Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-66480 — WordPress YITH WooCommerce Product Add-Ons plugin <= 4.34.0 - Sensitive Data Exposure vul…

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in YITH YITH WooCommerce Product Add-Ons allows Retrieve Embedded Sensitive Data. This issue affects YITH Woo…

Remote | Information Disclosure
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-57742 — WordPress Kids Planet theme <= 2.2.14.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group Kids Planet allows Reflected XSS. This issue affects Kids Planet: from n/a throug…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.4 MEDIUM
CVE-2026-107434 — WordPress MicroPayments plugin <= 3.2.9 - Bypass Vulnerability vulnerability

Subscriber Bypass Vulnerability in MicroPayments <= 3.2.9 versions.

micropayments | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-107420 — WordPress Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway plugin <= 1.…

Unauthenticated Bypass Vulnerability in Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway <= 1.7.2 versions.

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-81797 — WordPress Buzz Stone | Magazine & Viral Blog WordPress Theme theme <= 1.0.2 - PHP Object …

Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme <= 1.0.2 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-78535 — WordPress Photolia theme <= 1.0.3 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-78534 — WordPress Educavo theme <= 3.4.2 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Educavo <= 3.4.2 versions.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-78533 — WordPress Qwery theme <= 3.6.1 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Qwery <= 3.6.1 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-78532 — WordPress LMS theme <= 8.3 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in LMS <= 8.3 versions.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-78531 — WordPress Jacqueline theme <= 2.22 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Jacqueline <= 2.22 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.7 HIGH
CVE-2026-78530 — WordPress FoodBakery theme <= 4.6 - Arbitrary File Deletion vulnerability

Subscriber Arbitrary File Deletion in FoodBakery <= 4.6 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-78529 — WordPress Alliance theme <= 3.11 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Alliance <= 3.11 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-66569 — WordPress Kicker theme <= 2.2.1 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Kicker <= 2.2.1 versions.

kicker | Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-66568 — WordPress Original theme <= 1.9.0 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Original <= 1.9.0 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-66567 — WordPress Anesta theme <= 1.5.3 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Anesta <= 1.5.3 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-66566 — WordPress Ambient theme <= 1.7 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in Ambient <= 1.7 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-66565 — WordPress FC United theme <= 1.1.1 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in FC United <= 1.1.1 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-66564 — WordPress ShiftCV theme <= 3.0.14 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in ShiftCV <= 3.0.14 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-66563 — WordPress Windsor theme <= 2.10 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Windsor <= 2.10 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-66483 — WordPress Education Center theme <= 3.6.12 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Education Center <= 3.6.12 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Showing 20 of 14149 Results