Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-103347 — WordPress hCaptcha for WP plugin <= 5.3.0 - Bypass Vulnerability vulnerability

Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions.

Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.8 HIGH
CVE-2026-103068 — WordPress ByteCoreStack – MCP Connector for AI Tools plugin <= 1.2.2 - Privilege Escalati…

Subscriber Privilege Escalation in ByteCoreStack &#8211; MCP Connector for AI Tools <= 1.2.2 versions.

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-102378 — WordPress Parallax Section block plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerabili…

Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions.

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.5 HIGH
CVE-2026-100517 — WordPress Photo Reviews for WooCommerce plugin <= 1.2.30 - Insecure Direct Object Referen…

Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions.

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.5 HIGH
CVE-2026-100514 — WordPress REST API Log plugin <= 1.7.2 - Insecure Direct Object References (IDOR) vulnera…

Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions.

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.6 HIGH
CVE-2026-97297 — WordPress Gratisfaction plugin <= 4.6.3 - Broken Access Control vulnerability

Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions.

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.8 HIGH
CVE-2026-97284 — WordPress Icegram plugin <= 3.1.31 - PHP Object Injection vulnerability

Contributor PHP Object Injection in Icegram <= 3.1.31 versions.

Remote | Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.3 MEDIUM
CVE-2026-97281 — WordPress WP Project Manager plugin <= 4.0.7 - Broken Access Control vulnerability

Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions.

wp_project_manager | Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.6 HIGH
CVE-2026-97277 — WordPress Social Boost plugin <= 3.6.2 - Broken Access Control vulnerability

Subscriber Broken Access Control in Social Boost <= 3.6.2 versions.

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-97273 — WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.13 - Cross Site Scripting (XSS…

Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.5 MEDIUM
CVE-2026-97269 — WordPress WPFunnels plugin <= 3.13.1 - Insecure Direct Object References (IDOR) vulnerabi…

Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions.

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-97268 — WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.13 - Cross Site Scripting (XSS…

Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-97260 — WordPress MaxGalleria plugin <= 6.5.3 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions.

maxgalleria | Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.5 MEDIUM
CVE-2026-97258 — WordPress Aruba Migration Tool plugin <= 1.0.4 - Broken Access Control vulnerability

Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions.

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.5 MEDIUM
CVE-2026-97251 — WordPress Bus Ticket Booking with Seat Reservation plugin <= 5.9.3 - Insecure Direct Obje…

Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions.

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.6 HIGH
CVE-2026-95588 — WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Arbitrary File Deletion vulnerabi…

Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions.

Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.2 HIGH
CVE-2026-94390 — WordPress Hide Shipping Method For WooCommerce plugin <= 1.5.4 - PHP Object Injection vul…

Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions.

Remote | Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.5 HIGH
CVE-2026-62073 — WordPress WP Full Stripe Free plugin <= 8.5.6 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions.

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.3 CRITICAL
CVE-2026-62071 — WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability

Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.

Remote | Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.8 CRITICAL
CVE-2026-103752 — WordPress Authorizer plugin <= 3.15.3 - Privilege Escalation vulnerability

Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions.

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Showing 20 of 15019 Results