Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-75528 — Broken Link Checker <= 2.4.13 - Unauthenticated Stored Cross-Site Scripting via Comment A…

The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author URL / Link Log in all versions up to, and including, 2.4.13 due to insufficient input sani…

broken_link_checker | Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-14828 — ManageEngine Password Manager Pro, PAM360, and Access Manager Plus SQL Injection Vulnerab…

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerabil…

Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.4 MEDIUM
CVE-2025-7963 — Easy Waveform Player <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting …

The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer() function in all versions up to, and including, 1.2.2 due to insuffici…

Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.1 HIGH
CVE-2026-82883 — WordPress Login With Ajax plugin <= 4.5.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS. This issue affects Login With Ajax: from n/a throug…

Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.4 MEDIUM
CVE-2026-3850 — Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Contact For…

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_contact_form` shortcode in all versions up to, and including, 4.27.6. This is …

divi divi | Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-82183 — OAuth Single Sign On 6.25.0 - 7.0.0 - Unauthenticated Account Takeover via Unverified Ste…

The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary …

| Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-82182 — WPvivid Backup & Migration < 0.9.133 - Admin+ SQLi via Upload Cleaner Isolation

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied list of identifiers before using it in a SQL query, allowing administrators to perform SQL …

| Injection
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-81807 — Simple Ajax Chat < 20260827 - Unauthenticated Stored XSS via Chat Message Linkification

The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and r…

| Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-81737 — FAQ Builder AYS 1.6.3 - 1.8.4 - Unauthenticated Stored XSS via ays_get_user_information

The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in an admin area page, and the escaping…

| Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-81583 — Theme My Login 7.0 - 7.1.15 - Subscriber+ Unauthorised Multisite Site Creation and Privil…

The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and …

| Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-81432 — JetStyleManager < 1.3.9 - Skin Deletion and Modification via CSRF

The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on some of its AJAX actions, allowing attackers to make a logged-in user with the edit_posts capability (…

| Cross-Site Request Forgery
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-81428 — WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Product and Arbitrary Post Modification via I…

The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownership or the object type of user-supplied IDs when saving product variations, allowing authenticated users with the vendor role to …

| Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-81427 — WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Order Shipment Status Change

The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment status change owns the referenced order, allowing any authenticated vendor to mar…

| Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-81426 — WC Vendors < 2.7.2.1 - Order Shipment Status Change via CSRF

The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order shipment status actions, which could allow attackers to make a logged-in vendor change the…

| Cross-Site Request Forgery
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-81199 — MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure via student/stat…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to di…

| Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-81198 — MasterStudy LMS < 3.7.46 - Instructor+ Cross-Course Curriculum Deletion and Tampering via…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated users with the instructor ro…

| Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-81197 — MasterStudy LMS < 3.7.46 - Unauthenticated Unpublished Course Title Disclosure via course…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route that lists an author's courses, nor does it filter that listing by publication status, al…

| Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-81196 — MasterStudy LMS < 3.7.46 - Instructor+ Quiz Answer Disclosure via IDOR

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access to read other instructors' …

| Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-81195 — MasterStudy LMS < 3.7.46 - Unauthenticated Student Enrollment Disclosure via student-cour…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning per-student course enrollment and progress data, allowing unauthenticated…

| Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-81194 — MasterStudy LMS < 3.7.46 - Subscriber+ Cross-Instructor Order Data Disclosure via author_…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers…

| Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
Showing 20 of 12512 Results