Known Vulnerabilities for Custom PHP Settings by Cyclonecode
Listed below are 10 of the newest known vulnerabilities associated with "Custom PHP Settings" by "Cyclonecode".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-6041 json | The Buzz Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom Buzz Avatar' (buzz_commen... | Not Provided | 2026-04-22 | 2026-04-22 |
| CVE-2026-5347 json | The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. This ... | Not Provided | 2026-04-24 | 2026-04-24 |
| CVE-2026-3551 json | The Custom New User Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's admin set... | Not Provided | 2026-04-16 | 2026-04-16 |
| CVE-2026-3499 json | The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to Cros... | Not Provided | 2026-04-08 | 2026-04-08 |
| CVE-2026-2717 json | The HTTP Headers plugin for WordPress is vulnerable to CRLF Injection in all versions up to, and including, 1.19.2. This is d... | Not Provided | 2026-04-22 | 2026-04-22 |
| CVE-2026-2432 json | The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored Cross-Si... | Not Provided | 2026-03-20 | 2026-04-08 |
| CVE-2026-2294 json | The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized mo... | Not Provided | 2026-03-21 | 2026-04-08 |
| CVE-2026-1390 json | The Redirect countdown plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... | Not Provided | 2026-03-21 | 2026-04-08 |
| CVE-2025-15616 json | Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search path vu... | Not Provided | 2026-03-27 | 2026-03-27 |
| CVE-2024-4942 json | The Custom Dash plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, a... | Not Provided | 2024-06-06 | 2026-04-08 |