Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.3 LOW
CVE-2026-108505 — Information disclosure vulnerability in ZTE Z80 Ultra product

ZTE Z80 Ultra has a local information disclosure vulnerability. Third-party applications can capture data returned by system interfaces to obtain device-related information.

| Information Disclosure
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-107657 — HivePress <= 1.7.31 - Unauthenticated Stored Cross-Site Scripting via Custom User Attribu…

The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<custom user attribute field name, e.g. profile_test>' …

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.4 MEDIUM
CVE-2026-4791 — PeproDev Ultimate Profile Solutions <= 8.2.36 - Authenticated (Contributor+) Stored Cross…

The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `logout-url` shortcode's 'button' attribute in all versions up to, and including, 8.2…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
4.9 MEDIUM
CVE-2026-104722 — Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 6.1.2 - Authentic…

The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the LSD_Menus_IX_CSV…

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.5 HIGH
CVE-2026-91136 — Divi Plus <= 2.4.0 - Unauthenticated Arbitrary File Read via 'svg_image' Parameter

The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the 'svg_image' parameter of the /wp-json/elicus/v1/dipl-modules/svg-animator REST …

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.4 MEDIUM
CVE-2026-97396 — Email Marketing for WordPress and WooCommerce <= 1.0.10 - Authenticated (Subscriber+) Sto…

The Email Marketing for WordPress and WooCommerce – Retainful plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 1.0.10 d…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.4 MEDIUM
CVE-2026-97340 — Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Authenticated (Subscriber…

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Stored Cross-Site Scripting via the user profile 'Author Page' social link contact-method fields (author_f…

avada | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-96765 — WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenti…

The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id_token' parameter in all versions up to, and incl…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.5 HIGH
CVE-2026-96662 — Appointment Booking Plugin <= 5.7.2 - Unauthenticated SQL Injection via 'booking[service_…

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to generic SQL Injection via 'booking[service_id]' Parameter in all versions up to,…

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.5 MEDIUM
CVE-2026-96653 — WP Directory Kit <= 1.5.9 - Authenticated (Subscriber+) SQL Injection via 'display_name' …

The WP Directory Kit plugin for WordPress is vulnerable to time-based SQL Injection via 'display_name' Profile Field (Second-Order) in all versions up to, and including, 1.5.9 due to insufficient esc…

wp_directory_kit | Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.4 MEDIUM
CVE-2026-96563 — Motors <= 1.4.123 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'stm_f_s'…

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'stm_f_s' parameter in all versions up to, and including, 1.4.123 du…

motors_-_car_dealer\,_classifieds_\&_listing | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-96278 — WP Photo Album Plus <= 9.3.03.002 - Unauthenticated Stored Cross-Site Scripting via REQUE…

The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Session History in all versions up to, and including, 9.3.03.002 due to insufficient input sa…

wp_photo_album_plus | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-93951 — WordPress Zeinet theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Zeinet zeinet allows Reflected XSS.This issue affects Zeinet: from n/a through 1.0.0.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.5 HIGH
CVE-2026-93950 — WordPress Motors theme <= 1.4.108 - Broken Access Control vulnerability

Missing Authorization vulnerability in StylemixThemes Motors motors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through 1.4.108.

Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-93949 — WordPress Grocery Shopping Store theme <= 1.3.3 - Broken Authentication vulnerability

Authentication Bypass Using an Alternate Path or Channel vulnerability in Omegathemes Grocery Shopping Store grocery-shopping-store allows Password Recovery Exploitation.This issue affects Grocery Sh…

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-93945 — WordPress Balance theme <= 1.12.0 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-93944 — WordPress Camelia theme <= 1.2.15 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-93943 — WordPress Convex theme <= 1.16.0 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-93942 — WordPress Dwell theme <= 1.16.0 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a through 1.16.0.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-93941 — WordPress Edema theme <= 1.2.2.2 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Showing 20 of 14203 Results