Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-16981 — DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Download via IDOR

The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or ownership check) on one of its shipping-label download…

| Authorization
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-16968 — GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users

The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to re…

| Information Disclosure
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-16942 — WP Custom HTML Pages <= 0.6.2 - Author+ Stored XSS

The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page handlers, nor restrict it to users allowed to post unfiltered HTML, allowing users …

| Cross-Site Scripting
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-16940 — Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path …

The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.…

| Path Traversal
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-16746 — MultiVendorX < 5.0.11 - Store Owner+ Cross-Store Commission Data Disclosure via commissio…

The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-level user to read other ve…

| Authorization
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-16736 — User Registration & Membership < 5.2.6 - Unauthenticated Account Creation While Registrat…

The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated use…

| Authentication
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-16613 — GDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF

The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, allowing an attac…

| Authentication
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-16605 — MultiVendorX < 5.0.11 - Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing…

The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (Store Owner and above…

| Authorization
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-16604 — Content Protector (Passster) < 4.3.6 - Unauthenticated Protected Content Disclosure via C…

The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the protected…

| Information Disclosure
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-16603 — Content Protector (Passster) < 4.3.6 - Unauthenticated Category-Locked Content Disclosure…

The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated users to read the full content, title, and excer…

| Information Disclosure
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-16602 — Content Protector (Passster) < 4.3.6 - Unauthenticated Non-Public Post Content Disclosure…

The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint, allowing unauthenticated users to disclose the co…

| Information Disclosure
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-16583 — Orbit Fox by ThemeIsle < 3.0.8 - Author+ Stored XSS via SVG Upload

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded SVG files when its SVG upload feature is enabled, a…

| Cross-Site Scripting
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-16573 — Bit Form < 3.2.0 - Unauthenticated Stored XSS via SVG Signature Upload

The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upload a crafted SVG file containing JavaScript that…

| Cross-Site Scripting
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-16561 — Sunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment Disclosure

The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging …

| Authorization
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-16055 — Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_lo…

The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password…

| Authentication
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-16036 — miniOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding

The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attac…

| Authentication
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-15372 — WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys Provider

The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's pa…

| Authentication
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-15360 — Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_args

The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL …

| Injection
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-15230 — YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Discl…

The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscribe…

| Authorization
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-15210 — Login/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeo…

The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an…

| Authentication
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
Showing 20 of 9666 Results