Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-92430 — Rede Itaú for WooCommerce < 5.4.7 - Unauthenticated Order Status Manipulation via PIX Web…

The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook before updating an order's status, allowin…

| Authentication
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-92425 — Hydra Booking < 1.2.4 - Hydra Host+ Cross-Host Account Modification and Deletion via IDOR

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing u…

| Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-92421 — Hydra Booking 1.1.0 - < 1.2.3 - Hydra Host+ Host Profile Takeover via IDOR

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the user making the request, allowing authen…

| Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-92420 — Hydra Booking < 1.2.2 - Hydra Host+ Cross-Host Booking Deletion and Modification via IDOR

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its…

| Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-92404 — MgoSync 2.1.5 - 2.1.6 - Unauthenticated WooCommerce API Credential Disclosure

The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, in…

| Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-92403 — Secure Custom Fields < 6.9.4 - Unauthenticated Post Modification via Front-End Form ID Su…

The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated use…

| Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-92099 — WPGraphQL Smart Cache < 2.3.2 - Unauthenticated Persisted Query Registration and Alias Sq…

The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persisted query from a request, allowing unauthe…

| Authentication
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-91847 — Bookly < 28.2 - Unauthenticated AI Assistant Conversation Disclosure and Message Injectio…

The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversat…

| Authentication
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-88926 — VikRentItems Flexible Rental Management System < 1.2.4 - Unauthenticated SQLi

The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated user…

| Injection
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-88824 — Master Blocks 1.4.1 - 1.4.1.4 - Unauthenticated Stored XSS via White Label Settings

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescap…

| Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-86814 — UsersWP - Social Login < 1.5.10 - Unauthenticated Account Takeover via Unverified Provide…

The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthent…

| Authentication
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-86591 — Botiga Pro < 1.6.5 - Unauthenticated Arbitrary Blog Options Update via Templates Builder …

The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary v…

| Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-85680 — Ultimate Member < 2.13.1 - Unauthenticated Stored XSS via Profile Page Title

The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its …

| Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-85574 — Unbounce Landing Pages 1.1.1 - 1.1.4 - Subscriber+ Reverse-Proxy Target Hijack via set_un…

The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such …

| Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-84750 — Ultimate Addons for Contact Form 7 3.2.4 - 3.5.50 - Unauthenticated Arbitrary File Upload…

The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uploaded through one of its form fields, and stores them at a predictable public pa…

| Authentication
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-76790 — Estatik < 4.3.5 - Reflected XSS via get_listings hash Parameter

The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back in an unauthenticated AJAX respon…

| Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-76554 — WP Import Export Lite < 3.9.35 - Authenticated Privilege Escalation via User Import

The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to create or modify user accounts and assign roles, allowing users granted a dele…

| Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-19860 — JetFormBuilder 3.5.6.2 - 3.6.5.2 - Admin+ Arbitrary File Deletion via Server-Side Validat…

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blo…

| Authentication
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-16557 — Nimble Builder <= 3.3.8 - Subscriber+ Non-Public Content Disclosure via sek_get_nimble_co…

The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated use…

| Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2025-15698 — Business Name Generator <= 1.3 - Admin+ Stored XSS via Button Color Setting

The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting…

| Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
Showing 20 of 14313 Results