CVEs we hold for Smub
Records whose assigning authority named Smub as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-8832WPCode <= 2.3.5 - Authenticated (Author+) Remote Code Execution via CPT Capability Bypass via XML-RPC wp.newPostsmub WPCode – Insert Headers and Footers + Custom Code…
CVE-2026-8613aThemes Addons for Elementor <= 1.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Widget…smub aThemes Addons for Elementor
CVE-2026-84909Custom Twitter Feeds <= 2.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'buttoncolor' Shortcode…smub Custom Twitter Feeds – A Tweets Widget or X Feed Widget
CVE-2026-7792WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook…smub WPForms – Easy Form Builder for WordPress – Contact…
CVE-2026-77189Charitable <= 1.8.12.1 - Authenticated (Contributor+) SQL Injection via 'order' Shortcode Attributesmub Charitable – Donation & Fundraising Platform (Donation…
CVE-2026-7636Slider by Soliloquy <= 2.8.1 - Authenticated (Subscriber+) Information Disclosure via REST API Endpointsmub Slider by Soliloquy – Responsive Image Slider for…
CVE-2026-7619Charitable <= 1.8.10.4 - Authenticated (Custom+) SQL Injection via 's' Search Parametersmub Charitable – Donation Plugin for WordPress –…
CVE-2026-7533Easy Digital Downloads <= 3.6.7 - Cross-Site Request Forgery to Payment Account Hijacking via 'square_tokens' Parametersmub Easy Digital Downloads – eCommerce Payments and…
CVE-2026-7526PDF Embedder <= 4.9.3 - Authenticated (Contributor+) Information Exposure via Block Editor Pagesmub PDF Embedder – PDF Viewer & Embed PDF Files for…
CVE-2026-6566Photo Gallery, Sliders, Proofing and Themes <= 4.2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+)…smub Photo Gallery, Sliders, Proofing and Themes – NextGEN…
CVE-2026-6177Custom Twitter Feeds <= 2.5.4 - Unauthenticated Stored Cross-Site Scripting via Cached Tweet Textsmub Custom Twitter Feeds – A Tweets Widget or X Feed Widget
CVE-2026-5488ExactMetrics <= 9.1.2 - Authenticated (Subscriber+) Missing Authorization to Google Ads Access Token Retrieval via AJAX…smub ExactMetrics – Google Analytics Dashboard for…
CVE-2026-5464ExactMetrics <= 9.1.2 - Authenticated (Editor+) Arbitrary Plugin Installation/Activation via…smub ExactMetrics – Google Analytics Dashboard for…
CVE-2026-5361Envira Gallery <= 1.12.4 - Authenticated (Author+) Stored Cross-Site Scripting via 'arrows' Parametersmub Envira Gallery – Image Photo Gallery, Albums, Video…
CVE-2026-5075All in One SEO <= 4.9.7 - Authenticated (Contributor+) Sensitive Information Exposure via 'internalOptions' Localized…smub All in One SEO – Powerful SEO Plugin to Boost SEO…
CVE-2026-3423Envira Gallery <= 1.12.4 - Authenticated (Author+) Stored Cross-Site Scripting via Gallery Descriptionsmub Envira Gallery – Image Photo Gallery, Albums, Video…
CVE-2026-3177Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.9.7 - Insufficient…smub Charitable – Donation Plugin for WordPress –…
CVE-2026-2471WP Mail Logging <= 1.15.0 - Unauthenticated PHP Object Injection via Email Log Message Fieldsmub WP Mail Logging
CVE-2026-1993ExactMetrics 7.1.0 - 9.0.2 - Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via…smub ExactMetrics – Google Analytics Dashboard for…
CVE-2026-1992ExactMetrics 8.6.0 - 9.0.2 - Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installationsmub ExactMetrics – Google Analytics Dashboard for…
CVE-2026-16775Smash Balloon Social Post Feed <= 4.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode…smub Smash Balloon Social Post Feed – Simple Social Feeds…
CVE-2026-15782WPForms <= 2.0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey…smub WPForms – AI Form Builder for WordPress – Contact…
