Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-23113 — io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop

In the Linux kernel, the following vulnerability has been resolved: io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop Currently this is checked before running the pending work. Normally thi…

linux_kernel | Denial of Service
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
0.0 NA
CVE-2025-71200 — mmc: sdhci-of-dwcmshc: Prevent illegal clock reduction in HS200/HS400 mode

In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-of-dwcmshc: Prevent illegal clock reduction in HS200/HS400 mode When operating in HS200 or HS400 timing modes, reducin…

linux_kernel | Denial of Service
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
4.3 MEDIUM
CVE-2026-2312 — Media Library Folders <= 8.3.6 - Insecure Direct Object Reference to Authenticated (Autho…

The Media Library Folders plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 8.3.6 via the delete_maxgalleria_media() and maxgalleria_rename_…

media_library_folders | Remote | Authorization
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-1512 — Essential Addons for Elementor <= 6.5.9 - Authenticated (Contributor+) Stored Cross-Site …

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Info Box widget in all versions up to, an…

essential_addons_for_elementor | Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
7.2 HIGH
CVE-2026-1843 — Super Page Cache <= 5.2.2 - Unauthenticated Stored Cross-Site Scripting via Activity Log

The Super Page Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Activity Log in all versions up to, and including, 5.2.2 due to insufficient input sanitization and outp…

super_page_cache | Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
4.9 MEDIUM
CVE-2026-1258 — Mail Mint <= 1.19.2 - Authenticated (Administrator+) SQL Injection via Multiple API Endpo…

The Mail Mint plugin for WordPress is vulnerable to blind SQL Injection via the 'forms', 'automation', 'email/templates', and 'contacts/import/tutorlms/map' API endpoints in all versions up to, and i…

Remote | Injection
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
4.3 MEDIUM
CVE-2026-1254 — Modula Image Gallery – Photo Grid & Video Gallery <= 2.13.6 - Missing Authorization to Au…

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.6. This is due to the plugin not properly v…

Remote | Authorization
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
5.0 MEDIUM
CVE-2026-1249 — MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 5.3 - 5.10 - Authentica…

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side Request Forgery in versions 5.3 to 5.10 via the 'load_lyrics_ajax_callback' fun…

mp3_audio_player_for_music\,_radio_\&_podcast | Remote | Server-Side Request Forgery
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-0550 — myCred <= 2.9.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'mycred_…

The myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mycred_load_coupon' shortcode in all versions up to, and including, 2.9.7.3 due to insufficient input sa…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2025-8572 — Truelysell Core <= 1.8.7 - Unauthenticated Privilege Escalation via Registration

The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient validation of the user_role parameter during user…

Remote | Authorization
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
7.5 HIGH
CVE-2026-2024 — PhotoStack Gallery <= 0.4.1 - Unauthenticated SQL Injection via 'postid' Parameter

The PhotoStack Gallery plugin for WordPress is vulnerable to SQL Injection via the 'postid' parameter in all versions up to, and including, 0.4.1 due to insufficient escaping on the user supplied par…

Remote | Injection
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
4.3 MEDIUM
CVE-2026-2022 — Smart Forms <= 2.6.99 - Missing Authorization to Authenticated (Subscriber+) Campaign Dat…

The Smart Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'rednao_smart_forms_get_campaigns' AJAX action in all versions up to, and in…

smart_forms | Remote | Authorization
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
7.5 HIGH
CVE-2026-1988 — Flexi Product Slider and Grid for WooCommerce <= 1.0.5 - Authenticated (Contributor+) Loc…

The Flexi Product Slider and Grid for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.5 via the `flexipsg_carousel` shortcode. This is…

Remote | Path Traversal
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
5.4 MEDIUM
CVE-2026-1987 — Scheduler Widget <= 0.1.6 - Insecure Direct Object Reference to Authenticated (Subscriber…

The Scheduler Widget plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 0.1.6. This is due to the `scheduler_widget_ajax_save_event()` functi…

Remote | Authorization
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-1985 — Press3D <= 1.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via Link URL Param…

The Press3D plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 3D Model Gutenberg block in all versions up to, and including, 1.0.2. This is due to the plugin failing to saniti…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
5.3 MEDIUM
CVE-2026-1944 — CallbackKiller service widget <= 1.2 - Missing Authorization to Unauthenticated Arbitrary…

The CallbackKiller service widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cbk_save() function in all versions up to, and inclu…

Remote | Authorization
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-1939 — Percent to Infograph <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…

The Percent to Infograph plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `percent_to_graph` shortcode in all versions up to, and including, 1.0 due to insufficient input san…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-1915 — Simple Plyr <= 0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'post…

The Simple Plyr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'poster' parameter in the 'plyr' shortcode in all versions up to, and including, 0.0.1 due to insufficient in…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-1910 — UpMenu <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'upmenu-menu…

The UpMenu – Online ordering for restaurants plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lang' attribute of the 'upmenu-menu' shortcode in all versions up to, and inclu…

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
6.4 MEDIUM
CVE-2026-1905 — Sphere Manager <= 1.0.2 - Authenticated (Contributor+) Cross-Site Scripting via 'width' S…

The Sphere Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in the 'show_sphere_image' shortcode in all versions up to, and including, 1.0.2 due to …

Remote | Cross-Site Scripting
Feb 14, 2026 Feb 18, 2026
Feb 14, 2026
Feb 18, 2026
Showing 20 of 5046 Results