Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-81348 — My Private Site < 4.2.3 - Unauthenticated Sensitive Information Exposure via RSS Feeds an…

The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post conte…

my_private_site | Authorization
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
7.2 HIGH
CVE-2026-78438 — W3 Total Cache <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via LazyLoad Backg…

The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficie…

w3_total_cache | Remote | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-78362 — SEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation via API Key A…

The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator wh…

| Authentication
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-78150 — Post Carousel 4.0.0 - 4.0.7 - Contributor+ Private and Protected Post Content Disclosure …

The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges and above to copy any priva…

| Authorization
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-78149 — Post Carousel 4.0.0 - 4.0.7 - Unauthenticated Password-Protected Post Content and post_pa…

The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenticated AJAX action, allowing…

| Information Disclosure
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
7.2 HIGH
CVE-2026-77830 — Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.86 - Unauthenticated Stored Cross-…

The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all versions up to, and including…

spam_protection\,_antispam\,_firewall | Remote | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-77826 — RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing F…

The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attac…

registrationmagic | Authentication
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
5.0 MEDIUM
CVE-2026-4361 — Divi <= 4.27.6 - Authenticated (Contributor+) Server-Side Request Forgery via 'image_src'…

The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` function usi…

divi divi | Remote | Server-Side Request Forgery
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
6.4 MEDIUM
CVE-2026-3853 — Divi <= 4.27.6 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via V…

The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider_item` shortcode in all versions up to, and including, 4.27…

divi divi | Remote | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
8.8 HIGH
CVE-2026-19887 — Welcart e-Commerce <= 2.12.1 - Unauthenticated Arbitrary File Deletion via PHP Object Inj…

The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callba…

welcart_e-commerce | Remote | Injection
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-19861 — JetFormBuilder < 3.6.5.2 - Unauthenticated Stored XSS via WYSIWYG Field in Notification E…

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it send…

| Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-19858 — JetFormBuilder < 3.6.5.2 - Unauthenticated Password Hash and Arbitrary Metadata Disclosur…

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthentica…

| Authorization
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
7.2 HIGH
CVE-2026-19769 — Ninja Forms <= 3.15.1 - Unauthenticated Stored Cross-Site Scripting via Repeater Child 't…

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key in all ver…

ninja_forms | Remote | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
6.1 MEDIUM
CVE-2026-18843 — Beaver Builder Plugin (Pro Version) <= 2.11.0.1 - Reflected Cross-Site Scripting via 'no_…

The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all versions up to, and including, …

beaver_builder | Remote | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
7.2 HIGH
CVE-2026-18406 — SureForms <= 2.12.2 - Unauthenticated Stored Cross-Site Scripting via Text Field Entity-E…

The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field Entity-Encoded Payload in all versions up …

Remote | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
7.2 HIGH
CVE-2026-16649 — Gravity Forms <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via Post Body Field…

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 due to insufficient input sanitization and o…

Remote | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
7.2 HIGH
CVE-2026-15984 — QuickCal <= 1.0.20 - Unauthenticated Stored Cross-Site Scripting via Custom Field Paramet…

The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and including, 1.0.20 due to insufficient input sanitization and outp…

Remote | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-15247 — Search Atlas SEO < 2.6.24 - Subscriber+ Google Service Account Credential Overwrite/Delet…

The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated…

| Authentication
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
6.5 MEDIUM
CVE-2026-14975 — WP File Download <= 6.3.8 - Authenticated (Subscriber+) Arbitrary File Read via Path Trav…

The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter. This makes it possible for authenticated atta…

wp_file_download | Remote | Path Traversal
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2025-15694 — Joli Table Of Contents 2.0.0 - 2.8.0 - Admin+ Stored XSS

The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as admi…

| Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
Showing 20 of 12769 Results