Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-65459 — WordPress Forminator plugin <= 1.57.3 - Arbitrary Content Deletion vulnerability

Unauthenticated Arbitrary Content Deletion in Forminator <= 1.57.3 versions.

forminator | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-62130 — WordPress WooCommerce Multilingual & Multicurrency plugin <= 5.5.8 - PHP Object Injection…

Shop manager PHP Object Injection in WooCommerce Multilingual & Multicurrency <= 5.5.8 versions.

Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.9 CRITICAL
CVE-2026-62129 — WordPress Creator LMS plugin <= 1.2.21 - Arbitrary File Upload vulnerability

Contributor Arbitrary File Upload in Creator LMS <= 1.2.21 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-62125 — WordPress Asia Garden theme <= 1.3.1 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Asia Garden <= 1.3.1 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-62124 — WordPress N7 | Golf Club Sports & Events theme <= 2.21 - PHP Object Injection vulnerabili…

Unauthenticated PHP Object Injection in N7 | Golf Club Sports & Events <= 2.21 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-62123 — WordPress Invetex theme <= 2.18 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Invetex <= 2.18 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-62120 — WordPress Law Office theme <= 3.20 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Law Office <= 3.20 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.3 HIGH
CVE-2026-62118 — WordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.13.1 - Broken Access…

Unauthenticated Broken Access Control in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.

Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.5 HIGH
CVE-2026-62117 — WordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.13.1 - SQL Injection…

Subscriber SQL Injection in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-62116 — WordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.13.1 - Cross Site Sc…

Unauthenticated Cross Site Scripting (XSS) in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-62115 — WordPress KuteShop theme <= 4.2.9 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in KuteShop <= 4.2.9 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-62100 — WordPress KuteShop theme <= 4.2.9 - Reflected Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in KuteShop <= 4.2.9 versions.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-62099 — WordPress Boutique theme <= 2.3.3 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in Boutique <= 2.3.3 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.5 MEDIUM
CVE-2026-62098 — WordPress Boutique theme <= 2.3.3 - Arbitrary Shortcode Execution vulnerability

Unauthenticated Content Injection in Boutique <= 2.3.3 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-62096 — WordPress Biolife theme <= 3.2.3 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in Biolife <= 3.2.3 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-62095 — WordPress Biolife theme <= 3.2.3 - Reflected Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Biolife <= 3.2.3 versions.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-62094 — WordPress TechOne theme <= 3.0.3 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in TechOne <= 3.0.3 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-62093 — WordPress TechOne theme <= 3.0.3 - Reflected Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in TechOne <= 3.0.3 versions.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-62092 — WordPress Armania theme <= 1.4.8 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in Armania <= 1.4.8 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-62091 — WordPress Armania theme <= 1.4.8 - Reflected Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Armania <= 1.4.8 versions.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Showing 20 of 14148 Results