CVE-2026-15452Smash Balloon Social Photo Feed <= 6.11.3 - Reflected Cross-Site Scripting via REQUEST_URI Query Stringsmub Smash Balloon Social Photo Feed – Easy Social Feeds…
CVE-2026-1463Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery <= 4.0.4 - Authenticated (Author+) Local File Inclusionsmub Photo Gallery, Sliders, Proofing and Themes – NextGEN…
CVE-2026-12476Easy Digital Downloads <= 3.6.9 - Authenticated (Shop Manager+) Arbitrary File Upload via 'edd-import-file' Parametersmub Easy Digital Downloads – eCommerce Payments and…
CVE-2026-1236Envira Gallery for WordPress <= 1.12.3 - Authenticated (Author+) Stored Cross-Site Scripting via…smub Envira Gallery – Image Photo Gallery, Albums, Video…
CVE-2026-12127WPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To…smub WPForms – AI Form Builder for WordPress – Contact…
CVE-2026-12002Smash Balloon Social Photo Feed – Easy Social Feeds Plugin <= 6.11.1 - Cross-Site Request Forgery to oEmbed Access…smub Smash Balloon Social Photo Feed – Easy Social Feeds…
CVE-2026-10038Charitable <= 1.8.11.1 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Attachment Deletion…smub Charitable – Donation Plugin for WordPress –…
CVE-2025-8149aThemes Addons for Elementor Lite <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown…smub aThemes Addons for Elementor
CVE-2025-8102Easy Digital Downloads <= 3.5.0 - Cross-Site Request Forgery to Plugin Deactivation via edd_sendwp_disconnect and…smub Easy Digital Downloads – eCommerce Payments and…
CVE-2025-5275Charitable <= 1.8.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin's Privacy Settingssmub Charitable – Donation Plugin for WordPress –…
CVE-2025-4670Easy Digital Downloads <= 3.3.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via edd_receipt Shortcodesmub Easy Digital Downloads – eCommerce Payments and…
CVE-2025-4577Smash Balloon Custom Facebook Feed <= 4.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via `data-color`…smub Smash Balloon Social Post Feed – Simple Social Feeds…
CVE-2025-3794WPForms Lite <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'start_timestamp' Parametersmub WPForms – Easy Form Builder for WordPress – Contact…
CVE-2025-2892All in One SEO Pack <= 4.8.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta Description and…smub All in One SEO – Powerful SEO Plugin to Boost SEO…
CVE-2025-2252Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 - Unauthenticated Private Post Title…smub Easy Digital Downloads – eCommerce Payments and…
CVE-2025-14783Easy Digital Downloads <= 3.6.2 - Unvalidated Redirect in Password Reset Flow via edd_redirectsmub Easy Digital Downloads – eCommerce Payments and…
CVE-2025-14384All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.9.2 - Missing Authorization to…smub All in One SEO – Powerful SEO Plugin to Boost SEO…
CVE-2025-13641Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery <= 3.59.12 - Authenticated (Contributor+) Local File…smub Photo Gallery, Sliders, Proofing and Themes – NextGEN…
CVE-2025-1314Custom Twitter Feeds <= 2.2.5 - Cross-Site Request Forgery to Cache Reset via ctf_clear_cache_admin Functionsmub Custom Twitter Feeds – A Tweets Widget or X Feed Widget
CVE-2025-12847All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.8.9 - Missing Authorization to…smub All in One SEO – Powerful SEO Plugin to Boost SEO…
CVE-2025-12837aThemes Addons for Elementor <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Call To Action…smub aThemes Addons for Elementor
CVE-2025-12484Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers <= 1.12.19 -…smub Giveaways and Contests by RafflePress – Get More…
CVE-2025-12377Gallery Plugin for WordPress – Envira Photo Gallery <= 1.12.0 - Missing Authorization to Authenticated (Author+)…smub Envira Gallery – Image Photo Gallery, Albums, Video…
