Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-32377 — WordPress Pranayama Yoga theme <= 1.2.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in raratheme Pranayama Yoga pranayama-yoga allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pranayama Yoga: from n/a thro…

Remote | Authorization
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
5.3 MEDIUM
CVE-2026-32376 — WordPress Kalon theme <= 1.2.9 - Broken Access Control vulnerability

Missing Authorization vulnerability in raratheme Kalon kalon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kalon: from n/a through <= 1.2.9.

Remote | Authorization
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
5.3 MEDIUM
CVE-2026-32375 — WordPress Travel Diaries theme <= 1.2.4 - Broken Access Control vulnerability

Missing Authorization vulnerability in raratheme Travel Diaries travel-diaries allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel Diaries: from n/a thro…

Remote | Authorization
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
5.3 MEDIUM
CVE-2026-32374 — WordPress The Minimal theme <= 1.2.9 - Broken Access Control vulnerability

Missing Authorization vulnerability in raratheme The Minimal the-minimal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Minimal: from n/a through <= 1.…

Remote | Authorization
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
5.4 MEDIUM
CVE-2026-32373 — WordPress SMS Alert Order Notifications plugin <= 3.9.0 - Broken Access Control vulnerabi…

Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order N…

Remote | Authorization
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
5.3 MEDIUM
CVE-2026-32372 — WordPress ShopBuilder – Elementor WooCommerce Builder Addons plugin <= 3.2.4 - Sensitive …

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Builder Addons shopbuilder allows Retrieve Embedded Sensiti…

shopbuilder | Remote | Information Disclosure
Mar 13, 2026 Mar 17, 2026
Mar 13, 2026
Mar 17, 2026
5.3 MEDIUM
CVE-2026-32371 — WordPress Elegant Pink theme <= 1.3.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in raratheme Elegant Pink elegant-pink allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elegant Pink: from n/a through <=…

Remote | Authorization
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
5.3 MEDIUM
CVE-2026-32370 — WordPress Influencer theme <= 1.1.7 - Broken Access Control vulnerability

Missing Authorization vulnerability in raratheme Influencer influencer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Influencer: from n/a through <= 1.1.7.

Remote | Authorization
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
7.5 HIGH
CVE-2026-32369 — WordPress Medilink-Core plugin < 2.0.7 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Medilink-Core medilink-core allows PHP Local File Inclusion.This i…

Remote | Path Traversal
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
8.5 HIGH
CVE-2026-32368 — WordPress Geo to Lat plugin <= 1.0.19 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in delphiknight Geo to Lat geo-to-lat allows Blind SQL Injection.This issue affects Geo to Lat: from…

Remote | Injection
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
9.1 CRITICAL
CVE-2026-32367 — WordPress Modal Dialog plugin <= 3.5.16 - Remote Code Execution (RCE) vulnerability

Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dialog allows Remote Code Inclusion.This issue affects Modal Dialog: from n/a through <=…

modal_dialog | Remote | Injection
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
8.5 HIGH
CVE-2026-32366 — WordPress Collapsing Categories plugin <= 3.0.9 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Categories collapsing-categories allows Blind SQL Injection.This issue affect…

Remote | Injection
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
8.5 HIGH
CVE-2026-32365 — WordPress Collapsing Archives plugin <= 3.0.7 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Archives collapsing-archives allows Blind SQL Injection.This issue affects Co…

collapsing_archives | Remote | Injection
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
7.5 HIGH
CVE-2026-32364 — WordPress Turbo Manager plugin < 4.0.8 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in redqteam Turbo Manager turbo-manager allows PHP Local File Inclusion.This issu…

Remote | Path Traversal
Mar 13, 2026 Mar 17, 2026
Mar 13, 2026
Mar 17, 2026
5.3 MEDIUM
CVE-2026-32363 — WordPress WPLifeCycle plugin <= 3.3.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Funlus Oy WPLifeCycle free-php-version-info allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLifeCycle: from n/a thr…

Remote | Authorization
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
5.3 MEDIUM
CVE-2026-32362 — WordPress WP Sessions Time Monitoring Full Automatic plugin <= 1.1.3 - Broken Access Cont…

Missing Authorization vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affe…

Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
6.5 MEDIUM
CVE-2026-32361 — WordPress Editorial Calendar plugin <= 3.9.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marketing Fire Editorial Calendar editorial-calendar allows DOM-Based XSS.This issue affects Edit…

Remote | Cross-Site Scripting
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
5.9 MEDIUM
CVE-2026-32360 — WordPress Rich Showcase for Google Reviews plugin <= 6.9.4.3 - Cross Site Scripting (XSS)…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in richplugins Rich Showcase for Google Reviews widget-google-reviews allows Stored XSS.This issue a…

plugin_for_google_reviews | Remote | Cross-Site Scripting
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
6.5 MEDIUM
CVE-2026-32359 — WordPress Icon List Block plugin <= 1.2.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Icon List Block icon-list-block allows Stored XSS.This issue affects Icon List Block: fr…

Remote | Cross-Site Scripting
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
7.6 HIGH
CVE-2026-32358 — WordPress Booking Calendar plugin <= 10.14.15 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevelop Booking Calendar booking allows Blind SQL Injection.This issue affects Booking Calendar…

booking_calendar | Remote | Injection
Mar 13, 2026 Mar 16, 2026
Mar 13, 2026
Mar 16, 2026
Showing 20 of 5443 Results