Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-86833 — MetForm < 4.3.1 - Unauthenticated HTML Injection in Notification Emails via Field Shortco…

The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, allowing unauthenticated attacke…

Remote | Cross-Site Scripting
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.3 MEDIUM
CVE-2026-86816 — WPCafe < 3.0.21 - Unauthenticated Product Data Disclosure via REST API

The WPCafe WordPress plugin before 3.0.21 does not restrict access to some of its REST API endpoints, allowing unauthenticated attackers to read WooCommerce product data, including per-product sales…

Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.5 HIGH
CVE-2026-82212 — Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Bypass via NPG Notification Handler

The Nexi XPay Build WordPress plugin through 7.6.2 does not correctly validate the security token on its payment notification route, accepting the request when the target order has no stored token, w…

Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
8.2 HIGH
CVE-2026-82211 — Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Completion and Order Key Disclosure

The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing attackers to mark arbitrary orders as paid or failed,…

Remote | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.3 MEDIUM
CVE-2026-105322 — Magee Shortcodes <= 2.1.1 - Unauthenticated Mail Relay via Contact Form

The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any…

magee_shortcodes | Remote | Information Disclosure
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.1 HIGH
CVE-2026-105316 — Magee Shortcodes <= 2.1.1 - Reflected XSS via live_preview and magee_create_shortcode Act…

The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the…

magee_shortcodes | Remote | Cross-Site Scripting
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.8 MEDIUM
CVE-2026-104953 — MPG < 4.2.3 - Editor+ SQLi via Project Import

The MPG WordPress plugin before 4.2.3 does not properly validate the structure of imported project data before using it in a database query, allowing users with the Editor role or higher to perform …

Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
2.7 LOW
CVE-2026-104678 — CP Media Player < 1.3.4 - Contributor+ Media Player Settings Update

The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and…

Remote | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.2 HIGH
CVE-2026-104677 — WP Coder 4.0 - 4.5.1 - Editor+ RCE via Global PHP

The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, whic…

Remote | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.8 MEDIUM
CVE-2026-104667 — Animated Number Counters < 3.1 - Editor+ Second-Order SQLi via Counter Order

The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated…

Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.8 MEDIUM
CVE-2026-104653 — Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Crop Dimensions

The Envira Gallery WordPress plugin before 1.16.1 does not sanitise or escape user-supplied gallery display configuration values before storing them and outputting them in an image tag attribute, al…

Remote | Cross-Site Scripting
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.8 MEDIUM
CVE-2026-104652 — Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Image ID

The Envira Gallery WordPress plugin before 1.16.1 does not sanitise and escape a gallery item identifier before outputting it in an image tag attribute, allowing users with the Author role and above…

Remote | Cross-Site Scripting
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.3 MEDIUM
CVE-2026-104651 — Yaad Sarig Payment Gateway For WC < 2.2.13 - Subscriber+ Arbitrary Order Payment Manipula…

The Yaad Sarig Payment Gateway For WC WordPress plugin before 2.2.13 does not verify authorization or that the requesting user owns the target order in several of its order payment-processing actions…

Remote | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.3 MEDIUM
CVE-2026-104050 — Academy LMS < 4.0.0 - Subscriber+ Cross-Course Quiz Answer Disclosure via render_quiz_ans…

The Academy LMS WordPress plugin before 4.0.0 does not verify that a quiz question belongs to the course the requesting user is authorized to access before returning that question's answer options, …

Remote | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.3 MEDIUM
CVE-2026-104049 — Academy LMS < 4.0.0 - Subscriber+ Arbitrary Lesson Content Disclosure via Topic REST Endp…

The Academy LMS WordPress plugin before 4.0.0 does not verify course enrollment or object ownership when returning a lesson's content through one of its REST API routes, allowing users with a self-r…

Remote | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.3 MEDIUM
CVE-2026-103681 — Frontend Dashboard < 3.0.0 - Subscriber+ Profile and Post Field Deletion via fed_user_pro…

The Frontend Dashboard WordPress plugin before 3.0.0 does not perform a capability check in one of its AJAX actions, allowing authenticated users with low privileges, such as subscribers, to delete t…

Remote | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.5 MEDIUM
CVE-2026-103378 — Geliver Akıllı Kargo Pazaryeri 3.0.0 - 3.1.0 - Unauthenticated API Key Disclosure via Pub…

The Geliver Akıllı Kargo Pazaryeri WordPress plugin before 3.1.1 does not prevent unauthenticated access to a log file it stores within its own web-accessible directory, into which it writes the site…

Remote | Information Disclosure
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.9 MEDIUM
CVE-2026-103323 — Integration for Epos Now and WooCommerce 4.6.0 - 4.11.1 - Unauthenticated Action Schedule…

The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2 does not perform an authorization check on one of its REST endpoints, allowing unauthenticated users to retrieve the site's…

Remote | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
8.1 HIGH
CVE-2026-59347 — VMware Workstation and Fusion HGFS stack-based buffer-overflow vulnerability

VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execut…

workstation fusion | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.3 CRITICAL
CVE-2026-59346 — VMware Workstation and Fusion VMXNET3 integer-overflow vulnerability

VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit t…

workstation fusion | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
Showing 20 of 15450 Results