CVE-2026-56014
— WordPress Master Slider plugin <= 3.11.2 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions.
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
CVE-2026-56013
— WordPress License Manager for WooCommerce plugin <= 3.0.15 - Insecure Direct Object Refer…
Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.
Remote
|
Authorization
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
CVE-2026-56006
— WordPress H5P plugin <= 1.17.6 - Reflected Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions.
Remote
|
Cross-Site Scripting
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
CVE-2026-56005
— WordPress WP Activity Log plugin <= 5.6.3.1 - Cross Site Scripting (XSS) vulnerability
Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions.
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
CVE-2026-54849
— WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.11 - SQL Injection vulnerabili…
Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.
Remote
|
Injection
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
CVE-2026-54845
— WordPress MDTF plugin <= 1.3.8 - Local File Inclusion vulnerability
Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions.
Remote
|
Path Traversal
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
CVE-2026-54844
— WordPress CheckView Automated Testing plugin <= 2.1.0 - Broken Access Control vulnerabili…
Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.
Remote
|
Authorization
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
CVE-2026-54843
— WordPress MDTF plugin <= 1.3.7 - SQL Injection vulnerability
Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.
Remote
|
Injection
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
CVE-2026-54841
— WordPress Vitepos plugin <= 3.4.2 - Sensitive Data Exposure vulnerability
Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.
Remote
|
Information Disclosure
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
CVE-2026-54838
— WordPress WC Vendors Marketplace plugin <= 2.6.8 - SQL Injection vulnerability
Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions.
Remote
|
Injection
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
CVE-2026-54830
— WordPress Five Star Restaurant Reservations plugin <= 2.7.19 - Broken Access Control vuln…
Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.
Remote
|
Authorization
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
CVE-2026-54828
— WordPress Motors plugin <= 1.4.109 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.
Remote
|
Authorization
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
CVE-2026-54823
— WordPress Widget Options plugin <= 4.2.3 - Remote Code Execution (RCE) vulnerability
Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.
Remote
|
Injection
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
CVE-2026-54822
— WordPress SALESmanago & Leadoo plugin <= 3.11.2 - SQL Injection vulnerability
Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.
Remote
|
Injection
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
CVE-2026-54821
— WordPress Visual Link Preview plugin <= 2.3.1 - Sensitive Data Exposure vulnerability
Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.
Remote
|
Information Disclosure
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
CVE-2026-27366
— WordPress MainWP Child plugin <= 6.1.1 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions.
Remote
|
Authorization
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
CVE-2026-57619
— WordPress Elementor Website Builder plugin <= 4.1.3 - Sensitive Data Exposure vulnerabili…
Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
CVE-2026-52690
— Spoofed answers can mark an authoritative non-EDNS capable
Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail.
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Incomplete validation of the SOA record present in a catalog zone might lead to a crash.
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026
Jun 25, 2026