CVE-2025-11893Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.8.4 - Authenticated…smub Charitable – Donation Plugin for WordPress –…
CVE-2025-11448Gallery Plugin for WordPress – Envira Photo Gallery <= 1.11.0 - Missing Authorization to Authenticated (Contributor+)…smub Envira Gallery – Image Photo Gallery, Albums, Video…
CVE-2025-11271Easy Digital Download <= 3.5.2 - Insufficient Verification to Order Manipulationsmub Easy Digital Downloads – eCommerce Payments and…
CVE-2025-10694User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.8.0 - Missing Authorization…smub UserFeedback – Create Interactive Feedback Form, User…
CVE-2024-9654Easy Digital Downloads 3.1 - 3.3.4 - Improper Authorization to Paywall Bypasssmub Easy Digital Downloads – eCommerce Payments and…
CVE-2024-8791Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress <= 1.8.1.14 - Insecure Direct…smub Charitable – Donation Plugin for WordPress –…
CVE-2024-8200Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More <= 1.1.2 -…smub Reviews Feed – Add Testimonials and Customer Reviews…
CVE-2024-8199Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More <= 1.1.2 -…smub Reviews Feed – Add Testimonials and Customer Reviews…
CVE-2024-6897aThemes Starter Sites <= 1.0.53 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Uploadsmub aThemes Starter Sites
CVE-2024-6694WP Mail SMTP <= 4.0.1 - Authenticated (Admin+) SMTP Password Exposuresmub WP Mail SMTP by WPForms – The Most Popular SMTP and…
CVE-2024-6692Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 -…smub Easy Digital Downloads – eCommerce Payments and…
CVE-2024-6691Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 -…smub Easy Digital Downloads – eCommerce Payments and…
CVE-2024-6263WP Lightbox 2 <= 3.0.6.6 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scriptingsmub WP Lightbox 2
CVE-2024-6256Feeds for YouTube (YouTube video, channel, and gallery plugin) <= 2.2.1 - Authenticated (Contributor+) DOM-Based Stored…smub Feeds for YouTube (YouTube video, channel, and gallery…
CVE-2024-6210Duplicator <= 1.5.9 - Full Path Disclosuresmub Duplicator – Backups & Migration Plugin – Cloud…
CVE-2024-5902UserFeedback Lite <= 1.0.15 - Unauthenticated Stored Cross-Site Scripting via Name Parametersmub UserFeedback – Create Interactive Feedback Form, User…
CVE-2024-4473Sydney Toolbox <= 1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via aThemes: Portfolio Widgetsmub Sydney Toolbox
CVE-2024-4045Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation <= 2.16.1 -…smub Popup Builder & Popup Maker for WordPress –…
CVE-2024-4036Sydney Toolbox <= 1.30 - Authenticated (Contributor+) Stored Cross-Site Scriptingsmub Sydney Toolbox
CVE-2024-3649Contact Form by WPForms – Drag & Drop Form Builder for WordPress <= 1.8.7.2 - Unauthenticated Price Manipulationsmub WPForms – Easy Form Builder for WordPress – Contact…
CVE-2024-3554All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic <= 4.6.0 - Authenticated…smub All in One SEO – Powerful SEO Plugin to Boost SEO…
CVE-2024-3208Sydney Toolbox <= 1.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallerysmub Sydney Toolbox
CVE-2024-3097WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosuresmub Photo Gallery, Sliders, Proofing and Themes – NextGEN…
CVE-2024-3073Easy WP SMTP by SendLayer <= 2.3.0 - Exposure of Sensitive Information via the UIsmub Easy WP SMTP – WordPress SMTP and Email Logs: Gmail…
CVE-2024-2936Sydney Toolbox <= 1.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via _idsmub Sydney Toolbox
CVE-2024-2302Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.2.9 - Sensitive…smub Easy Digital Downloads – eCommerce Payments and…
