Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-97300 — WordPress WP Event Solution plugin <= 4.1.25 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.2 HIGH
CVE-2026-75962 — Post SMTP <= 4.0.1 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'user_emai…

The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email…

Remote | Cross-Site Scripting
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.5 HIGH
CVE-2026-41563 — WordPress Sitemovr plugin <= 1.0.1 - Sensitive Data Exposure vulnerability

Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions.

Remote | Information Disclosure
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.5 HIGH
CVE-2026-41558 — WordPress WP Migration Plugin DB & Files – WP Synchro plugin <= 1.16.1 - 2FA Bypass vulne…

Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.5 HIGH
CVE-2026-39789 — WordPress Fluent Affiliate Pro plugin <= 1.6.4 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.1 HIGH
CVE-2026-39760 — WordPress Real 3D FlipBook plugin <= 5.5 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.

Remote | Cross-Site Scripting
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.5 HIGH
CVE-2026-39723 — WordPress Morning for WooCommerce plugin <= 2.4.1 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
4.3 MEDIUM
CVE-2026-39599 — WordPress WDS MCP Content Manager plugin <= 3.10.4 - Broken Access Control vulnerability

Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.5 MEDIUM
CVE-2026-32582 — WordPress IATO MCP plugin <= 1.11.0 - Broken Access Control vulnerability

Contributor Broken Access Control in IATO MCP <= 1.11.0 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.5 MEDIUM
CVE-2026-32576 — WordPress Faktur Pro for WooCommerce plugin <= 3.2.1 - Insecure Direct Object References …

Customer Insecure Direct Object References (IDOR) in Faktur Pro for WooCommerce <= 3.2.1 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
4.3 MEDIUM
CVE-2026-105775 — vllm-project vLLM Completions Request mamba_mixer2.py conv_ssm_forward out-of-bounds

A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component …

vllm | Remote | Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.0 MEDIUM
CVE-2026-105708 — imgproxy SVG svg.go sanitizeElement cross site scripting

A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation…

imgproxy | Remote | Cross-Site Scripting
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.5 HIGH
CVE-2026-105072 — WordPress FluentBooking Pro plugin < 2.5.0 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-86786 — Slider Pro <= 1.0.0 - Unauthenticated Sensitive Data Disclosure via sliderpro_multiple_im…

The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and perm…

| Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-94278 — File Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment-compat

The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename …

| Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-89289 — Fast Courier <= 5.2.3 - Unauthenticated Order Fulfillment Update via order-status-update …

The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status…

| Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-94299 — elegro Crypto Payment <= 1.0.1 - Unauthenticated Arbitrary Order Status Change via IPN Ca…

The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers t…

| Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-94271 — Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Confirmation Forgery via Unverif…

The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the payment with the payment provider when handling the return from the hosted checkout, and does not check the payment status…

| Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-94270 — Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Bypass and Order Manipulation vi…

The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the authenticity of incoming payment provider notifications, and ships with that verification disabled by default, allowing un…

| Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-105776 — bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL admin_transaction.p…

A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to ae783195ba7e0390d3b3bfaddd99944b7e9735a4. Affected by this vulnerability is an unknown functionali…

| Injection
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Showing 20 of 14543 Results