Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-84225 — Kirki 6.0.0 - 6.2.5 - Authenticated Collaboration Comment Status Modification via IDOR

The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-le…

| Authorization
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-84221 — Kirki 6.0.0 - 6.2.5 - Editor+ SQLi via Content Manager Field ID

The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read …

| Injection
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-84022 — Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via Multiple Shortcode Element Attrib…

The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML attributes, allowing users with the Contributor role and a…

bold_page_builder | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-84021 — Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via bt_bb_button/bt_bb_headline/bt_bb…

The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a filter that can be evaded, allowing users with the Co…

bold_page_builder | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-83544 — Greenshift < 13.2.0 - Contributor+ Stored XSS via Block Animation customProps Attribute

The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it within an HTML attribute, allowing users with contributor-level access and abo…

greenshift | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-83543 — Greenshift < 13.2.0 - Contributor+ SSRF via get-csv-to-json REST Endpoint

The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue re…

greenshift | Server-Side Request Forgery
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-82846 — Masteriyo LMS 1.18.0 - 2.3.3 - Instructor+ Stored XSS via Course Custom Fields

The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role…

| Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-82304 — Music Store – WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-data Handler

The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

| Injection
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-81424 — Accept Stripe Payments < 2.1.4 - Unauthenticated Product Substitution via IDOR

The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, c…

accept_stripe | Authorization
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-81423 — Accept Stripe Payments < 2.1.4 - Open Redirect via IPN Handler

The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect visitors to an arbitrary e…

accept_stripe | Server-Side Request Forgery
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-81404 — IPGP Visitors Origin < 1.6 - Reflected XSS

The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attackers to perform Reflected Cro…

| Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-81348 — My Private Site < 4.2.3 - Unauthenticated Sensitive Information Exposure via RSS Feeds an…

The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post conte…

my_private_site | Authorization
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
7.2 HIGH
CVE-2026-78438 — W3 Total Cache <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via LazyLoad Backg…

The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficie…

w3_total_cache | Remote | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-78362 — SEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation via API Key A…

The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator wh…

| Authentication
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-78150 — Post Carousel 4.0.0 - 4.0.7 - Contributor+ Private and Protected Post Content Disclosure …

The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges and above to copy any priva…

| Authorization
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-78149 — Post Carousel 4.0.0 - 4.0.7 - Unauthenticated Password-Protected Post Content and post_pa…

The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenticated AJAX action, allowing…

| Information Disclosure
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
7.2 HIGH
CVE-2026-77830 — Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.86 - Unauthenticated Stored Cross-…

The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all versions up to, and including…

spam_protection\,_antispam\,_firewall | Remote | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
0.0 NA
CVE-2026-77826 — RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing F…

The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attac…

registrationmagic | Authentication
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
5.0 MEDIUM
CVE-2026-4361 — Divi <= 4.27.6 - Authenticated (Contributor+) Server-Side Request Forgery via 'image_src'…

The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` function usi…

divi divi | Remote | Server-Side Request Forgery
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
6.4 MEDIUM
CVE-2026-3853 — Divi <= 4.27.6 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via V…

The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider_item` shortcode in all versions up to, and including, 4.27…

divi divi | Remote | Cross-Site Scripting
Sep 05, 2026 Sep 05, 2026
Sep 05, 2026
Sep 05, 2026
Showing 20 of 12750 Results