Known Vulnerabilities for Facebook For WordPress by Facebook
Listed below are 9 of the newest known vulnerabilities associated with "Facebook For WordPress" by "Facebook".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-83561 json | The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment C... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-77826 json | The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued t... | Not Provided | 2026-09-05 | 2026-09-06 |
| CVE-2026-66705 json | Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions. | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-18059 json | The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exposu... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-18056 json | The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in al... | Not Provided | 2026-09-06 | 2026-09-07 |
| CVE-2026-16684 json | The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact Meth... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-13604 json | The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits pub... | Not Provided | 2026-08-01 | 2026-08-05 |
| CVE-2026-12002 json | The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request For... | Not Provided | 2026-07-08 | 2026-07-08 |
| CVE-2026-4298 json | The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4... | Not Provided | 2026-07-09 | 2026-07-09 |