Intrudify research

Security Advisories

Vulnerabilities found by our autonomous pentesting engine in software other people depend on. Each one was validated by hand with a working exploit, reported to the vendor under coordinated disclosure, fixed, and assigned a CVE. These pages carry the analysis behind the database record: the root cause, the chain, and what the class of bug generalises to.

20 Published CVEs
500 Plugins scanned
4.7 million+ Active installs covered
  • 7 High
  • 13 Medium
Published CVEs found by Intrudify. Sortable by CVE, weakness class, active installs, disclosure date and severity.
Advisory
CVE-2026-97287 Routing around a working whitelist in Event Tickets Event Tickets SQL injection CWE-89 90,000+ High 8.5
CVE-2026-97293 Injecting past the closing parenthesis in Media Library Assistant Media Library Assistant SQL injection CWE-89 70,000+ High 8.5
CVE-2026-94487 A nonce check that fails open in PublishPress Capabilities PublishPress Capabilities Cross-site request forgery CWE-352 100,000+ High 8.1
CVE-2026-94123 Unauthenticated arbitrary file read in NextGEN Gallery NextGEN Gallery Path traversal CWE-22 400,000+ High 7.5
CVE-2026-94178 Subscriber to administrator through a CSV batch resume Import and export users and customers Privilege escalation CWE-266 70,000+ High 7.5
CVE-2026-93770 One unescaped anchor, and a way to reach it in WP Statistics WP Statistics Cross-site scripting CWE-79 600,000+ High 7.1
CVE-2026-94078 Unauthenticated stored XSS in Site Reviews Site Reviews Cross-site scripting CWE-79 60,000+ High 7.1
CVE-2026-97067 Turning a working allowlist into a wildcard in EWWW Image Optimizer EWWW Image Optimizer Cross-site scripting CWE-79 1,000,000+ Medium 6.5
CVE-2026-97279 Choosing both the placeholder and its replacement in Polylang Polylang Cross-site scripting CWE-79 800,000+ Medium 6.5
CVE-2026-94168 Zero-click stored XSS in Premium Addons for Elementor Premium Addons Cross-site scripting CWE-79 600,000+ Medium 6.5
CVE-2026-95530 Subscriber to administrator in PixelYourSite PixelYourSite Cross-site scripting CWE-79 500,000+ Medium 6.5
CVE-2026-94680 Stored XSS in The Post Grid via an unvalidated shortcode ID The Post Grid Cross-site scripting CWE-79 100,000+ Medium 6.5
CVE-2026-96834 Claiming an email you do not own in GiveWP GiveWP Missing authorization CWE-862 100,000+ Medium 6.5
CVE-2026-94674 Breaking out of the data layer in Pixel Manager for WooCommerce Pixel Manager for WooCommerce Cross-site scripting CWE-79 50,000+ Medium 6.5
CVE-2026-97262 Letting the client decide whether to check permissions Visual Composer Website Builder Cross-site scripting CWE-79 40,000+ Medium 6.5
CVE-2026-97266 A style attribute inside a class attribute in Virtue Toolkit Virtue/Ascend/Pinnacle Toolkit Cross-site scripting CWE-79 40,000+ Medium 6.5
CVE-2026-94461 Stored XSS in the Ditty WordPress plugin Ditty Cross-site scripting CWE-79 30,000+ Medium 6.5
CVE-2026-97301 Escaping the value and printing the key in Cool FormKit Lite Cool FormKit Lite Cross-site scripting CWE-79 20,000+ Medium 6.5
CVE-2026-97298 Three call sites escaped, two not, in King Addons for Elementor King Addons for Elementor Cross-site scripting CWE-79 10,000+ Medium 6.5
CVE-2026-102399 The twenty-sixth action in Photo Gallery by Supsystic Photo Gallery by Supsystic Cross-site request forgery CWE-352 20,000+ Medium 5.4

Reporting a vulnerability in Intrudify's own systems? See our security policy.

Join the Future of
AI-Driven Pentesting