Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-85309 — WordPress Ultimate Maps by Supsystic plugin <= 1.5.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Maps by Supsystic: fr…

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.3 MEDIUM
CVE-2026-85308 — WordPress SureForms plugin <= 2.12.5 - Insecure Direct Object References (IDOR) vulnerabi…

Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: fr…

sureforms | Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.3 MEDIUM
CVE-2026-85307 — WordPress KP Agent Ready plugin < 1.2.08 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready allows Retrieve Embedded Sensitive Data. This issue affects KP Agent Ready: from n/a before 1.2.08.

Remote | Information Disclosure
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-85306 — WordPress MountDev AI MCP Connector for WordPress plugin <= 1.6.5 - Broken Access Control…

Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mount…

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.4 MEDIUM
CVE-2026-85305 — WordPress SEOPress plugin <= 10.1 - Server Side Request Forgery (SSRF) vulnerability

Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress: from n/a through 10.1.

Remote | Server-Side Request Forgery
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.3 MEDIUM
CVE-2026-85304 — WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.…

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. …

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-85303 — WordPress Booking and Rental Manager plugin <= 2.7.7 - Cross Site Scripting (XSS) vulnera…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking and Ren…

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-85302 — WordPress WPKoi Templates for Elementor plugin <= 3.7.2 - Cross Site Scripting (XSS) vuln…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects WP…

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.9 MEDIUM
CVE-2026-85242 — Server-Side Request Forgery via Favicon Redirect to Local Network Resources in Playwright…

PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application validates the initial favicon…

playwright_capture | Remote | Server-Side Request Forgery
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-85186 — itsourcecode Online Medicine Delivery System Customer Controller controller.php doupdatei…

A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function doupdateimage of the file /customer/controller.php?action=photos of …

online_medicine_delivery_system | Remote | Misconfiguration
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-84849 — WordPress Pre-Orders for WooCommerce plugin <= 2.3 - Bypass Vulnerability vulnerability

Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.

Remote | Authentication
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-84848 — WordPress Quick Event Manager plugin <= 9.17 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-84847 — WordPress Quick Event Manager plugin <= 9.17 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-84836 — WordPress WC Ukraine Shipping plugin <= 1.22.3 - Insecure Direct Object References (IDOR)…

Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions.

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-84834 — WordPress JobSearch plugin <= 3.2.0 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.

jobsearch_wp_job_board jobsearch | Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-84814 — WordPress Bricksforge plugin <= 3.1.8.8 - Privilege Escalation vulnerability

Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.3 CRITICAL
CVE-2026-84813 — WordPress GeoDirectory plugin <= 2.8.174 - SQL Injection vulnerability

Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.

geodirectory | Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-84812 — WordPress BP Better Messages plugin <= 2.15.27 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.1 HIGH
CVE-2026-84779 — WordPress Agentimus – AI SEO, llms.txt & MCP for AI Agents plugin <= 1.51.0 - Broken Acce…

Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt &amp; MCP for AI Agents <= 1.51.0 versions.

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-84778 — WordPress Migrate Guru – Site Migration & Cloning plugin <= 6.65 - Denial of Service Atta…

Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration &amp; Cloning <= 6.65 versions.

Remote | Denial of Service
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Showing 20 of 12630 Results