Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-96039 — BA Book Everything <= 1.8.27 - Unauthenticated Stored Cross-Site Scripting via first_name…

The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all versions up to, and including, 1.8.27 due to insufficient input sanitization a…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.4 MEDIUM
CVE-2026-94376 — Better Messages <= 3.0.4 - Authenticated (Subscriber+) Stored DOM-Based Cross-Site Script…

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via User Display Name in all versions up to, …

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.5 MEDIUM
CVE-2026-93899 — Better Messages <= 3.0.4 - Authenticated (Subscriber+) SQL Injection via 'group_id' Messa…

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to generic SQL Injection via 'group_id' Message Meta Parameter in all versions up to, …

Remote | Injection
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.4 MEDIUM
CVE-2026-93897 — GeoDirectory <= 2.8.181 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Tex…

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text-type Custom Field (e.g., 'phone') in all v…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.9 MEDIUM
CVE-2026-93477 — Private action arguments can be set by user input on the bulk destroy and bulk update pat…

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the bulk destroy and bul…

ash | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
9.1 CRITICAL
CVE-2026-93399 — Online Scheduling and Appointment Booking System <= 28.2 - Insecure Direct Object Referen…

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calenda…

Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.2 HIGH
CVE-2026-93303 — HT Contact Form <= 2.10.1 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'fo…

The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'form_data' Rich Text Field via Draft Save/Resume in all v…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
4.3 MEDIUM
CVE-2026-92829 — Blog2Social: Social Media Auto Post & Scheduler <= 9.1.0 - Missing Authorization to Authe…

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.1.0. This is due to the plugin not properly veri…

Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.3 MEDIUM
CVE-2026-92799 — Online Scheduling and Appointment Booking System <= 28.2 - Unauthenticated Authorization …

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions up to, and including, 28.2. This is due …

Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.4 MEDIUM
CVE-2026-92746 — Gutenverse <= 4.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post C…

The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Comment Block 'suffixMain' Attribute in all versions up to, an…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.1 MEDIUM
CVE-2026-92212 — JetFormBuilder <= 3.6.5.3 - Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Varia…

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field in all versions…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
9.1 CRITICAL
CVE-2026-89055 — Customer Reviews for WooCommerce <= 5.120.0 - Missing Authorization to Unauthenticated Ar…

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a …

Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.2 HIGH
CVE-2026-84281 — Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via 'produc…

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta in all versions up to, and including, 6.5.2 due to insuf…

fancy_product_designer | Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.2 HIGH
CVE-2026-84279 — Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via 'output…

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'output_format' parameter in all versions up to, and including, 6.5.2 due to insufficient input sa…

fancy_product_designer | Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.2 HIGH
CVE-2026-83591 — AMP for WP <= 1.1.16 - Unauthenticated Stored Cross-Site Scripting via Comment Content Re…

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Regex Transformation in all versions up to, and including, 1.1.16 d…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-78397 — Link Library < 7.9.6 - Unauthenticated SSRF via Reciprocal Link Validation

The Link Library WordPress plugin before 7.9.6 does not validate the destination of a user-supplied URL before falling back to an unprotected fetch when its safe request is rejected, allowing unauthe…

| Server-Side Request Forgery
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-78394 — Link Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' Parameter

The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a generated image to disk, allowing users with the Contributor role and above to cre…

| Path Traversal
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-78393 — Link Library < 7.9.6 - Reflected XSS via 'link_tags' and 'link_price' Sort and Breadcrumb…

The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the addresses of links it generates on its front-end directory pages, leading to Refl…

| Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
2.4 LOW
CVE-2026-75553 — Tohoku Electric Power Yorisou e Net Hard-Coded Cryptographic Key Vulnerability

Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a hard-coded cryptographic key from the affected product.

| Cryptography
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.8 HIGH
CVE-2026-62062 — WordPress Elementor Website Builder plugin <= 4.3.1 - Cross Site Request Forgery (CSRF) v…

Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1.

website_builder | Remote | Cross-Site Request Forgery
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
Showing 20 of 14187 Results