CVE-2026-82023
— LearnPress WordPress Plugin < 4.4.6 Broken Object-Level Authorization via Quiz Answer Ins…
LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned…
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-63219
— Unauthenticated file upload via missing authorization on formatter upload endpoint
GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and all…
Remote
|
Misconfiguration
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-58400
— GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configurat…
GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure proc…
Remote
|
Misconfiguration
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85309
— WordPress Ultimate Maps by Supsystic plugin <= 1.5.3 - Broken Access Control vulnerability
Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Ultimate Maps by Supsystic: fr…
Remote
|
Authorization
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85308
— WordPress SureForms plugin <= 2.12.5 - Insecure Direct Object References (IDOR) vulnerabi…
Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects SureForms: fr…
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85307
— WordPress KP Agent Ready plugin < 1.2.08 - Sensitive Data Exposure vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready allows Retrieve Embedded Sensitive Data.
This issue affects KP Agent Ready: from n/a before 1.2.08.
Remote
|
Information Disclosure
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85306
— WordPress MountDev AI MCP Connector for WordPress plugin <= 1.6.5 - Broken Access Control…
Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Mount…
Remote
|
Authorization
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85305
— WordPress SEOPress plugin <= 10.1 - Server Side Request Forgery (SSRF) vulnerability
Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery.
This issue affects SEOPress: from n/a through 10.1.
Remote
|
Server-Side Request Forgery
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85304
— WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.…
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels.
…
Remote
|
Authorization
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85303
— WordPress Booking and Rental Manager plugin <= 2.7.7 - Cross Site Scripting (XSS) vulnera…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS.
This issue affects Booking and Ren…
Remote
|
Cross-Site Scripting
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85302
— WordPress WPKoi Templates for Elementor plugin <= 3.7.2 - Cross Site Scripting (XSS) vuln…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS.
This issue affects WP…
Remote
|
Cross-Site Scripting
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85242
— Server-Side Request Forgery via Favicon Redirect to Local Network Resources in Playwright…
PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application validates the initial favicon…
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85186
— itsourcecode Online Medicine Delivery System Customer Controller controller.php doupdatei…
A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function doupdateimage of the file /customer/controller.php?action=photos of …
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-84849
— WordPress Pre-Orders for WooCommerce plugin <= 2.3 - Bypass Vulnerability vulnerability
Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.
Remote
|
Authentication
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-84848
— WordPress Quick Event Manager plugin <= 9.17 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.
Remote
|
Cross-Site Scripting
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-84847
— WordPress Quick Event Manager plugin <= 9.17 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
Remote
|
Authorization
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-84836
— WordPress WC Ukraine Shipping plugin <= 1.22.3 - Insecure Direct Object References (IDOR)…
Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions.
Remote
|
Authorization
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-84834
— WordPress JobSearch plugin <= 3.2.0 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-84814
— WordPress Bricksforge plugin <= 3.1.8.8 - Privilege Escalation vulnerability
Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
Remote
|
Authorization
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-84813
— WordPress GeoDirectory plugin <= 2.8.174 - SQL Injection vulnerability
Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026