Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-25006 — WordPress XStore theme <= 9.6.4 - Arbitrary Shortcode Execution vulnerability

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore xstore allows Code Injection.This issue affects XStore: from n/a through <= 9.6.4.

xstore | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 27, 2026
Feb 19, 2026
Feb 27, 2026
5.3 MEDIUM
CVE-2026-25005 — WordPress Frontend File Manager plugin <= 23.5 - Insecure Direct Object References (IDOR)…

Authorization Bypass Through User-Controlled Key vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This …

frontend_file_manager | Remote | Authorization
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
4.8 MEDIUM
CVE-2026-25004 — WordPress CM Business Directory plugin <= 1.5.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Business Directory cm-business-directory allows Stored XSS.This issue a…

Remote | Cross-Site Scripting
Feb 19, 2026 Mar 03, 2026
Feb 19, 2026
Mar 03, 2026
4.3 MEDIUM
CVE-2026-25003 — WordPress Client Portal plugin <= 1.2.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in madalin.ungureanu Client Portal client-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Portal: from n/a…

client_portal | Remote | Authorization
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
5.3 MEDIUM
CVE-2026-25000 — WordPress Wheel of Life plugin <= 1.2.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Kraft Plugins Wheel of Life wheel-of-life allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wheel of Life: from n/a thr…

wheel_of_life | Remote | Authorization
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
5.3 MEDIUM
CVE-2026-24999 — WordPress Alma plugin <= 5.16.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Alma Alma alma-gateway-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Alma: from n/a through <= 5.16…

alma | Remote | Authorization
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
5.9 MEDIUM
CVE-2026-24392 — WordPress HurryTimer plugin <= 2.14.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nabil Lemsieh HurryTimer hurrytimer allows Stored XSS.This issue affects HurryTimer: from n/a thr…

hurrytimer | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
5.3 MEDIUM
CVE-2026-24375 — WordPress Ultimate Gift Cards For WooCommerce plugin <= 3.2.4 - Broken Access Control vul…

Missing Authorization vulnerability in WP Swings Ultimate Gift Cards For WooCommerce woo-gift-cards-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ult…

ultimate_gift_cards_for_woocommerce | Remote | Authorization
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
7.6 HIGH
CVE-2026-23805 — WordPress Media Search Enhanced plugin <= 0.9.1 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yoren Chang Media Search Enhanced media-search-enhanced allows SQL Injection.This issue affects M…

Remote | Injection
Feb 19, 2026 Feb 24, 2026
Feb 19, 2026
Feb 24, 2026
5.4 MEDIUM
CVE-2026-23804 — WordPress Better Business Reviews plugin <= 0.1.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in BBR Plugins Better Business Reviews better-business-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Bu…

Remote | Authorization
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
6.4 MEDIUM
CVE-2026-23803 — WordPress Smart Auto Upload Images plugin <= 1.2.2 - Server Side Request Forgery (SSRF) v…

Server-Side Request Forgery (SSRF) vulnerability in Burhan Nasir Smart Auto Upload Images smart-auto-upload-images allows Server Side Request Forgery.This issue affects Smart Auto Upload Images: from…

Remote | Server-Side Request Forgery
Feb 19, 2026 Feb 24, 2026
Feb 19, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-23549 — WordPress WpEvently plugin <= 5.1.1 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.1.1.

Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
5.3 MEDIUM
CVE-2026-23548 — WordPress DirectoryPress plugin <= 3.6.25 - Broken Access Control vulnerability

Missing Authorization vulnerability in designinvento DirectoryPress directorypress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DirectoryPress: from n/a …

directorypress | Remote | Authorization
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
7.1 HIGH
CVE-2026-23547 — WordPress CMSMasters Content Composer plugin <= 2.5.8 - Broken Access Control vulnerabili…

Missing Authorization vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CM…

Remote | Authorization
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
6.5 MEDIUM
CVE-2026-23545 — WordPress Aruba HiSpeed Cache plugin <= 3.0.4 - Broken Access Control vulnerability

Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aruba HiSpeed Ca…

aruba_hispeed_cache | Remote | Authorization
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
8.8 HIGH
CVE-2026-23544 — WordPress Valenti theme <= 5.6.3.5 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects Valenti: from n/a through <= 5.6.3.5.

Remote | Injection
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
5.3 MEDIUM
CVE-2026-23543 — WordPress Essential Addons for Elementor plugin <= 6.5.5 - Broken Access Control vulnerab…

Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…

essential_addons_for_elementor | Remote | Authorization
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-23542 — WordPress Grand Restaurant theme <= 7.0.10 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through <= 7.0.10.

grand_restaurant | Remote | Injection
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
0.0 NA
CVE-2026-23541 — WordPress Mail Mint plugin <= 1.19.4 - Broken Access Control vulnerability

Missing Authorization vulnerability in WPFunnels Mail Mint mail-mint allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Mail Mint: from n/a through <= 1.19.4.

| Authorization
Feb 19, 2026 Feb 19, 2026
Feb 19, 2026
Feb 19, 2026
5.3 MEDIUM
CVE-2026-22422 — WordPress Everest Forms plugin <= 3.4.1 - Arbitrary Shortcode Execution vulnerability

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in wpeverest Everest Forms everest-forms allows Code Injection.This issue affects Everest Forms: from n/a t…

everest_forms | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
Showing 20 of 5070 Results