Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-24988 — WordPress The Events Calendar Shortcode & Block plugin <= 3.1.1 - Cross Site Scripting (X…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Hogg The Events Calendar Shortcode &amp; Block the-events-calendar-shortcode allows Stored …

Remote | Cross-Site Scripting
Feb 03, 2026 Feb 04, 2026
Feb 03, 2026
Feb 04, 2026
5.4 MEDIUM
CVE-2026-24986 — WordPress Simple Membership WP user Import plugin <= 1.9.1 - Cross Site Request Forgery (…

Cross-Site Request Forgery (CSRF) vulnerability in wp.insider Simple Membership WP user Import simple-membership-wp-user-import allows Cross Site Request Forgery.This issue affects Simple Membership …

simple_membership_wp_user_import | Remote | Cross-Site Request Forgery
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
4.3 MEDIUM
CVE-2026-24985 — WordPress WP Forms Signature Contract Add-On plugin <= 1.8.2 - Broken Access Control to N…

Missing Authorization vulnerability in approveme WP Forms Signature Contract Add-On wp-forms-signature-contract-add-on allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

Remote | Authorization
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
6.5 MEDIUM
CVE-2026-24984 — WordPress Visual Link Preview plugin <= 2.2.9 - Broken Access Control vulnerability

Missing Authorization vulnerability in Brecht Visual Link Preview visual-link-preview allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Visual Link Preview: f…

visual_link_preview | Remote | Authorization
Feb 03, 2026 Feb 27, 2026
Feb 03, 2026
Feb 27, 2026
5.3 MEDIUM
CVE-2026-24982 — WordPress Spectra plugin <= 2.19.17 - Broken Access Control vulnerability

Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from …

spectra | Remote | Authorization
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
5.3 MEDIUM
CVE-2026-24967 — WordPress Amelia plugin <= 1.2.38 - Broken Access Control vulnerability

Missing Authorization vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through <= 1.2.38.

amelia | Remote | Authorization
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
4.3 MEDIUM
CVE-2026-24966 — WordPress Copyscape Premium plugin <= 1.4.1 - Cross Site Request Forgery (CSRF) vulnerabi…

Cross-Site Request Forgery (CSRF) vulnerability in Copyscape Copyscape Premium copyscape-premium allows Cross Site Request Forgery.This issue affects Copyscape Premium: from n/a through <= 1.4.1.

Remote | Cross-Site Request Forgery
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
4.3 MEDIUM
CVE-2026-24965 — WordPress Contest Gallery plugin <= 28.1.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a…

Remote | Authorization
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
4.3 MEDIUM
CVE-2026-24962 — WordPress Sigmize plugin <= 0.0.9 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Sigmize sigmize allows Cross Site Request Forgery.This issue affects Sigmize: from n/a through <= 0.0.9.

Remote | Cross-Site Request Forgery
Feb 03, 2026 Feb 09, 2026
Feb 03, 2026
Feb 09, 2026
5.4 MEDIUM
CVE-2026-24961 — WordPress Grand Blog theme < 3.1.5 - Server Side Request Forgery (SSRF) vulnerability

Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Server Side Request Forgery.This issue affects Grand Blog: from n/a through < 3.1.5.

Remote | Server-Side Request Forgery
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
6.5 MEDIUM
CVE-2026-24958 — WordPress JetElements For Elementor plugin <= 2.7.12.2 - Cross Site Scripting (XSS) vulne…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows DOM-Based XSS.This issue affects JetElem…

jetelements_for_elementor | Remote | Cross-Site Scripting
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
6.5 MEDIUM
CVE-2026-24957 — WordPress Strong Testimonials plugin <= 3.2.20 - Broken Access Control vulnerability

Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Strong Testimonials:…

Remote | Authorization
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
8.8 HIGH
CVE-2026-24954 — WordPress WpEvently plugin <= 5.0.8 - Deserialization of untrusted data vulnerability

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.0.8.

Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
6.5 MEDIUM
CVE-2026-24952 — WordPress Seriously Simple Podcasting plugin <= 3.14.1 - Cross Site Scripting (XSS) vulne…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Stored XSS.This issue…

seriously_simple_podcasting | Remote | Cross-Site Scripting
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
4.3 MEDIUM
CVE-2026-24951 — WordPress myCred plugin <= 2.9.7.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 2.9.7.3.

Remote | Authorization
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
4.3 MEDIUM
CVE-2026-24947 — WordPress LA-Studio Element Kit for Elementor plugin < 1.5.6.3 - Broken Access Control vu…

Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA…

element_kit_for_elementor | Remote | Authorization
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
5.3 MEDIUM
CVE-2026-24945 — WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.34 - Broken Access Control vul…

Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…

ultimate_addons_for_contact_form_7 | Remote | Authorization
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
4.3 MEDIUM
CVE-2026-24942 — WordPress WpEvently plugin <= 5.1.1 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam WpEvently mage-eventpress allows Cross Site Request Forgery.This issue affects WpEvently: from n/a through <= 5.1.1.

event_manager_and_tickets_selling_for_woocommerce | Remote | Cross-Site Request Forgery
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
4.3 MEDIUM
CVE-2026-24940 — WordPress Travelfic Toolkit plugin <= 1.3.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Themefic Travelfic Toolkit travelfic-toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travelfic Toolkit: from …

Remote | Authorization
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
4.3 MEDIUM
CVE-2026-24939 — WordPress Modula Image Gallery plugin <= 2.13.6 - Broken Access Control vulnerability

Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Modula Image G…

Remote | Authorization
Feb 03, 2026 Feb 03, 2026
Feb 03, 2026
Feb 03, 2026
Showing 20 of 5256 Results