Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-62124 — WordPress N7 | Golf Club Sports & Events theme <= 2.21 - PHP Object Injection vulnerabili…

Unauthenticated PHP Object Injection in N7 | Golf Club Sports & Events <= 2.21 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-62123 — WordPress Invetex theme <= 2.18 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Invetex <= 2.18 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-62120 — WordPress Law Office theme <= 3.20 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Law Office <= 3.20 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.3 HIGH
CVE-2026-62118 — WordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.13.1 - Broken Access…

Unauthenticated Broken Access Control in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.

Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.5 HIGH
CVE-2026-62117 — WordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.13.1 - SQL Injection…

Subscriber SQL Injection in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-62116 — WordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.13.1 - Cross Site Sc…

Unauthenticated Cross Site Scripting (XSS) in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-62115 — WordPress KuteShop theme <= 4.2.9 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in KuteShop <= 4.2.9 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-62100 — WordPress KuteShop theme <= 4.2.9 - Reflected Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in KuteShop <= 4.2.9 versions.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-62099 — WordPress Boutique theme <= 2.3.3 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in Boutique <= 2.3.3 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.5 MEDIUM
CVE-2026-62098 — WordPress Boutique theme <= 2.3.3 - Arbitrary Shortcode Execution vulnerability

Unauthenticated Content Injection in Boutique <= 2.3.3 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-62096 — WordPress Biolife theme <= 3.2.3 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in Biolife <= 3.2.3 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-62095 — WordPress Biolife theme <= 3.2.3 - Reflected Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Biolife <= 3.2.3 versions.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-62094 — WordPress TechOne theme <= 3.0.3 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in TechOne <= 3.0.3 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-62093 — WordPress TechOne theme <= 3.0.3 - Reflected Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in TechOne <= 3.0.3 versions.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-62092 — WordPress Armania theme <= 1.4.8 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in Armania <= 1.4.8 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-62091 — WordPress Armania theme <= 1.4.8 - Reflected Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Armania <= 1.4.8 versions.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-62090 — WordPress WineShop theme <= 3.20 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in WineShop <= 3.20 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-62087 — WordPress Equadio theme <= 1.1.4 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Equadio <= 1.1.4 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-62086 — WordPress Juno theme <= 2.25 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Juno <= 2.25 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-62082 — WordPress Pin WP theme <= 7.0 - Reflected Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Pin WP <= 7.0 versions.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Showing 20 of 14131 Results