
4.4
Comment SPAM Wiper plugin exposes WordPress sites to malicious scripts
CVE-2026-3353
The Comment SPAM Wiper plugin for WordPress has a security issue that could allow an attacker with high-level access to inject malicious code into your site. This affects multi-site installations or s...
4.4
Ricerca Search Plugin Allows Attackers to Inject Scripts on WordPress Sites
CVE-2026-2837
The Ricerca search plugin for WordPress has a security flaw that allows attackers to inject malicious scripts into certain pages on affected sites. This can happen if an attacker has administrator-lev...
4.4
Reward Video Ad Plugin for WordPress: Unauthorized Code Injection Risk
CVE-2026-2424
The Reward Video Ad plugin for WordPress fails to properly filter user input, allowing attackers with Administrator-level access to inject code into web pages. This could lead to unauthorized actions ...
4.4
Weaver Show Posts plugin for WordPress: Malicious scripts can be injected into pages
CVE-2026-2121
The Weaver Show Posts plugin for WordPress has a security flaw that allows attackers with Administrator-level access to inject malicious scripts into pages. This can happen when an administrator adds ...
4.4
Mandatory Field WordPress Plugin Allows Attackers to Inject Malicious Code
CVE-2026-1278
The Mandatory Field plugin for WordPress can be exploited by attackers with admin-level permissions to inject malicious code into pages, which can be executed when users access them. This affects mult...
4.4
WordPress Survey Plugin Allows Attackers to Inject Malicious Scripts
CVE-2026-1247
A security flaw in the Survey plugin for WordPress (all versions up to 1.1) allows attackers with admin permissions to inject malicious code on certain pages, potentially affecting multi-site installa...
4.4
Keep Backup Daily plugin allows attackers to inject malicious scripts in WordPress backup titles
CVE-2026-3577
The Keep Backup Daily plugin for WordPress is vulnerable to a type of attack that allows an attacker to inject malicious code into backup titles. This can happen if an attacker has Administrator-level...
4.4
PbootCMS Cross-Site Scripting Risk Through Malicious Redirects
CVE-2026-4510
Attackers can inject malicious code into PbootCMS versions up to 3.2.12, potentially taking control of user sessions or stealing sensitive information. This could happen if a user clicks on a maliciou...
5.3
Fakturama Plugin for WordPress Allows Malicious Settings Changes
CVE-2026-4143
The Fakturama plugin for WordPress can be tricked into changing its settings by an attacker. This can happen if a site administrator clicks on a malicious link. Update to the latest version to fix the...
4.3
Xhanch - My Advanced Settings plugin allows unauthorized settings changes
CVE-2026-3332
The Xhanch - My Advanced Settings plugin for WordPress has a security flaw that lets attackers change settings without permission. This could happen if an administrator clicks on a malicious link. We ...
4.3
Lobot Slider Administrator plugin for WordPress allows unauthorized menu changes
CVE-2026-3331
The Lobot Slider Administrator plugin for WordPress is not properly securing its settings page, allowing attackers to trick an administrator into changing the plugin's configuration without their know...
4.3
Unauthorized Changes to WordPress Plugin Settings
CVE-2026-2294
The UiPress lite plugin for WordPress is vulnerable to unauthorized changes to its settings by users with Subscriber-level access or higher. This means that an attacker could alter the plugin's settin...
4.3
WordPress LinkedIn Plugin Allows Authorized Users to Delete LinkedIn Data
CVE-2026-1935
An issue in the LinkedIn plugin for WordPress allows users with Subscriber-level access and above to delete LinkedIn post data. This data is stored in the site's options table. Affected users should u...
4.3
WordPress Login Register Plugin Allows Hackers to Inject Malicious Code
CVE-2026-1503
The WordPress Login Register plugin has a security weakness that could let hackers inject malicious code into your website. This could happen if an administrator clicks on a fake link sent by the hack...
4.3
Add Google Social Profiles to Knowledge Graph Box plugin may let attackers change settings
CVE-2026-1393
The Add Google Social Profiles to Knowledge Graph Box plugin for WordPress is at risk because of a security weakness. This means an attacker could trick a site administrator into making changes to the...
4.3
SR WP Minify HTML plugin settings can be changed by attackers
CVE-2026-1392
The SR WP Minify HTML plugin for WordPress is not secure, allowing attackers to trick site administrators into changing plugin settings. This can happen through a fake link or email, and can lead to u...
4.3
Redirect Countdown Plugin for WordPress Allows Unauthenticated Setting Changes
CVE-2026-1390
The Redirect Countdown plugin for WordPress is vulnerable to attacks that can let hackers change plugin settings without permission. This could allow them to change the countdown timer, where it redir...
4.3
WP Posts Re-order plugin for WordPress allows attackers to change settings
CVE-2026-1378
The WP Posts Re-order plugin for WordPress is not secure. An attacker could trick a site administrator into clicking a link, allowing them to change important settings like what posts are displayed an...
4.3