Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-64799 — Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere…

Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network servi…

| Server-Side Request Forgery
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.5 MEDIUM
CVE-2026-16078 — WCPOS <= 1.9.8 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read via …

The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9.8 via the 'type' parameter parameter. This m…

Remote | Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.5 MEDIUM
CVE-2026-15906 — Premium Packages <= 7.0.4 - Authenticated (Admin+) SQL Injection via 'orderby' Parameter

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insuff…

Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.3 MEDIUM
CVE-2026-15827 — GutenKit <= 2.4.12 - Missing Authorization to Unauthenticated Sensitive Information Expos…

The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/gutenkit/v1/mailchimp/get/lists and /wp-json/gutenkit/v1/mailch…

Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.4 MEDIUM
CVE-2026-15794 — Grid/List View for WooCommerce <= 3.0.9 - Authenticated (Contributor+) Stored Cross-Site …

The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versions up to, and including, 3.0.9 due to insufficient…

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
4.9 MEDIUM
CVE-2026-15786 — WP Encryption <= 7.8.6.6 - Authenticated (Administrator+) Arbitrary File Write via 'implo…

The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 …

Remote | Path Traversal
Jul 23, 2026 Jul 24, 2026
Jul 23, 2026
Jul 24, 2026
6.5 MEDIUM
CVE-2026-15761 — Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_event_filter' Parameter

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event_filter' parameter in all versions up to, and including, 3.6.0.1 due to insuffi…

tickera | Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
4.4 MEDIUM
CVE-2026-15647 — Brands for WooCommerce <= 3.8.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripti…

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient inp…

brands_for_woocommerce | Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.4 MEDIUM
CVE-2026-15646 — Brands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scriptin…

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sani…

brands_for_woocommerce | Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.5 MEDIUM
CVE-2026-15448 — Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_order_status_filter' Pa…

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to …

tickera | Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.4 MEDIUM
CVE-2026-15404 — Bulk Page Generator <= 2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting v…

The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.5.7. This is due to insufficient input sanitization and output escapi…

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.4 MEDIUM
CVE-2026-15394 — Header Footer Script Adder <= 2.1 - Authenticated (Author+) Stored Cross-Site Scripting v…

The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code' Snippet Meta in all versions up to, and includin…

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.3 MEDIUM
CVE-2026-15348 — Premium Packages <= 7.0.4 - Authentication Bypass to Non-Admin via 'wpdmppdl' Parameter

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via the `wpdmppdl` parameter. This is due…

Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.8 HIGH
CVE-2026-15017 — MDJM Event Management <= 1.7.8.4 - Authenticated (Subscriber+) Privilege Escalation via '…

The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in …

Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.8 CRITICAL
CVE-2026-15015 — MountDev AI MCP Connector for WordPress <= 1.6.1 - Unauthenticated Privilege Escalation v…

The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying th…

Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.8 CRITICAL
CVE-2026-15011 — Customer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Injection via '…

The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic funct…

Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.4 MEDIUM
CVE-2026-14481 — Equalize Digital Accessibility Checker <= 1.46.0 - Authenticated (Contributor+) Stored Cr…

The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'html' parameter in all versions up to…

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.8 CRITICAL
CVE-2026-14282 — GoDAM <= 1.12.2 - Unauthenticated Arbitrary File Upload via WPForms File Upload Field

The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and includ…

Remote | Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.5 MEDIUM
CVE-2026-13119 — Registrations for the Events Calendar <= 3.2 - Authenticated (Contributor+) SQL Injection…

The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to …

Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.5 MEDIUM
CVE-2026-13009 — AI Copilot <= 1.5.4 - Authenticated (Subscriber+) SQL Injection via 'order[0][dir]' Param…

The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 1.5.4 due to insufficient escaping o…

Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Showing 20 of 8954 Results