Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-8978 — OptinCraft <= 1.2.0 - Authenticated (Administrator+) SQL Injection via 'order_by' Paramet…

The OptinCraft – Drag & Drop Optins & Popup Builder for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.2.0 …

| Injection
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
0.0 NA
CVE-2026-7792 — WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via …

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to an…

| Authentication
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
0.0 NA
CVE-2026-2500 — Quick Playground <= 1.3.4 - Authenticated (Administrator+) Arbitrary File Read via 'filen…

The Quick Playground plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.4. This is due to the `qckply_data()` function passing the user-supplied `filename`…

| Path Traversal
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
0.0 NA
CVE-2026-8502 — LearnPress <= 4.3.6 - Unauthenticated Sensitive Information Exposure via 'c_status' and '…

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6 via the 'retu…

| Information Disclosure
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
0.0 NA
CVE-2026-7796 — EmbedPress <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block …

The EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block 'url' attribute in al…

| Cross-Site Scripting
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
0.0 NA
CVE-2026-7665 — Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Inform…

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_mor…

| Information Disclosure
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
0.0 NA
CVE-2026-7795 — Click to Chat <= 4.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'num…

The Click to Chat – WA Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [chat] shortcode 'num' parameter in all versions up to, and including, 4.38. This is due to ins…

| Cross-Site Scripting
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
0.0 NA
CVE-2026-7537 — MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload v…

The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. This is due to no file type,…

| Authentication
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
0.0 NA
CVE-2026-7566 — LearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object…

The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted input . This makes it …

| Injection
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
0.0 NA
CVE-2026-7565 — LearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Rea…

The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Traversal in all versions up to, and including, 4.1.4 via the 'import-user-file' param…

| Path Traversal
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
0.0 NA
CVE-2026-9280 — Ad Inserter <= 2.8.15 - Reflected Cross-Site Scripting via URL Parameters in iframe Mode

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Parameters in iframe Mode in all versions up to, and including, 2.8.15 due to i…

| Cross-Site Scripting
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
0.0 NA
CVE-2026-9197 — Smart Slider 3 <= 3.5.1.36 - Authenticated (Administrator+) Path Traversal to Arbitrary F…

The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1.36 via the replaceHTMLImage function. This makes it possible for authenticated…

smart_slider_3 | Path Traversal
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
0.0 NA
CVE-2026-8991 — Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Authenticated (Adminis…

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings in all versio…

| Cross-Site Scripting
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
6.4 MEDIUM
CVE-2026-9281 — Master Addons For Elementor <= 3.1.0 - Authenticated (Author+) Stored Cross-Site Scriptin…

The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jtlma_custom_js' Page Settin…

Remote | Cross-Site Scripting
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
4.3 MEDIUM
CVE-2026-9008 — Page-list <= 6.2 - Missing Authorization to Authenticated (Contributor+) Sensitive Inform…

The Page-list plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.2. This is due to the pagelist_unqprfx_ext_shortcode() function (the [pagelist_ext] /…

Remote | Authorization
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
7.2 HIGH
CVE-2026-8901 — Integration for Freshsales <= 1.0.15 - Unauthenticated Stored Cross-Site Scripting via Fo…

The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Submission Data in all versions …

Remote | Cross-Site Scripting
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
7.2 HIGH
CVE-2026-8438 — All-In-One Security (AIOS) <= 5.4.7 - Unauthenticated Stored Cross-Site Scripting via RES…

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.4.7. This is due to insufficient input sanit…

Remote | Cross-Site Scripting
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
4.3 MEDIUM
CVE-2026-9719 — LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.0. This is due to missin…

Remote | Cross-Site Request Forgery
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
7.5 HIGH
CVE-2026-9290 — WP User Manager <= 2.9.17 - Unauthenticated Path Traversal to Local File Inclusion via 't…

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) functi…

Remote | Path Traversal
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
4.3 MEDIUM
CVE-2026-8976 — RSS Aggregator by Feedzy <= 5.1.7 - Missing Authorization to Authenticated (Contributor+)…

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.7…

Remote | Authorization
Jun 06, 2026 Jun 06, 2026
Jun 06, 2026
Jun 06, 2026
Showing 20 of 7268 Results