Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-93882 — LearnPress <= 4.4.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Infor…

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the CourseM…

learnpress | Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.1 MEDIUM
CVE-2026-89047 — Social Media Share Buttons & Social Sharing Icons <= 3.0.1 - Reflected DOM-Based Cross-Si…

The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up to, and including, 3.0.1 due to insufficient inpu…

social_media_share_buttons_\&_social_sharing_icons | Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.8 MEDIUM
CVE-2026-78249 — FujiFilm Multifunction Devices and Printers Path Traversal Vulnerability

A path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 1.1.3 and earlier, Apeos C3567 1.1.3, or other products lis…

| Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.8 CRITICAL
CVE-2026-75957 — Ultimate Multisite <= 2.15.0 - Unauthenticated Authentication Bypass via 'checkout_form' …

The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` para…

Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.1 MEDIUM
CVE-2026-19902 — Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via {search-query} Dynamic Tag (Re…

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions up to, and including, 2.8.18 due to insufficient…

ad_inserter | Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.8 HIGH
CVE-2026-19807 — ByteCoreStack <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via wp_update_u…

The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool…

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.8 CRITICAL
CVE-2026-15989 — Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's befor…

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.6 HIGH
CVE-2026-103651 — MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authenticati…

MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter. The HOTP verification logic c…

misp | Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.3 CRITICAL
CVE-2026-103655 — MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period

MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The…

Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.5 MEDIUM
CVE-2026-103544 — datadrivenconstruction OpenConstructionERP Al Provider Configuration ai_client.py wrong s…

A vulnerability was found in datadrivenconstruction OpenConstructionERP up to 14.8.1. The impacted element is an unknown function of the file backend/app/modules/ai/ai_client.py of the component Al P…

openconstructionerp | Remote | Information Disclosure
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.8 CRITICAL
CVE-2025-41753 — Path traversal in dynamically created BACnet File Objects

The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthent…

Remote | Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-96255 — Payments for Hubtel < 1.0.2 - Unauthenticated Payment Gateway Credentials Disclosure via …

The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plai…

| Information Disclosure
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-96200 — Payments for Hubtel < 1.0.2 - Unauthenticated Payment Confirmation Forgery via Delayed Pa…

The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing unauthenticated attackers to…

| Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-96173 — Payments for Hubtel < 1.0.2 - Unauthenticated Order Key Disclosure via IDOR

The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that the requester is authorized to view an order before redirecting a public payment-callback request, allowing unauthenticated …

| Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-92412 — Five Star Restaurant Reviews < 2.3.14 - Reflected XSS

The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbi…

| Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-90974 — WP Fusion Lite 3.37.14 - 3.47.14 - Unauthenticated CRM Integration Settings Update

The WP Fusion Lite WordPress plugin before 3.48.0 does not require authentication on a settings handler that runs during admin initialization, allowing unauthenticated users to overwrite the site's …

| Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-90972 — WP Fusion Lite < 3.48.0 - Subscriber+ User Email Disclosure and Cross-User CRM Data Delet…

The WP Fusion Lite WordPress plugin before 3.48.0 does not perform a capability check on two of its admin AJAX handlers, allowing any authenticated subscriber to read other users' email addresses an…

| Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-89296 — Pro Like Button < 2.0 - Unauthenticated SQLi via 'postid' Parameter

The Pro Like Button WordPress plugin before 2.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

| Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
4.3 MEDIUM
CVE-2026-88999 — Redux Framework <= 4.5.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrar…

The Redux Framework plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.14 This is due to the plugin not properly verifying that a user is authorized …

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-87973 — If-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion Name

The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name before storing it, nor escape it when rendering the analytics page, allowing users with editor-level acce…

| Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Showing 20 of 14976 Results