Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-93742 — Totolink A3002MU formWsc command injection

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes com…

a3002mu | Injection
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-9858 — Partial Shipment for Woocommerce <= 3.4 - Missing Authorization to Authenticated (Subscri…

The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipment, wxp_order_item_shipment, and wxp_ord…

| Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-9613 — Datalogics Ecommerce Delivery <= 2.6.65 - Missing Authorization to Authenticated (Subscri…

The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifyin…

| Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-76579 — LiteSpeed Cache <= 7.9 - Reflected Cross-Site Scripting via ESI 'esi' Parameter

The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7.9 due to insufficient input sanitization and o…

litespeed_cache | Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-1256 — YS LeadGen – Popups, Opt-ins & Lead Capture <= 2.1.4 - Missing Authorization to Authentic…

The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and including, 2.1.4 due to missing capabi…

| Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-9766 — Empik for Woocommerce <= 1.5.1 - Missing Authorization to Authenticated (Subscriber+) Arb…

The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the plugin not properly verifying that a user is autho…

| Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-9289 — WordLift <= 3.54.10 - Unauthenticated Sensitive Information Exposure in JSON-LD REST API …

The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 via the JSON-LD REST API endpoints. This is d…

| Information Disclosure
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-1255 — YS LeadGen – Popups, Opt-ins & Lead Capture <= 2.1.4 - Unauthenticated Information Disclo…

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible t…

| Information Disclosure
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-18346 — TikTok <= 1.4.1 - Missing Authorization to Unauthenticated TikTok Integration Takeover vi…

The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1. This is due to the plugin not properly verifying that a user is authorized to perfor…

| Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-8354 — Gum Addon for Elementor <= 1.3.15 - Authenticated (Contributor+) Stored Cross-Site Script…

The Gum Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pop_tag' parameter in all versions up to, and including, 1.3.15 due to insufficient input saniti…

| Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-5410 — Redux Framework <= 4.5.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting via S…

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is due to insufficient input sanitization and…

| Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.5 MEDIUM
CVE-2026-9855 — Custom Field Template <= 2.7.8 - Authenticated (Contributor+) SQL Injection via 'post_ID'…

The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all versions up to, and including, 2.7.8 due to insufficient escaping on the user …

Remote | Injection
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
5.3 MEDIUM
CVE-2026-9832 — Payment Gateway of Stripe for WooCommerce <= 5.0.8 - Unauthenticated Improper Verificatio…

The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the pu…

Remote | Authentication
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.3 MEDIUM
CVE-2026-9615 — Flex Import <= 3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modif…

The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. This is due to the license_activate_fleximp() and license_deactivate_fleximp() f…

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.5 MEDIUM
CVE-2026-9232 — Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Contributor+) Sens…

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for auth…

Remote | Information Disclosure
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.1 MEDIUM
CVE-2026-87917 — MC4WP: Mailchimp for WordPress <= 4.14.0 - Reflected Cross-Site Scripting via 'data' Dyna…

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data' Dynamic Content Tag in all versions up to, and including, 4.14.0 due to insufficient…

Remote | Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
8.1 HIGH
CVE-2026-85658 — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Res…

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all ve…

Remote | Injection
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.7 MEDIUM
CVE-2026-7527 — WP Ghost (Hide My WP Ghost) <= 7.0.02 - Unauthenticated Open Redirect via 'redirect_to' P…

The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 7.0.02. This is due to the plugin not properly validati…

Remote | Misconfiguration
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.9 MEDIUM
CVE-2026-75959 — GoPay for WooCommerce <= 1.0.36 - Authenticated (Shop Manager+) SQL Injection via 'log_ta…

The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'log_table_filter' parameter in all versions up to, and including, 1.0.36 due to insufficient escaping on…

Remote | Injection
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.9 MEDIUM
CVE-2026-6295 — WP Optimizer <= 2.5.0 - Authenticated (Administrator+) SQL Injection via 's' Parameter

The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.0. This is due to an unsafe subquery-detection branch in the Query::…

Remote | Injection
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
Showing 20 of 14313 Results