The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versions up to, and including, 4.5.18. The plugin's `wpmsTemplateRedirect()` hook detects a 404 and concatenates `$_SERVER['HTTP_HOST']` with the raw `$_SERVER['REQUEST_URI']`, inserting the value into the `wp_wpms_links.link_url` column via `$wpdb->insert()`. This a [truncated]
The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.5.18 via the 'new_link' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. The H [truncated]
CVE-2026-9690 is a high-severity vulnerability in WP Media folder Addon versions <= 4.0.1. It allows unauthenticated arbitrary file downloads, posing a significant risk to affected systems. The vulnerability has a CVSS score of 7.5 and is considered HIGH severity. The CVE was published on 2026-06-17T13:21:35.147Z and last modified on 2026-06-17T17:17:28.293Z. Users of the affected plugin should take immed [truncated]