Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-85310 — WordPress Groundhogg plugin <= 4.7.1 - Path Traversal vulnerability

import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.

Remote | Path Traversal
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.5 HIGH
CVE-2026-84821 — WordPress WP Fast Total Search plugin <= 1.82.284 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.

Remote | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.1 HIGH
CVE-2026-84819 — WordPress WPAdverts plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.

Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.1 HIGH
CVE-2026-84816 — WordPress WPCS plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.

Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.1 HIGH
CVE-2026-81805 — WordPress SiteSkite plugin <= 2.1.5 - Privilege Escalation vulnerability

Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.

Remote | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.5 HIGH
CVE-2026-81804 — WordPress ZHBackup – Backup, Restore & Migration plugin <= 2.4.2 - Sensitive Data Exposur…

Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration <= 2.4.2 versions.

Remote | Information Disclosure
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.5 HIGH
CVE-2026-81803 — WordPress RepairBuddy plugin <= 4.1224 - Remote Code Execution (RCE) vulnerability

Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.

Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.1 HIGH
CVE-2026-81801 — WordPress WP-Stateless plugin <= 4.4.1 - Settings Change vulnerability

Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.

Remote | Misconfiguration
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.3 CRITICAL
CVE-2026-81800 — WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vulnerability

Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.

Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.5 HIGH
CVE-2026-81799 — WordPress Return Refund and Exchange For WooCommerce plugin <= 4.6.4 - Broken Access Cont…

Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.

Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.3 HIGH
CVE-2026-81796 — WordPress WP Travel plugin <= 12.0.3 - Broken Authentication vulnerability

Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.

Remote | Authentication
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.1 HIGH
CVE-2026-81795 — WordPress Page Visits Counter – Lite plugin <= 1.2.3 - Cross Site Scripting (XSS) vulnera…

Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter &#8211; Lite <= 1.2.3 versions.

Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.5 HIGH
CVE-2026-81794 — WordPress Shirt Product Designer for WooCommerce plugin 1.0.4 - Broken Access Control vul…

Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.

Remote | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-81793 — WordPress Salon booking system plugin <= 10.31.5 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.

Remote | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-81791 — WordPress EventON plugin <= 2.5.7 - Cross Site Scripting (XSS) vulnerability

Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions.

Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.6 HIGH
CVE-2026-81789 — WordPress Advanced Product Fields Extended for WooCommerce plugin <= 3.1.6 - Arbitrary Fi…

Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce <= 3.1.6 versions.

Remote | Path Traversal
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.3 MEDIUM
CVE-2026-81788 — WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Access Control vulnerability

Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.

impress_for_idx_broker | Remote | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-81787 — WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Authentication vulnerability

Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions.

impress_for_idx_broker | Remote | Authentication
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.5 HIGH
CVE-2026-81786 — WordPress Thank You Page Customizer for WooCommerce plugin <= 1.2.2 - Broken Access Contr…

Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions.

Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-81785 — WordPress BuddyForms plugin <= 2.9.0 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions.

buddyforms | Remote | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Showing 20 of 13954 Results