CVE-2026-56028
— WordPress Easy Elements for Elementor – Addons & Website Templates plugin <= 1.4.9 - Priv…
Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website Templates <= 1.4.9 versions.
Remote
|
Authorization
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-56027
— WordPress Booster for WooCommerce plugin <= 8.0.1 - Arbitrary File Upload vulnerability
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
Remote
|
Misconfiguration
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-56026
— WordPress utm.codes plugin <= 1.9.0 - Server Side Request Forgery (SSRF) vulnerability
Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions.
Remote
|
Server-Side Request Forgery
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-56025
— WordPress Paymob for WooCommerce plugin <= 4.1.2 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.
Remote
|
Authorization
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-56011
— WordPress MapPress Maps for WordPress plugin <= 2.97.3 - Cross Site Scripting (XSS) vulne…
Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.
Remote
|
Cross-Site Scripting
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-56010
— WordPress Abandoned Cart Pro for WooCommerce plugin <= 10.4.0 - Privilege Escalation vuln…
Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-56008
— WordPress Fusion Builder plugin <= 3.15.4 - Privilege Escalation vulnerability
Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions.
Remote
|
Authorization
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-54847
— WordPress Stylish Cost Calculator plugin <= 8.3.9 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions.
Remote
|
Authorization
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-54846
— WordPress Syncee Premium Dropshipping & Wholesale plugin <= 1.0.27 - Broken Access Contro…
Unauthenticated Broken Access Control in Syncee Premium Dropshipping & Wholesale <= 1.0.27 versions.
Remote
|
Authorization
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-54840
— WordPress Newsletters plugin <= 4.13 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-54839
— WordPress Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups plugin <= 2…
Unauthenticated Sensitive Data Exposure in Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups <= 2.0.9 versions.
Remote
|
Information Disclosure
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-54837
— WordPress Intranet & Private Site – All-In-One Intranet plugin <= 1.8.1 - Broken Access C…
Unauthenticated Broken Access Control in Intranet & Private Site – All-In-One Intranet <= 1.8.1 versions.
Remote
|
Authorization
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-54835
— WordPress Five Star Restaurant Menu plugin <= 2.5.2 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.
Remote
|
Authorization
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-54834
— WordPress Object Cache 4 everyone plugin <= 2.3.2 - Sensitive Data Exposure vulnerability
Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.
Remote
|
Information Disclosure
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-54833
— WordPress Enable CORS plugin <= 2.0.3 - Backdoor vulnerability
Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions.
Remote
|
Authentication
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-54832
— WordPress Gutenverse Companion plugin <= 2.5.0 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.
Remote
|
Authorization
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-54831
— WordPress GeoDirectory plugin <= 2.8.162 - SQL Injection vulnerability
Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.
Remote
|
Injection
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-54827
— WordPress Real Estate 7 theme <= 3.5.9 - SQL Injection vulnerability
Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.
Remote
|
Injection
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-54826
— WordPress SupportCandy plugin <= 3.4.6 - Insecure Direct Object References (IDOR) vulnera…
Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions.
Remote
|
Authorization
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
CVE-2026-54825
— WordPress wpDataTables plugin <= 7.4 - SQL Injection vulnerability
Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.
Remote
|
Injection
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026
Jun 26, 2026