Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-62046 — WordPress Gutentype theme <= 2.1.12 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-62045 — WordPress Booklovers theme <= 2.13.0 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.5 MEDIUM
CVE-2026-108504 — Unauthorized information retrieval vulnerability in ZTE Z80 Ultra product

ZTE Z80 Ultra has an unauthorized information disclosure vulnerability. The access control for methods within the framework is insufficient. An attacker can exploit this method to read device-related…

| Information Disclosure
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-106606 — WordPress YITH WooCommerce Affiliates plugin <= 3.31.0 - PHP Object Injection vulnerabili…

Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Affiliates yith-woocommerce-affiliates allows Object Injection.This issue affects YITH WooCommerce Affiliates: from n/a throug…

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-104803 — WPCOM Member <= 1.7.27 - Unauthenticated Authentication Bypass via 'uuid' and 'code' Para…

The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via the `uuid` and `code` parameters of the social-login callback handler reg…

wpcom_member | Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-104759 — WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenti…

The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Authentication Bypass via OIDC Nonce Replay in all versions up to, and including, 44.1 T…

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
4.3 MEDIUM
CVE-2026-104728 — AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Inf…

The AutomatorWP – No-Code Workflow Automation, Integration & Webhooks Plugin, now with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This …

Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.4 MEDIUM
CVE-2026-103478 — Premium Packages <= 7.2.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via '…

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkout[billing][phone] (and state / taxid / email)' parameter in all…

premium_packages_-_sell_digital_products_securely | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.4 MEDIUM
CVE-2026-102774 — SureDash <= 1.12.1 - Authenticated (Subscriber+) Stored DOM-Based Cross-Site Scripting vi…

The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Image 'alt' Attribute in Community Post Content in all versions up…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.4 MEDIUM
CVE-2026-102291 — Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.3.1 - Authenticated (Sub…

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.3.1 This is due to the plug…

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
4.7 MEDIUM
CVE-2026-101921 — WPForms <= 2.0.2.1 - Reflected Cross-Site Scripting via 'query_var' Smart Tag in iframe s…

The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'attacker-chosen key …

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-101920 — Molongui Authorship <= 5.2.12 - Unauthenticated Stored DOM-Based Cross-Site Scripting via…

The Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'comment (href attribute inside co…

molongui_authorship | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-100178 — WPAdverts <= 2.3.4 - Unauthenticated Stored Cross-Site Scripting via 'adverts_location' P…

The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'adverts_location' parameter in all versions up to, and including, 2.3.4 due to insufficie…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-100147 — FunnelKit <= 3.16.0.5 - Unauthenticated Stored Cross-Site Scripting via Order Fields (shi…

The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shipping_first_name' parameter in all versions up to, and including,…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.5 MEDIUM
CVE-2026-97348 — SiteOrigin Widgets Bundle <= 1.74.3 - Authenticated (Contributor+) Arbitrary File Read vi…

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.74.3 via the get_instance_css function. This makes it possible for auth…

siteorigin_widgets_bundle | Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-96840 — Post Grid Gutenberg Blocks <= 5.1.0 - Unauthenticated Stored Cross-Site Scripting via dis…

The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via display_name User Field in all versions up to, and including, 5.1.0 due to insufficient in…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.4 MEDIUM
CVE-2026-96574 — User Frontend <= 4.3.12 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wp…

The User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission plugin for WordPress is vulnerable to Stored Cross-Site Scripting v…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-96572 — WP Meteor Website Speed Optimization Addon <= 3.4.18 - Unauthenticated Stored Cross-Site …

The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.4.18 due to insufficie…

wp_meteor | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-96558 — Quiz and Survey Master (QSM) <= 11.2.6 - Unauthenticated Stored DOM-Based Cross-Site Scri…

The Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'qsm_hidden_questions' parameter in all versions up to…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-95684 — VikBooking Hotel Booking Engine & PMS <= 1.8.15 - Unauthenticated Stored Cross-Site Scrip…

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'attachments[name]' Parameter in all versions up to, and including, 1.8.15 due to insuf…

vikbooking_hotel_booking_engine_\&_pms | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Showing 20 of 14163 Results