Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-77946 — TRENDnet TEW-821DAP NTP Timezone Configuration apply_time.cgi uci_safe_get stack-based ov…

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configur…

tew-821dap | Memory Corruption
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-77945 — TRENDnet TEW-821DAP ssi upload.cgi command injection

A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.cgi of the component ssi. Performing a manipulation of the argument filename re…

tew-821dap | Injection
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
9.8 CRITICAL
CVE-2026-78003 — Mailgun for WordPress <= 2.2.0 - Unauthenticated Server-Side Request Forgery (SSRF) via '…

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validati…

Remote | Server-Side Request Forgery
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
9.3 CRITICAL
CVE-2026-12710 — Missing Authorization in Application Integration QueryEngineTask

A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal …

application_integration | Remote | Authorization
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-77002 — SmilePass Selfie Login <= 1.0.2 - Unauthenticated Authentication Bypass

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any re…

| Authentication
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-77001 — Social Login & Sharing buttons with Analytics By SoClever <= 1.2.0 - Unauthenticated Auth…

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login…

| Authentication
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-77000 — WP Social Media Login <= 1.0.6 - Unauthenticated Account Takeover via Twitter Login Flow

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticate…

| Authentication
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-76793 — Firebase Authentication < 1.7.1 - Unauthenticated Account Takeover via Firebase Email Cla…

The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session,…

| Authentication
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-76789 — Slider Hero < 9.1.3 - Unauthenticated Stored XSS via Slider Type Change and Add-Slider Ha…

The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before…

| Authorization
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-19222 — Forminator Forms < 1.57.0.7 - Authenticated Privilege Escalation via Registration Form Ro…

The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configur…

| Authorization
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-19221 — Forminator Forms < 1.57.0.5 - Admin+ Network-Wide RCE via Hub Connector API Key on Multis…

The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execu…

| Authorization
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-19093 — Tutor LMS < 4.0.6 - Instructor+ Arbitrary File Read via Video Path

The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor role to read arbitrary files on the server, inclu…

| Path Traversal
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-18052 — ManageWP Worker < 4.9.37 - Unauthenticated Authentication Bypass via Unsigned Auto-Login …

The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, a…

| Authentication
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-16738 — Conekta Payment Gateway < 6.2.2 - Unauthenticated Order Payment Completion via Webhook Fo…

The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or v…

| Authentication
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-16612 — FiboSearch < 1.34.1 - Unauthenticated Password-Protected Product Information Disclosure

The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumer…

| Information Disclosure
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-16260 — Post Grid, Slider & Carousel Ultimate < 1.8.1 - Contributor+ Stored XSS via Header Title …

The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit …

| Cross-Site Scripting
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
0.0 NA
CVE-2026-14187 — Tutor LMS < 4.0.6 - Instructor+ Cross-Instructor Private Course Disclosure via IDOR

The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses…

| Authorization
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
4.3 MEDIUM
CVE-2026-76074 — AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Inf…

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including…

Remote | Authorization
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
4.3 MEDIUM
CVE-2026-76057 — AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Inf…

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including…

Remote | Authorization
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
5.3 MEDIUM
CVE-2026-75027 — Themify Builder <= 7.8.0 - Missing Authorization to Unauthenticated Arbitrary Builder Dat…

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin not properly verifying that a user is authorized …

Remote | Authorization
Aug 22, 2026 Aug 22, 2026
Aug 22, 2026
Aug 22, 2026
Showing 20 of 11695 Results