Intrudify research
Security Advisories
Vulnerabilities found by our autonomous pentesting engine in software other people depend on. Each one was validated by hand with a working exploit, reported to the vendor under coordinated disclosure, fixed, and assigned a CVE. These pages carry the analysis behind the database record: the root cause, the chain, and what the class of bug generalises to.
20 Published CVEs
500 Plugins scanned
4.7 million+ Active installs covered
- 7 High
- 13 Medium
| Advisory | |||||
|---|---|---|---|---|---|
| CVE-2026-97287 | Routing around a working whitelist in Event Tickets Event Tickets | SQL injection CWE-89 | 90,000+ | High 8.5 | |
| CVE-2026-97293 | Injecting past the closing parenthesis in Media Library Assistant Media Library Assistant | SQL injection CWE-89 | 70,000+ | High 8.5 | |
| CVE-2026-94487 | A nonce check that fails open in PublishPress Capabilities PublishPress Capabilities | Cross-site request forgery CWE-352 | 100,000+ | High 8.1 | |
| CVE-2026-94123 | Unauthenticated arbitrary file read in NextGEN Gallery NextGEN Gallery | Path traversal CWE-22 | 400,000+ | High 7.5 | |
| CVE-2026-94178 | Subscriber to administrator through a CSV batch resume Import and export users and customers | Privilege escalation CWE-266 | 70,000+ | High 7.5 | |
| CVE-2026-93770 | One unescaped anchor, and a way to reach it in WP Statistics WP Statistics | Cross-site scripting CWE-79 | 600,000+ | High 7.1 | |
| CVE-2026-94078 | Unauthenticated stored XSS in Site Reviews Site Reviews | Cross-site scripting CWE-79 | 60,000+ | High 7.1 | |
| CVE-2026-97067 | Turning a working allowlist into a wildcard in EWWW Image Optimizer EWWW Image Optimizer | Cross-site scripting CWE-79 | 1,000,000+ | Medium 6.5 | |
| CVE-2026-97279 | Choosing both the placeholder and its replacement in Polylang Polylang | Cross-site scripting CWE-79 | 800,000+ | Medium 6.5 | |
| CVE-2026-94168 | Zero-click stored XSS in Premium Addons for Elementor Premium Addons | Cross-site scripting CWE-79 | 600,000+ | Medium 6.5 | |
| CVE-2026-95530 | Subscriber to administrator in PixelYourSite PixelYourSite | Cross-site scripting CWE-79 | 500,000+ | Medium 6.5 | |
| CVE-2026-94680 | Stored XSS in The Post Grid via an unvalidated shortcode ID The Post Grid | Cross-site scripting CWE-79 | 100,000+ | Medium 6.5 | |
| CVE-2026-96834 | Claiming an email you do not own in GiveWP GiveWP | Missing authorization CWE-862 | 100,000+ | Medium 6.5 | |
| CVE-2026-94674 | Breaking out of the data layer in Pixel Manager for WooCommerce Pixel Manager for WooCommerce | Cross-site scripting CWE-79 | 50,000+ | Medium 6.5 | |
| CVE-2026-97262 | Letting the client decide whether to check permissions Visual Composer Website Builder | Cross-site scripting CWE-79 | 40,000+ | Medium 6.5 | |
| CVE-2026-97266 | A style attribute inside a class attribute in Virtue Toolkit Virtue/Ascend/Pinnacle Toolkit | Cross-site scripting CWE-79 | 40,000+ | Medium 6.5 | |
| CVE-2026-94461 | Stored XSS in the Ditty WordPress plugin Ditty | Cross-site scripting CWE-79 | 30,000+ | Medium 6.5 | |
| CVE-2026-97301 | Escaping the value and printing the key in Cool FormKit Lite Cool FormKit Lite | Cross-site scripting CWE-79 | 20,000+ | Medium 6.5 | |
| CVE-2026-97298 | Three call sites escaped, two not, in King Addons for Elementor King Addons for Elementor | Cross-site scripting CWE-79 | 10,000+ | Medium 6.5 | |
| CVE-2026-102399 | The twenty-sixth action in Photo Gallery by Supsystic Photo Gallery by Supsystic | Cross-site request forgery CWE-352 | 20,000+ | Medium 5.4 |
Reporting a vulnerability in Intrudify's own systems? See our security policy.