Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-4361 — Divi <= 4.27.6 - Authenticated (Contributor+) Server-Side Request Forgery via 'image_src'…

The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` function usi…

divi divi | Server-Side Request Forgery
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-3853 — Divi <= 4.27.6 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via V…

The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider_item` shortcode in all versions up to, and including, 4.27…

divi divi | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-15984 — QuickCal <= 1.0.20 - Unauthenticated Stored Cross-Site Scripting via Custom Field Paramet…

The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and including, 1.0.20 due to insufficient input sanitization and outp…

| Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-18406 — SureForms <= 2.12.2 - Unauthenticated Stored Cross-Site Scripting via Text Field Entity-E…

The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field Entity-Encoded Payload in all versions up …

| Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-19887 — Welcart e-Commerce <= 2.12.1 - Unauthenticated Arbitrary File Deletion via PHP Object Inj…

The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callba…

| Injection
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-78438 — W3 Total Cache <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via LazyLoad Backg…

The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficie…

w3_total_cache | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-14975 — WP File Download <= 6.3.8 - Authenticated (Subscriber+) Arbitrary File Read via Path Trav…

The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter. This makes it possible for authenticated atta…

wp_file_download | Path Traversal
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-19769 — Ninja Forms <= 3.15.1 - Unauthenticated Stored Cross-Site Scripting via Repeater Child 't…

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key in all ver…

| Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-16649 — Gravity Forms <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via Post Body Field…

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 due to insufficient input sanitization and o…

| Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-77830 — Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.86 - Unauthenticated Stored Cross-…

The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all versions up to, and including…

| Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-18843 — Beaver Builder Plugin (Pro Version) <= 2.11.0.1 - Reflected Cross-Site Scripting via 'no_…

The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all versions up to, and including, …

| Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
6.4 MEDIUM
CVE-2026-8625 — Dear Flipbook <= 2.4.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via '.…

The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (Custom HTML block inner HTML)' parameter …

Remote | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
6.4 MEDIUM
CVE-2026-8623 — Dear Flipbook <= 2.4.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via '.…

The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (class attribute of .dvcss element)' param…

Remote | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
8.2 HIGH
CVE-2026-86145 — PCRE2 Out-of-Bounds Write Vulnerability

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated blo…

pcre2 | Remote | Memory Corruption
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
4.3 MEDIUM
CVE-2026-83628 — Theme My Login <= 7.1.15 - Authenticated (Subscriber+) Missing Authorization to Unauthori…

The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite installations. This is due to the `tml_ms_signup_handler()` functi…

Remote | Authorization
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
9.8 CRITICAL
CVE-2026-83627 — Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthentic…

The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() functi…

Remote | Information Disclosure
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
7.2 HIGH
CVE-2026-77263 — iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more <= 3.13.4 - Unauthe…

The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3…

Remote | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
7.2 HIGH
CVE-2026-77233 — iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more <= 3.13.4 - Unauthe…

The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via AdSense Regex Rewrite in all versio…

Remote | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
6.4 MEDIUM
CVE-2026-18404 — Social Chat <= 8.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'cons…

The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all versions up to, and includ…

Remote | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
9.8 CRITICAL
CVE-2026-13447 — MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT…

The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the …

Remote | Authentication
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
Showing 20 of 12816 Results