Bonds

15
All Time Ranking
448
All Time Discoveries
0
90 Day Published Submissions
N/A
Last Published Submission

Showing 1-20 of 448 Vulnerabilities

Title CVE ID CVSS Vector Date
777 <= 1.13.0 - Unauthenticated PHP Object Injection CVE-2026-57738 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H July 9, 2026
Flatsome <= 3.20.5 - Reflected Cross-Site Scripting CVE-2026-57728 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N July 6, 2026
Flatsome <= 3.20.5 - Missing Authorization CVE-2026-57729 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N July 6, 2026
RT-Theme 18 Responsive WordPress Theme <= 2.5 - Reflected Cross-Site Scripting CVE-2026-57745 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N July 6, 2026
RT-Theme 18 Responsive WordPress Theme <= 2.5 - Unauthenticated PHP Object Injection CVE-2026-57744 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H July 6, 2026
RT-Theme 18 Responsive WordPress Theme <= 2.5 - Unauthenticated Local File Inclusion CVE-2026-57743 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H July 6, 2026
Flatsome <= 3.20.5 - Missing Authorization CVE-2026-57731 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N July 1, 2026
Flatsome <= 3.20.5 - Missing Authorization CVE-2026-57730 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N July 1, 2026
Corpkit - Business Consulting WordPress Theme <= 1.0.5 - Authenticated (Subscriber+) Sensitive Information Exopsure CVE-2025-69132 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N June 30, 2026
Unicamp - University and College WordPress Theme <= 2.2.2 - Authenticated (Subscriber+) SQL Injection CVE-2025-69094 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N June 29, 2026
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.8 - Unauthenticated Stored Cross-Site Scripting CVE-2026-57320 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N June 29, 2026
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments <= 4.3.2 - Reflected Cross-Site Scripting CVE-2026-57314 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N June 26, 2026
Eagle Booking <= 1.3.4.3 - Cross-Site Request Forgery CVE-2025-68052 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N June 26, 2026
Auros Core <= 5.3.1 - Unauthenticated Arbitrary Shortcode Execution CVE-2025-64637 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N June 26, 2026
TablePress – Tables in WordPress made easy <= 3.3.1 - Reflected Cross-Site Scripting CVE-2026-56051 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N June 25, 2026
Pods – Custom Content Types and Fields <= 3.3.8 - Unauthenticated Stored Cross-Site Scripting CVE-2026-54191 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N June 15, 2026
Media Library Assistant <= 3.35 - Reflected Cross-Site Scripting CVE-2026-54198 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N June 15, 2026
WordPress & WooCommerce Scraper Plugin, Import Data from Any WebSite. <= 1.0.7 - Unauthenticated Arbitrary File Download CVE-2025-69131 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N June 12, 2026
Nifty <= 1.4.1 - Unauthenticated PHP Object Injection CVE-2026-27429 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H June 12, 2026
Kastell <= 2.0 - Unauthenticated Local File Inclusion CVE-2026-52707 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H June 12, 2026

Share this researcher's vulnerability discoveries

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation