Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-32498 — WordPress RegistrationMagic plugin <= 6.0.7.6 - Broken Access Control vulnerability

Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorrectly Configured Access Control Security Levels.Thi…

registrationmagic | Remote | Authorization
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
5.3 MEDIUM
CVE-2026-32497 — WordPress User Verification plugin <= 2.0.45 - Email Verification Bypass vulnerability

Weak Authentication vulnerability in PickPlugins User Verification user-verification allows Authentication Abuse.This issue affects User Verification: from n/a through <= 2.0.45.

Remote | Authentication
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
6.7 MEDIUM
CVE-2026-32496 — WordPress Spam Protect for Contact Form 7 plugin <= 1.2.9 - Arbitrary File Deletion vulne…

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NYSL Spam Protect for Contact Form 7 wp-contact-form-7-spam-blocker allows Path Traversal.This issue af…

Remote | Path Traversal
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
7.5 HIGH
CVE-2026-32495 — WordPress WP Terms Popup plugin <= 2.10.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Link Software LLC WP Terms Popup wp-terms-popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Terms Popup: from …

wp_terms_popup | Remote | Authorization
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
7.1 HIGH
CVE-2026-32494 — WordPress Image Slider by Ays plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Image Slider by Ays ays-slider allows Exploiting Incorrectly Configured Access Control Se…

Remote | Cross-Site Scripting
Mar 25, 2026 Mar 25, 2026
Mar 25, 2026
Mar 25, 2026
0.0 NA
CVE-2026-32493 — WordPress JobSearch plugin <= 3.2.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Reflected XSS.This issue affects JobSearch: from n/a through…

jobsearch_wp_job_board | Cross-Site Scripting
Mar 25, 2026 Mar 25, 2026
Mar 25, 2026
Mar 25, 2026
5.3 MEDIUM
CVE-2026-32492 — WordPress My Tickets plugin <= 2.1.1 - Bypass Vulnerability vulnerability

Authentication Bypass by Spoofing vulnerability in Joe Dolson My Tickets my-tickets allows Identity Spoofing.This issue affects My Tickets: from n/a through <= 2.1.1.

Remote | Authentication
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
6.5 MEDIUM
CVE-2026-32491 — WordPress WP Review Slider plugin <= 13.9 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgwhite33 WP Review Slider wp-facebook-reviews allows Stored XSS.This issue affects WP Review Sli…

Remote | Cross-Site Scripting
Mar 25, 2026 Mar 25, 2026
Mar 25, 2026
Mar 25, 2026
6.5 MEDIUM
CVE-2026-32490 — WordPress WP TripAdvisor Review Slider plugin <= 14.1 - Cross Site Scripting (XSS) vulner…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgwhite33 WP TripAdvisor Review Slider wp-tripadvisor-review-slider allows Stored XSS.This issue …

Remote | Cross-Site Scripting
Mar 25, 2026 Mar 25, 2026
Mar 25, 2026
Mar 25, 2026
6.5 MEDIUM
CVE-2026-32489 — WordPress B Blocks plugin < 2.0.30 - Broken Access Control vulnerability

Missing Authorization vulnerability in bPlugins B Blocks b-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects B Blocks: from n/a through < 2.0.30.

Remote | Authorization
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
8.1 HIGH
CVE-2026-32488 — WordPress User Registration plugin <= 4.4.9 - Privilege Escalation vulnerability

Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalation.This issue affects User Registration: from n/a through <= 4.4.9.

user_registration | Remote | Authorization
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
7.5 HIGH
CVE-2026-32485 — WordPress WP User Frontend plugin <= 4.2.8 - Broken Access Control vulnerability

Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a t…

wp_user_frontend | Remote | Authorization
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
8.8 HIGH
CVE-2026-32484 — WordPress weForms plugin <= 1.6.26 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in BoldGrid weForms weforms allows Object Injection.This issue affects weForms: from n/a through <= 1.6.26.

Remote | Injection
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
6.5 MEDIUM
CVE-2026-32483 — WordPress Contact Form Email plugin <= 1.3.63 - Broken Access Control vulnerability

Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Emai…

contact_form_email | Remote | Authorization
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
9.9 CRITICAL
CVE-2026-32482 — WordPress Ona theme < 1.24 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in deothemes Ona ona allows Upload a Web Shell to a Web Server.This issue affects Ona: from n/a through < 1.24.

Remote | Misconfiguration
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
7.7 HIGH
CVE-2026-32441 — WordPress Comments Import & Export plugin <= 2.4.9 - Broken Access Control vulnerability

Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects…

Remote | Authorization
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
8.2 HIGH
CVE-2026-31921 — WordPress Product Rearrange for WooCommerce plugin <= 1.2.2 - Broken Access Control vulne…

Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.Thi…

Remote | Authorization
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
9.3 CRITICAL
CVE-2026-31920 — WordPress Product Rearrange for WooCommerce plugin <= 1.2.2 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Blind…

Remote | Injection
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
6.5 MEDIUM
CVE-2026-31914 — WordPress WP Courses LMS plugin <= 3.2.26 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hookandhook WP Courses LMS wp-courses allows DOM-Based XSS.This issue affects WP Courses LMS: fro…

Remote | Cross-Site Scripting
Mar 25, 2026 Mar 25, 2026
Mar 25, 2026
Mar 25, 2026
8.6 HIGH
CVE-2026-31913 — WordPress Scape theme < 1.5.16 - Arbitrary File Deletion vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Whitebox-Studio Scape scape allows Path Traversal.This issue affects Scape: from n/a through < 1.5.16.

Remote | Path Traversal
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
Showing 20 of 6083 Results