Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Kitch

#20782of 56,329
13.6Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-89268
6.4
2026-09-10
Sunny Johal · Easy Google Fonts · CVE-2026-4657
The Easy Google Fonts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the control selectors meta field in all versions up to, and including, 2.0.4. This is due to the plugin registering the control selectors meta field with show in rest enabled but without a sanitize callback, and subsequently outputting this unsanitized data directly into <style> tags on the frontend without proper escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
PT-2026-56723
7.2
2026-07-09
WordPress · Connect Contact Form 7/Mailchimp · CVE-2026-15000
**Name of the Vulnerable Software and Affected Versions** Connect Contact Form 7 and Mailchimp versions prior to 0.9.78.07 **Description** Stored Cross-Site Scripting (XSS) occurs due to insufficient input sanitization and output escaping. This allows unauthenticated attackers to inject arbitrary web scripts through Mailchimp Merge Field Values. The execution is deferred and only triggers when an administrator performs a Contact Lookup for the email address submitted via the CF7 form. **Recommendations** Update the plugin to a version newer than 0.9.78.06.