Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-18347 — Kirki <= 6.1.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Informati…

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.1.1. This is due to the plugin not p…

| Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-17604 — Kirki <= 6.1.1 - Authenticated (Editor+) Path Traversal to Arbitrary File Read via 'data'…

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1.1 via the 'data' parameter paramete…

| Path Traversal
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-13424 — Online Scheduling and Appointment Booking System <= 27.7 - Unauthenticated Stored Cross-S…

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action in all versions up to, an…

| Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-17087 — WP Travel Engine <= 6.8.4 - Missing Authorization to Unauthenticated Sensitive Informatio…

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin n…

| Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-2497 — Gallery by BestWebSoft <= 4.7.9 - Authenticated (Editor+) SQL Injection via Gallery Image…

The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parameter array keys in all versions up to, and including, 4.7.9. This is due to insu…

| Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-17608 — WP Compress <= 7.10.09 - Cross-Site Request Forgery to Arbitrary Options Deletion

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.10.09. This is due to missing or in…

| Cross-Site Request Forgery
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-2357 — Bold Page Builder <= 5.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' shortcode in all versions up to, and including, 5.6.8 due to insufficient in…

| Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-12998 — Forminator Forms <= 1.55.0.2 - Insecure Direct Object Reference to Unauthenticated Sensit…

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.55.0.2 via the '…

| Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-10734 — Infility Global <= 2.15.21 - Unauthenticated Stored Cross-Site Scripting via /cf7_record …

The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in all versions up to, and including, 2.15.21 due to insufficient input sanitization…

| Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-9767 — The School Management <= 5.4 - Authenticated (Custom+) SQL Injection via 'order[0][dir]' …

The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 5.4 due to insuffi…

Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
4.9 MEDIUM
CVE-2026-2283 — User Login History <= 2.1.7 - Authenticated (Administrator+) SQL Injection via 'blog_id' …

The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions up to, and including, 2.1.7. This is due to insufficient escaping on the user su…

Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-19934 — itsourcecode Hospital Management System vieworder.php sql injection

A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /vieworder.php. The manipulation of the argument delid leads to sql injecti…

hospital_management_system | Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-19728 — Extra Product Options Builder for WooCommerce < 1.2.176 - Unauthenticated Customer File D…

The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploaded file before serving it, allowing unauthenticate…

| Information Disclosure
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-19726 — Visualizer < 4.0.7 - Contributor+ Cross-User Chart Configuration Disclosure

The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contributor role and above to read the full configuration …

| Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-19725 — WPvivid Backup & Migration < 0.9.131 - Unauthenticated Path Traversal via send_to_site_co…

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to build a log file path, allowing an attacke…

| Path Traversal
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-19717 — CatFolders Document Gallery < 2.0.7 - Unauthenticated Attachment Disclosure via REST API

The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API endpoints, allowing unauthenticated users to retrieve the title,…

| Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-19714 — Simple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Google id_token A…

The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate as any user whose email add…

| Authentication
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-19712 — Masteriyo LMS < 2.3.3 - Instructor+ Stored XSS via Quiz Description

The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its instructor role the ability to store unfiltered HTML, al…

| Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-19711 — Premium Packages – Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbitrary Amount …

The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber…

| Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-19613 — ECS < 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeater ACF Source

The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater data sources reads custom field values from a user-supplied post identifier, …

| Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
Showing 20 of 11278 Results