Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.7 LOW
CVE-2026-81200 — MasterStudy LMS < 3.7.42 - Instructor+ Cross-Tenant Order Billing PII Disclosure via IDOR

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order bil…

masterstudy_lms | Remote | Authorization
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
4.8 MEDIUM
CVE-2026-81026 — MasterStudy LMS < 3.7.40 - Unauthenticated Payment Bypass via PayPal IPN

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order complete…

masterstudy_lms | Remote | Authentication
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
4.1 MEDIUM
CVE-2026-80488 — WP Ultimate CSV Importer < 9.0 - Admin+ SQLi via AIOSEO Import Fields

The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such…

Remote | Injection
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
4.3 MEDIUM
CVE-2026-80311 — Stripe Payment Forms by WP Full Pay < 8.5.5 - Cross-Customer Subscription Cancellation vi…

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before cancelling it…

Remote | Authorization
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
4.9 MEDIUM
CVE-2026-77786 — Rank Math SEO < 1.0.277 - Editor+ Core Settings Modification via fix-site-seo Ability

The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed, allowing…

seo | Remote | Authorization
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
2.7 LOW
CVE-2026-77704 — Amelia 1.2.32 - 2.4.8 - Amelia Customer+ Appointment Status Update and Self-Approval

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing c…

Remote | Authorization
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
9.3 CRITICAL
CVE-2026-77012 — Icollect <= 1.0.0 - Unauthenticated Arbitrary File Read, SSRF and Path Traversal File Wri…

The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or desti…

Remote | Path Traversal
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-77010 — HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Moderator J…

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation checks on its REST API routes and does not consistently enforce the per-class acce…

Remote | Authorization
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-77008 — HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Plugin Sett…

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation or authentication check when saving its settings, allowing unauthenticated users …

Remote | Authentication
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
7.5 HIGH
CVE-2026-77007 — HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated BigBlueButt…

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API routes, allowing unauthenticated users to retriev…

Remote | Authorization
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
7.5 HIGH
CVE-2026-76586 — BookingPress 1.5.6 - 1.6.2 - Unauthenticated Booking Price Manipulation via PayPal Paymen…

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirmin…

appointment_booking_calendar | Remote | Authorization
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
8.2 HIGH
CVE-2026-76548 — Profile Builder < 4.0.1 - Unauthenticated Unpublished Content and Media Modification via …

The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This…

profile_builder | Remote | Authorization
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
6.6 MEDIUM
CVE-2026-76547 — Profile Builder < 4.0.1 - Admin+ PHP Object Injection via Import/Export

The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators…

profile_builder | Remote | Injection
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
6.8 MEDIUM
CVE-2026-76546 — Profile Builder < 4.0.1 - Contributor+ Stored XSS via Format Date Shortcode

The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scr…

profile_builder | Remote | Cross-Site Scripting
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
5.3 MEDIUM
CVE-2026-19430 — CatFolders Document Gallery Pro < 2.0.7 - Unauthenticated Missing Authorization via downl…

The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing un…

Remote | Authorization
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-18234 — MStore API < 4.21.1 - Subscriber+ Arbitrary Order Payment Bypass via Wallet

The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does not deduct the wallet balance for most payment…

mstore_api | Remote | Authorization
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
6.5 MEDIUM
CVE-2026-18233 — MStore API < 4.21.1 - Subscriber+ Arbitrary Order Completion

The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints belongs to the requester, allowing any authenticated user, including Subscriber…

mstore_api | Remote | Authorization
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
5.4 MEDIUM
CVE-2026-17522 — Newsletters < 4.17 - Arbitrary Plugin Option Update via CSRF

The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its settings screens, and writes every submitted parameter into its own options, allowin…

newsletters | Remote | Cross-Site Request Forgery
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
4.8 MEDIUM
CVE-2026-17520 — Newsletters < 4.17 - Unauthenticated API Access via Predictable API Key

The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute t…

newsletters | Remote | Cryptography
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
9.1 CRITICAL
CVE-2026-16947 — Total Processing Card Payments for WooCommerce <= 7.3 - Unauthenticated SSRF leading to P…

The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify…

Remote | Server-Side Request Forgery
Aug 29, 2026 Aug 30, 2026
Aug 29, 2026
Aug 30, 2026
Showing 20 of 11969 Results