Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-89213 — Llavero.io <= 0.1.4 - Unauthenticated Blind SQLi via 'cill_login' Parameter

The Llavero.io WordPress plugin through 0.1.4 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection att…

| Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-89195 — Site Setup Wizard <= 1.5.8 - Unauthenticated SQLi via ssw_check_admin_email_exists

The Site Setup Wizard WordPress plugin through 1.5.8 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL inject…

| Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-88930 — Social Web Suite <= 4.1.12 - Unauthenticated Blind SQLi via Unset Shared Secret

The Social Web Suite WordPress plugin through 4.1.12 does not require its shared secret to be set before accepting requests authorised by it, and does not sanitise and escape a parameter before usin…

| Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-88905 — KeyWord Collector <= 1.4 - Unauthenticated Stored XSS and Settings Update via WPKeyWordSe…

The KeyWord Collector WordPress plugin through 1.4 does not have any authorisation or nonce check when saving its settings, and does not escape them before output, allowing unauthenticated attackers …

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-88903 — Topcontent <= 1.2.1 - Unauthenticated Stored XSS via Content Webhook

The Topcontent WordPress plugin through 1.2.1 does not properly authorise one of its request handlers and disables HTML sanitisation before storing the submitted content, allowing unauthenticated att…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-88827 — Disable Users <= 1.0.5 - Disabled Account Authentication Bypass via XML-RPC and Applicati…

The Disable Users WordPress plugin through 1.0.5 does not enforce its account-disabling control on all authentication paths, allowing the holder of an account an administrator has disabled to continu…

| Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-88826 — SmugMug Embed <= 3.13 - Unauthenticated Stored XSS via saveSelectedAlbums

The SmugMug Embed WordPress plugin through 3.13 does not have authorisation or CSRF checks on an AJAX action that stores gallery data, and does not sanitise or escape that data before outputting it, …

| Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-88785 — Simple Membership < 4.8.3 - Newly Registered Member Password Disclosure via URL Query Str…

The Simple Membership WordPress plugin before 4.8.3 does not avoid transmitting a newly registered member's plaintext password in a URL query string when an optional auto-login-after-registration fea…

simple_membership | Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-87764 — BuddyPress Instant Chat <= 1.6 - Unauthenticated Stored XSS via Chat Message

The BuddyPress Instant Chat WordPress plugin through 1.6 does not check that the sender of a chat message belongs to the conversation it is being added to, nor does it escape message content before o…

| Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-87762 — Adwised Web Push Notification <= 2.5.7 - Unauthenticated Stored XSS via Secret Key Type J…

The Adwised Web Push Notification WordPress plugin through 2.5.7 does not have authorisation checks on several state-changing operations, and the secret comparison it uses instead can be bypassed on …

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-87761 — Adwised Web Push Notification <= 2.5.7 - Subscriber+ Stored XSS via Pop-up Settings

The Adwised Web Push Notification WordPress plugin through 2.5.7 does not perform any capability or nonce check before allowing an authenticated user to overwrite its site-wide configuration, and doe…

| Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-87760 — Web Vitals Tracking <= 5.4.2 - Unauthenticated Stored XSS via Tracking Beacon Metric Name

The Web Vitals Tracking WordPress plugin through 5.4.2 does not validate or escape performance measurements submitted by unauthenticated visitors before storing them and outputting them in a script c…

| Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-86798 — HootBoard <= 3.1.4 - Unauthenticated Stored XSS via Board Configuration REST Endpoint

The HootBoard WordPress plugin through 3.1.4 does not perform any authorisation check on some of its REST endpoints, and does not escape the values stored through them before outputting them in a pu…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-86717 — Insurify <= 1.0 - Unauthenticated Arbitrary Option Deletion via removeimg_popup

The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to delete arbitrary WordPress options, which can tak…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-86706 — Quick quotes <= 1.0.0 - Unauthenticated Integer-Value Option Update

The Quick quotes WordPress plugin through 1.0.0 does not perform any capability or nonce check on one of its AJAX actions and lets the caller choose which option is written, allowing unauthenticated…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-85126 — Crowdfundly <= 2.2.2 - Crowdfundly Manager+ Privilege Escalation

The Crowdfundly WordPress plugin through 2.2.2 does not have capability checks on some of its AJAX actions, allowing users holding one of its own low privileged roles to grant themselves the administ…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-85121 — Insurify <= 1.0 - Unauthenticated Arbitrary Option Creation and Overwrite via saveemailte…

The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to create and overwrite arbitrary WordPress options …

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-85118 — AI Content Generator Marketing <= 1.0.0 - Unauthenticated Privilege Escalation via Arbitr…

The AI Content Generator Marketing WordPress plugin through 1.0.0 does not enforce a nonce or capability check on some of its AJAX actions, allowing unauthenticated users to update and delete arbitra…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-84737 — Freeton WP <= 1.0.0 - Unauthenticated Account Takeover via 'secod' Parameter

The Freeton WP WordPress plugin through 1.0.0 does not correctly validate the activation code when authenticating a user, allowing unauthenticated attackers to log in as any user whose email address …

| Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-84734 — Mindstien Quick Login <= 1.0 - Unauthenticated Administrator Account Takeover via 'mql_pa…

The Mindstien Quick Login WordPress plugin through 1.0 does not correctly validate a value supplied in the request against the visitor's own session before authenticating them, allowing unauthenticat…

| Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
Showing 20 of 14145 Results