Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-87786 — Dewa Kirim <= 1.0.0 - Unauthenticated Stored XSS via Checkout Coordinates

The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated users to store JavaS…

| Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-86824 — Newsletter < 9.3.8 - Unauthenticated Subscriber PII Disclosure and Modification via Predi…

The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed hash, allowing an unauthenticated a…

newsletter | Cryptography
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-86788 — HT Mega 3.2.0 - 3.2.5 - Contributor+ Stored XSS via Section Headline Tag

The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several of its widgets and blocks to a safe allowlist, allow…

| Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-86710 — Login with QR <= 1.0.0 - Unauthenticated Authentication Bypass via 'autologin_code' Param…

The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated at…

| Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-86709 — The Pressengine <= 1.0 - Unauthenticated Authentication Bypass

The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including admi…

| Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-86707 — Private Feed Key <= 0.1 - Unauthenticated Authentication Bypass via 'feedkey' Parameter

The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unau…

| Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-86446 — LearnPress 4.4.3 - 4.4.6 - Unauthenticated Quiz Answer Disclosure via check-answer REST E…

The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is checked, allowing unauthenticated attackers to obtain the correct answer to ever…

learnpress | Information Disclosure
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-85130 — WPLP Cookie Consent < 4.4.4 - Unauthenticated Stored XSS via Consent Logs

The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for the JavaScript context it is later output in on an administrative screen, allowi…

| Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-85128 — Choose User Role at Registration for WooCommerce < 1.3.3 - Unauthenticated Privilege Esca…

The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to offer, allowing unauthenticated use…

| Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2025-15697 — Dictionary <= 1.0 - Reflected XSS via Multiple Parameters

The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform…

| Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.1 HIGH
CVE-2026-87935 — Paid Downloads <= 3.15 - Unauthenticated Arbitrary File Upload via 'paiddownloads_update_…

The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization …

Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.8 CRITICAL
CVE-2026-87796 — Multi Uploader for Gravity Forms <= 1.1.9 - Unauthenticated Arbitrary File Upload via Chu…

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient fi…

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
4.9 MEDIUM
CVE-2026-50604 — Unauthenticated Access Vulnerability in NitroSense and PredatorSense Software

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granti…

| Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.4 HIGH
CVE-2026-25294 — Buffer Over-read in WLAN Firmware

Transient DOS while parsing frame during channel usage.

| Denial of Service
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.8 HIGH
CVE-2026-25290 — Integer Overflow or Wraparound in OOBM

Memory Corruption when validating large data buffers from external sources using addition to check buffer length.

| Memory Corruption
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.3 HIGH
CVE-2026-25284 — Buffer Over-read in OOBM

Information Disclosure when a pointer is reused after being deallocated.

| Information Disclosure
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.8 HIGH
CVE-2026-25283 — Stack-based Buffer Overflow in OOBM

Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.

| Memory Corruption
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.9 HIGH
CVE-2026-25282 — Out-of-bounds Read in OOBM

Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.

| Memory Corruption
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.4 HIGH
CVE-2026-25281 — Allocation of Resources Without Limits or Throttling in OOBM

Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.

| Denial of Service
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.8 HIGH
CVE-2026-25280 — Out-of-bounds Write in DSP Service

Memory corruption when processing escape handling flow with insufficient user buffer sizes.

| Memory Corruption
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Showing 20 of 14837 Results