Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.4 MEDIUM
CVE-2026-14877 — Data Tables Generator by Supsystic <= 1.12.03 - Authenticated (Contributor+) Stored Cross…

The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id attribute in all versions up to, and including, 1.12.03 due to insufficient input s…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.4 MEDIUM
CVE-2026-14379 — GamiPress <= 7.9.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'video_i…

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_id' parameter in all v…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-14335 — Easy Digital Downloads <= 3.6.9 - Unauthenticated Stored Cross-Site Scripting via PayPal …

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PayPal IPN Parameters in all versions up to, and incl…

easy_digital_downloads | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.1 MEDIUM
CVE-2026-12054 — Download Manager <= 3.3.57 - Unauthenticated DOM-Based Reflected Cross-Site Scripting via…

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'REFERRER' parameter in all versions up to, and including, 3.3.57 due to insufficient input sanitization …

download_manager | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-107323 — Gallery PhotoBlocks 1.3.5 - Contributor+ Stored XSS

The Gallery PhotoBlocks WordPress plugin before 1.3.6 does not sanitize and escape one of its gallery settings before outputting it into an HTML attribute, allowing users with Contributor-level acces…

| Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-107321 — W3 Total Cache < 2.10.6 - Author+ Path Traversal via CDN Media Library Import

The W3 Total Cache WordPress plugin before 2.10.6 does not confine a media-import file copy to the document root, nor enforce an effective file-type restriction on it, allowing users with the Author …

| Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-107120 — Contest Gallery < 33.0.1 - Unauthenticated Email Verification Bypass via Brute-Forceable …

The Contest Gallery WordPress plugin before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step, which relies on a short numeric PIN, allowing una…

| Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-105995 — Booking Package < 1.7.30 - Unauthenticated Booking Customer PII Disclosure

The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal…

| Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-105990 — Accept PayPal Payments Using Contact Form 7 < 4.0.7 - Unauthenticated PII Disclosure via …

The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization checks before exporting stored form submissions, allowing unauthenticated attackers to…

| Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-105989 — Accept PayPal Payments using Contact Form 7 < 4.0.7 - Unauthenticated Transaction Status …

The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization or request-validation checks on one of its AJAX actions, allowing unauthenticated atta…

| Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-105977 — Portfolio Filter Gallery 2.0.2 - 2.2.0 - Contributor+ Cross-User Video Thumbnail Deletion…

The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform a per-object authorization check before deleting an attachment, allowing users with the Contributor role and above to perm…

| Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-105976 — Portfolio Filter Gallery < 2.2.1 - Contributor+ Missing Authorization via Multiple AJAX A…

The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform proper authorization checks in a set of AJAX actions, allowing users with at least the Contributor role to read, modify an…

| Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-104899 — GeoDirectory <= 2.8.187 - Unauthenticated Local File Inclusion via 'design_type' Parameter

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.187 via the 'des…

geodirectory | Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.8 HIGH
CVE-2026-104766 — Appointment Booking Plugin <= 5.7.3 - Authenticated (Custom+) Privilege Escalation to 'se…

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.7.3. This is due to…

Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
4.9 MEDIUM
CVE-2026-104763 — Post Export Import with Media <= 1.17.1 - Authenticated (Administrator+) Path Traversal t…

The Post Export Import with Media plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.17.1 via the 'file_path' parameter parameter. This makes it possibl…

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.4 MEDIUM
CVE-2026-104762 — Kadence Blocks <= 3.7.12 - Authenticated (Author+) Stored Cross-Site Scripting via Block …

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Block Font Family Attribute in all versions up to, and including, …

gutenberg_blocks_with_ai | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-104754 — Rank Math SEO < 1.0.280 - Admin+ Stored XSS via Redirection Source URL

The Rank Math SEO WordPress plugin before 1.0.280 does not escape a stored redirection source value before outputting it in an administrative list view, allowing users who can manage redirections (A…

seo | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-104753 — Rank Math SEO < 1.0.280 - Admin+ SQLi via 'per_page' Parameter

The Rank Math SEO WordPress plugin before 1.0.280 does not properly sanitise and escape a parameter before using it in a SQL query, allowing high-privilege users such as administrators to perform SQ…

seo | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-104752 — Rank Math SEO < 1.0.280 - Admin+ Arbitrary File Upload to RCE via Settings Import

The Rank Math SEO WordPress plugin before 1.0.280 does not correctly validate the type of a file uploaded through its settings import feature, allowing users with administrator-level access to uploa…

seo | Misconfiguration
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
3.1 LOW
CVE-2026-104742 — AI Puffer <= 2.4.89 - Missing Authorization to Authenticated (Subscriber+) Semantic Searc…

The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not prop…

Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Showing 20 of 14166 Results