CVE-2024-1935Giveaways and Contests by RafflePress <= 1.12.5 - Unauthenticated Stored Cross-Site Scriptingsmub Giveaways and Contests by RafflePress – Get More…
CVE-2024-1447Sydney Toolbox <= 1.25 - Authenticated (Contributor+) Stored Cross-Site Scriptingsmub Sydney Toolbox
CVE-2024-13547aThemes Addons for Elementor <= 1.0.12 - Authenticated (Contributor+) Stored Cross-Site Scriptingsmub aThemes Addons for Elementor
CVE-2024-13517Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 -…smub Easy Digital Downloads – eCommerce Payments and…
CVE-2024-13453Contact Form & SMTP Plugin for WordPress by PirateForms <= 2.6.0 - Unauthenticated Arbitrary Shortcode Executionsmub Contact Form & SMTP Plugin for WordPress by PirateForms
CVE-2024-13403WPForms Lite <= 1.9.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Parametersmub WPForms – Easy Form Builder for WordPress – Contact…
CVE-2024-12875Easy Digital Downloads <= 3.3.2 - Authenticated (Admin+) Arbitrary File Downloadsmub Easy Digital Downloads – eCommerce Payments and…
CVE-2024-11205WPForms 1.8.4 - 1.9.2.1 - Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription…smub WPForms – Easy Form Builder for WordPress – Contact…
CVE-2024-10878Sugar Calendar (Lite) <= 3.3.0 - Reflected Cross-Site Scriptingsmub Sugar Calendar – Events Calendar, Event Tickets, and…
CVE-2024-10876Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.3 - Reflected…smub Charitable – Donation Plugin for WordPress –…
CVE-2024-10593WPForms – Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletionsmub WPForms – Easy Form Builder for WordPress – Contact…
CVE-2024-0903User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.0.13 - Unauthenticated Stored…smub UserFeedback – Create Interactive Feedback Form, User…
CVE-2024-0659Easy Digital Downloads <= 3.2.6 - Authenticated(Shop Manager+) Stored Cross-Site Scripting via variable pricing optionssmub Easy Digital Downloads – eCommerce Payments and…
CVE-2024-0379Custom Twitter Feeds – A Tweets Widget or X Feed Widget <= 2.2.1 - Cross-Site Request Forgery to Plugin Options Updatesmub Custom Twitter Feeds – A Tweets Widget or X Feed Widget
CVE-2023-6742Envira Gallery Lite <= 1.8.7.2 - Missing Authorization to Gallery Modification via envira_gallery_insert_imagessmub Envira Gallery – Image Photo Gallery, Albums, Video…
CVE-2023-5049Giveaways and Contests by RafflePress <= 1.12.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodesmub Giveaways and Contests by RafflePress – Get More…
CVE-2023-4841Feeds for YouTube <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodesmub Feeds for YouTube (YouTube video, channel, and gallery…
CVE-2023-4404Donation Forms by Charitable <= 1.7.0.12 - Unauthenticated Privilege Escalationsmub Charitable – Donation Plugin for WordPress –…
CVE-2023-3081WP Mail Logging <= 1.11.1 - Unauthenticated Stored Cross-Site Scripting via Emailsmub WP Mail Logging
CVE-2023-0586All in One SEO Pack <= 4.2.9 - Authenticated (Contributor+) Stored Cross-Site Scriptingsmub All in One SEO – Powerful SEO Plugin to Boost SEO…
CVE-2023-0585All in One SEO Pack <= 4.2.9 - Authenticated (Administrator+) Stored Cross-Site Scriptingsmub All in One SEO – Powerful SEO Plugin to Boost SEO…
CVE-2022-2439Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 3.3.3 - Authenticated (Admin+) PHAR…smub Easy Digital Downloads – eCommerce Payments and…
CVE-2019-25145Contact Form & SMTP Plugin by PirateForms <= 2.5.1 - Unauthenticated HTML injectionsmub Contact Form & SMTP Plugin for WordPress by PirateForms
CVE-2019-25141Easy WP SMTP <= 1.3.9 - Missing Authorization to Arbitrary Options Updatesmub Easy WP SMTP – WordPress SMTP and Email Logs: Gmail…
96 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.