The PostX plugin for WordPress, specifically versions up to and including 5.0.13, is vulnerable to Stored Cross-Site Scripting via the 'inputPlaceHolder' parameter. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts into pages, which will execute when a user accesses an injected page. The vulnerability is due to insufficient input sani [truncated]
A Missing Authorization vulnerability was found in WPXPO WowAddons product-addons, allowing Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WowAddons from n/a through <= 1.6.8. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. Users of WPXPO WowAddons product-addons, especially those with versions from n/a through <= 1.6.8, should be aware [truncated]
CVE-2026-2518 is an authorization weakness in the FastX WordPress theme. Because the theme’s ultp_install_callback and ultp_activate_callback functions lack capability checks, authenticated users with Subscriber-level access and above can install and activate the PostX plugin. The issue affects FastX versions up to and including 1.0.2 and is rated Medium severity (CVSS 4.3).
CVE-2026-39700 is a Missing Authorization vulnerability in WPXPO WowOptin optin. The issue allows Exploiting Incorrectly Configured Access Control Security Levels and affects WowOptin from n/a through <= 1.4.32. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. This issue may impact users of WPXPO WowOptin optin version 1.4.32 or earlier. Affected deployments should be identified and patched.