Known Vulnerabilities for WP Plugin Manager by HasThemes
Listed below are 2 of the newest known vulnerabilities associated with "WP Plugin Manager" by "HasThemes".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-42796 json | Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint th... | Not Provided | 2026-05-04 | 2026-05-04 |
| CVE-2026-42313 json | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API meth... | Not Provided | 2026-05-11 | 2026-05-12 |
| CVE-2026-35463 json | pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTIONS pro... | Not Provided | 2026-04-07 | 2026-04-08 |
| CVE-2026-35204 json | Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or ... | Not Provided | 2026-04-09 | 2026-04-09 |
| CVE-2026-29924 json | Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin ... | Not Provided | 2026-03-30 | 2026-03-30 |
| CVE-2026-7106 json | The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and in... | Not Provided | 2026-04-27 | 2026-04-27 |
| CVE-2026-7049 json | The PixelYourSite Pro – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Server-Side Request Forgery in... | Not Provided | 2026-05-02 | 2026-05-04 |
| CVE-2026-5357 json | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_m... | Not Provided | 2026-04-09 | 2026-04-09 |
| CVE-2026-5337 json | During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perfor... | Not Provided | 2026-05-03 | 2026-05-04 |
| CVE-2026-4896 json | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vu... | Not Provided | 2026-04-04 | 2026-04-08 |