Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-100312 — mathurvishal CloudClassroom-PHP-Project updateguest.php sql injection

A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file /updateguest.php…

| Injection
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
0.0 NA
CVE-2026-98163 — cgroup: Avoid iteration of dying tasks with zero refcount

In the Linux kernel, the following vulnerability has been resolved: cgroup: Avoid iteration of dying tasks with zero refcount The commit 260fbcb92bbea ("cgroup: Move dying_tasks cleanup from cgroup…

| Race Condition
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
4.0 MEDIUM
CVE-2026-100311 — mathurvishal CloudClassroom-PHP-Project Faculty Video Management managevideos2.php cross …

A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The affected element is an unknown function of the file managevideos2.php of …

cloudclassroom-php-project | Remote | Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
0.0 NA
CVE-2026-96533 — Testimonials Widget <= 4.0.4 - Unauthenticated SSRF via Featured Image URL

The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users t…

testimonials_widget | Server-Side Request Forgery
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
0.0 NA
CVE-2026-96532 — Testimonials Widget <= 4.0.4 - Unauthenticated Arbitrary Post Update

The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modi…

testimonials_widget | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
0.0 NA
CVE-2026-96531 — Optimole 4.0.0 - 4.2.12 - Author+ Stored XSS via Video Player Block

The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users with the Author r…

| Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
0.0 NA
CVE-2026-96526 — MCP Server for WordPress < 1.8.2 - Contributor+ Arbitrary Post Title Disclosure via workf…

The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of its workflow REST routes, allowing users with the Contributor role to disclo…

| Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
0.0 NA
CVE-2026-96525 — MCP Server for WordPress < 1.8.2 - Contributor+ Workflow Modification and Deletion via Mi…

The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check on its workflow create, update and delete REST routes, allowing users with the…

| Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
0.0 NA
CVE-2026-96524 — MCP Server for WordPress < 1.8.2 - Administrator Account Creation via CSRF

The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is pres…

| Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
0.0 NA
CVE-2026-92411 — WP Delicious < 1.10.8 - Contributor+ Stored XSS via Recipe Block Tag Name

The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied recipe block data before rendering it on the front end, allowing users with the…

| Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
0.0 NA
CVE-2026-89237 — Bluff Post <= 1.1.1 - Unauthenticated SQLi via 'table_name' and 'column_name' Parameters

The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers in a SQL query, allowing unauthenticated attackers to append additional SQL and …

| Injection
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
0.0 NA
CVE-2026-85081 — Multiple elFinder Plugins - DOM-based XSS via postMessage Origin Bypass

The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages r…

file_manager fileorganizer filester | Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
0.0 NA
CVE-2026-84097 — WP Review Slider Pro < 12.7.12 - Subscriber+ SQLi via Stored Template Filter

The wp-review-slider-pro WordPress plugin before 12.7.12 does not sanitize a value stored through one of its AJAX handlers, which lacks a capability check, before using it in a SQL statement, allowin…

| Injection
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
0.0 NA
CVE-2026-84096 — WP Review Slider Pro < 12.7.12 - Subscriber+ Stored XSS via Review Form Fields

The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the AJAX handler that saves its review submission forms, and the nonce protecting it is generated for e…

| Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
0.0 NA
CVE-2026-84095 — WP Review Slider Pro < 12.7.12 - Subscriber+ Stored XSS via Review Import

The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers, and the nonce protecting it is generated for every visitor, allowing any auth…

| Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
0.0 NA
CVE-2026-19708 — File Manager 7.2.2 - 8.0.4 - Unauthenticated Database Backup Disclosure

The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing una…

file_manager | Information Disclosure
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
9.8 CRITICAL
CVE-2026-18143 — Request a Quote for WooCommerce <= 2.9.2 - Unauthenticated Arbitrary File Upload via AJAX…

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is …

Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
0.0 NA
CVE-2026-16591 — WP Directory Kit < 1.5.8 - Listing Admin+ Stored XSS via Category and Location Title and …

The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category and location fields before outputting them in page attributes, allowing users with a WP Directory …

| Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
0.0 NA
CVE-2026-11871 — Team Showcase Supreme <= 9.2 - Unauthenticated Sensitive Data Disclosure via wpm_6310_tea…

The Team Members WordPress plugin through 9.2 does not perform any authorization or visibility check in an unauthenticated AJAX action that returns full team member records by ID, allowing unauthent…

team_members | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.4 MEDIUM
CVE-2026-15273 — Automatic.css 4.0.0 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI

The Automatic.css plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI in all version 4.0.0 due to insufficient input sanitization and output escaping. This makes it poss…

Remote | Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Showing 20 of 14605 Results