jetmonsters
Web & CMS Pluginscommercial
Latest CVEs
The 15 most recently published vulnerabilities affecting jetmonsters.
- CVE-2026-5924Getwid <= 2.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Google Maps 'customStyle'6.4
- CVE-2026-12793JetFormBuilder <= 3.6.2 - Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter9.8
- CVE-2026-90650MotoPress Hotel Booking <= 6.2.4 - Unauthenticated Stored Cross-Site Scripting via Stripe Webhook Event Object 'id'7.2
- CVE-2026-73400WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Local File Inclusion vulnerability8.1
- CVE-2026-28140WordPress JetFormBuilder plugin <= 3.6.4.1 - Broken Access Control vulnerability7.5
- CVE-2026-9180MotoPress Appointment Booking <= 2.4.4 - Unauthenticated Insecure Direct Object Reference to 'payment_details.booking_id' Parameter5.3
- CVE-2026-57347WordPress Hotel Booking Lite plugin <= 6.0.3 - Sensitive Data Exposure vulnerability6.5
- CVE-2026-13459JetFormBuilder <= 3.6.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'context' Parameter5.3
- CVE-2026-13454MotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection via 's' Parameter6.5
- CVE-2026-11380JetWidgets For Elementor <= 1.0.21 - Authenticated (Author+) Stored Cross-Site Scripting via Animated Box 'animation_effect' Setting6.4
- CVE-2026-57644WordPress Restaurant Menu by MotoPress plugin <= 2.4.10 - SQL Injection vulnerability8.5
- CVE-2025-63078WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Broken Access Control vulnerability4.3
- CVE-2026-54196WordPress JetFormBuilder plugin <= 3.6.1 - Privilege Escalation vulnerability6.8
- CVE-2026-54195WordPress JetFormBuilder plugin <= 3.6.0.1 - Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-9228Timetable and Event Schedule by MotoPress <= 2.4.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via action_get_event_data Function4.3