Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-1085 — True Ranker <= 2.2.9 - Cross-Site Request Forgery to Unauthorized True Ranker Disconnecti…

The True Ranker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.9. This is due to missing nonce validation on the seolocalrank-signout actio…

Remote | Cross-Site Request Forgery
Mar 07, 2026 Mar 09, 2026
Mar 07, 2026
Mar 09, 2026
7.2 HIGH
CVE-2026-1074 — WP App Bar <= 1.5 - Unauthenticated Stored Cross-Site Scripting via 'app-bar-features' Pa…

The WP App Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app-bar-features' parameter in all versions up to, and including, 1.5. This is due to insufficient input sani…

Remote | Cross-Site Scripting
Mar 07, 2026 Mar 09, 2026
Mar 07, 2026
Mar 09, 2026
4.3 MEDIUM
CVE-2026-1073 — Purchase Button For Affiliate Link <= 1.0.2 - Cross-Site Request Forgery to Settings Upda…

The Purchase Button For Affiliate Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing nonce validation on the set…

Remote | Cross-Site Request Forgery
Mar 07, 2026 Mar 09, 2026
Mar 07, 2026
Mar 09, 2026
4.4 MEDIUM
CVE-2026-1071 — Carta Online <= 2.13.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via P…

The Carta Online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.13.0 due to insufficient input sanitization and output es…

Remote | Cross-Site Scripting
Mar 07, 2026 Mar 09, 2026
Mar 07, 2026
Mar 09, 2026
7.2 HIGH
CVE-2025-14675 — Meta Box <= 5.11.1 - Authenticated (Contributor+) Arbitrary File Deletion

The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_delete_file' function in all versions up to, and including, 5.11.1. Th…

meta_box | Remote | Path Traversal
Mar 07, 2026 Mar 09, 2026
Mar 07, 2026
Mar 09, 2026
Showing 20 of 5865 Results