Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-84254 — click5 CRM add-on to Contact Form 7 <= 1.0.4 - Unauthenticated Arbitrary Options Update

The click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-84253 — click5 CRM add-on to Gravity Forms <= 1.0.3 - Unauthenticated Arbitrary Options Update

The click5 CRM add-on to Gravity Forms WordPress plugin through 1.0.3 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be …

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-84252 — click5 CRM add-on to WPForms <= 1.0.3 - Unauthenticated Arbitrary Options Update

The click5 CRM add-on to WPForms WordPress plugin through 1.0.3 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be update…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-84251 — click5 CRM add-on to Ninja Forms <= 1.0.1 - Unauthenticated Arbitrary Options Update

The click5 CRM add-on to Ninja Forms WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be up…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-81649 — Fundiin <= 3.4.0 - Unauthenticated Payment Gateway Settings Update and Credential Disclos…

The Fundiin cho WooCommerce WordPress plugin through 3.4.0 does not have proper authorisation on several of its REST API routes, relying instead on a credential that is identical on every installatio…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-81420 — Tcard WP <= 1.8.0 - Unauthenticated SQLi via group_id Parameter

The Tcard WP WordPress plugin through 1.8.0 does not sanitise and escape a parameter before using it in a SQL statement in one of its unauthenticated AJAX actions, allowing unauthenticated users to p…

| Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-81156 — Robo Gallery < 5.2.6 - Contributor+ Stored XSS via Gallery Settings

The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape some of its gallery settings before outputting them on the gallery edit screen, allowing users with the Contributor role a…

| Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-81155 — Robo Gallery < 5.2.6 - Author+ Stored XSS via Gallery Search Label

The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape a gallery setting before outputting it on a frontend page, allowing users with the Author role and above to perform Stored…

| Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-81154 — Robo Gallery < 5.2.6 - Author+ Stored XSS via Image Alt Text

The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape image alt text before outputting it in one of its gallery layouts, allowing users with the Author role and above to perfor…

| Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-81153 — Robo Gallery < 5.2.6 - Author+ Stored XSS via Image Overlay Effect Meta

The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape some of its image settings before outputting them in a gallery page, allowing users with the Author role and above to perf…

| Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-14854 — WooCommerce Bookings < 3.11.0 - Unauthenticated Denial of Service

The WooCommerce Bookings WordPress plugin before 3.11.0 does not limit a user-supplied value before using it to allocate memory in one of its unauthenticated AJAX actions, allowing unauthenticated at…

| Denial of Service
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-12980 — Post Snippets <= 4.2.4 - Contributor+ Stored XSS via Snippet Variable

The Post Snippets WordPress plugin through 4.2.4 does not properly escape variable values substituted into snippets before outputting them, allowing users with the Contributor role and above to inje…

post_snippets | Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.5 MEDIUM
CVE-2026-108541 — highwarden Super Store Finder index.php sql injection

A vulnerability has been found in highwarden Super Store Finder up to 3.8. Affected is an unknown function of the file /products/superstorefinder/index.php. The manipulation of the argument lat/lng l…

super_store_finder | Remote | Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
9.9 CRITICAL
CVE-2026-108540 — OpenSpug File Transfer transfer os command injection

A flaw has been found in OpenSpug Spug up to 3.4.0/4.0.1. This impacts an unknown function of the file /exec/transfer of the component File Transfer. Executing a manipulation can lead to os command i…

spug | Remote | Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-107694 — Dokan < 5.2.0 - Vendor+ Cross-Vendor Commission Settings Disclosure via Commission REST E…

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.2.0 does not verify that the vendor a commission calculation is requested for is the requesting vendor, a…

| Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-107507 — Squadeno < 1.12.0 - Trainer+ Section and Age Group Reassignment via Quick Edit

The Squadeno WordPress plugin before 1.12.0 does not enforce its restrictions on every way a sport can be saved, allowing users with the lowest-tier Trainer role to change the section, age group, au…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-106029 — WeddingCity Lite <= 1.0.4 - Unauthenticated Arbitrary Post and Attachment Deletion

The WeddingCity Lite WordPress plugin through 1.0.4 does not perform any authorisation or validity checks before deleting posts, pages and media attachments, allowing unauthenticated attackers to pe…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-104684 — Envira Gallery < 1.16.2 - Author+ IDOR via Shortcode

The Envira Gallery WordPress plugin before 1.16.2 does not verify that a user is authorized to read a gallery before rendering it, allowing authors to embed and expose other users' non-public galler…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-104682 — Envira Gallery < 1.16.2 - Contributor Missing Authorization via Convert Gallery REST Route

The Envira Gallery WordPress plugin before 1.16.2 does not correctly check authorization on its gallery-conversion feature, verifying that the requester can edit an arbitrary post they name rather t…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-104681 — Envira Gallery < 1.16.2 - Author+ Non-Public Post Title and Excerpt Disclosure via Galler…

The Envira Gallery WordPress plugin before 1.16.2 does not verify that an image identifier added to a gallery refers to a media attachment the caller is permitted to view, allowing any user able to …

| Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
Showing 20 of 14155 Results