Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-12137 — SysBasics Customize My Account for WooCommerce <= 4.3.6 - Reflected Cross-Site Scripting …

The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all ve…

Remote | Cross-Site Scripting
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
6.4 MEDIUM
CVE-2026-12136 — SysBasics Customize My Account for WooCommerce <= 4.3.6 - Authenticated (Contributor+) St…

The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysbasics_user_avatar' shortcode in versions up to, and including, 4.3.6. This is d…

Remote | Cross-Site Scripting
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
4.3 MEDIUM
CVE-2026-12111 — Appointment Booking Calendar <= 1.4.01 - Authenticated (Contributor+) Sensitive Informati…

The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.4.01. This is due to insufficient authorization and missing p…

appointment_booking_calendar | Remote | Authorization
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
2.7 LOW
CVE-2026-12102 — UsersWP <= 1.2.63 - Insecure Direct Object Reference to Authenticated (Editor+) Arbitrary…

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and…

userswp | Remote | Authorization
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
6.4 MEDIUM
CVE-2026-12098 — PowerPress Podcasting plugin by Blubrry <= 11.16.8 - Authenticated (Author+) Stored Cross…

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed' Episode Meta Field in all versions up to, and including, 11.16.8 due to insuf…

powerpress | Remote | Cross-Site Scripting
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
7.2 HIGH
CVE-2026-11395 — CF7 to Webhook <= 5.0.0 - Unauthenticated Server-Side Request Forgery via CF7 Field Place…

The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.0 via the pull_the_trigger. This makes it possible for unauthenticated a…

Remote | Server-Side Request Forgery
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
8.8 HIGH
CVE-2026-9860 — Offload, AI & Optimize with Cloudflare Images <= 1.10.2 - Authenticated (Author+) Remote …

The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-id' parameter parameter. Th…

Remote | Misconfiguration
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
4.3 MEDIUM
CVE-2026-9199 — Equalize Digital Accessibility Checker <= 1.42.1 - Missing Authorization to Authenticated…

The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.42.1. This is…

Remote | Authorization
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
9.8 CRITICAL
CVE-2026-55740 — SQL Injection in Nur-Alam39 bus-ticket bus_info.php via busid parameter

Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulnerability in bus_info.php. The busid parameter recei…

Remote | Injection
Jun 18, 2026 Jun 22, 2026
Jun 18, 2026
Jun 22, 2026
5.3 MEDIUM
CVE-2026-12120 — FireBox Popups <= 3.1.7 - Unauthenticated Sensitive Information Exposure in 'form_id' Par…

The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.7 via the 'form_id' paramet…

Remote | Information Disclosure
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
5.3 MEDIUM
CVE-2026-12093 — Simple Membership <= 4.7.5 - Missing Authorization to Unauthenticated Arbitrary Member Ac…

The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorize…

simple_membership | Remote | Authorization
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
4.3 MEDIUM
CVE-2026-11784 — Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <…

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.…

Remote | Cross-Site Request Forgery
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
4.9 MEDIUM
CVE-2026-11777 — Form Maker by 10Web <= 1.15.43 - Authenticated (Administrator+) SQL Injection via 'name' …

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'name' parameter in all versions up to, and including, 1…

form_maker | Remote | Injection
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
4.9 MEDIUM
CVE-2026-11776 — Form Maker by 10Web <= 1.15.43 - Authenticated (Adminsitrator+) SQL Injection via 'groupi…

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'groupids' parameter in all versions up to, and includin…

form_maker | Remote | Injection
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
6.4 MEDIUM
CVE-2026-11402 — Services Section Block <= 1.4.4 - Authenticated (Contributor+) Stored Cross-Site Scriptin…

The Services Section Block – Showcase Service Details in Grid or Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'link' Block Attribute in all versions up to, and includ…

Remote | Cross-Site Scripting
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
4.9 MEDIUM
CVE-2026-11360 — Advanced Order Export For WooCommerce <= 4.0.10 - Authenticated (Shop Manager+) SQL Injec…

The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_direction' parameter in all versions up to, and including, 4.0.10 due to insufficie…

Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
4.4 MEDIUM
CVE-2026-11358 — Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More <=…

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, …

orbit_fox | Remote | Cross-Site Scripting
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
4.3 MEDIUM
CVE-2026-11357 — Kadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via…

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.7.5 via the editor_assets_v…

gutenberg_blocks_with_ai | Remote | Information Disclosure
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
4.9 MEDIUM
CVE-2026-10736 — Tutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data' Parameter

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, and including, 3.9.11 due to insuffici…

tutor_lms | Remote | Injection
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
4.3 MEDIUM
CVE-2026-10623 — PressPrimer Quiz <= 2.3.0 - Insecure Direct Object Reference to Authenticated (Custom+) A…

The PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.0 via the '…

Remote | Authorization
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
Showing 20 of 7989 Results