Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-13604 — Pixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo_event AJAX

The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end page, that forwards client-supplied event data to…

| Authentication
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
0.0 NA
CVE-2026-13596 — Participants Database < 2.7.8.4 - Unauthenticated SQL Injection via List Search

The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform…

| Injection
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
0.0 NA
CVE-2026-13329 — WC Buckaroo BPE Gateway < 4.9.0 - Subscriber+ Unauthorized Order Refund

The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any…

| Authorization
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
0.0 NA
CVE-2026-13158 — Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload

The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (A…

| Misconfiguration
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
0.0 NA
CVE-2026-13157 — Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload

The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Admi…

| Misconfiguration
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
0.0 NA
CVE-2026-12966 — Direct Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering …

The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its …

| Authorization
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
0.0 NA
CVE-2026-12696 — wpForo Forum < 3.1.2 - Subscriber+ Stored XSS via Profile Location Field

The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users w…

| Cross-Site Scripting
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
0.0 NA
CVE-2026-11882 — Builderall for WordPress < 3.0.2 - Unauthenticated OAuth Access Token Poisoning via Publi…

The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes to the initiating user session, allowing unauthenticated attackers to complete…

| Authentication
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
0.0 NA
CVE-2026-10827 — Spectra (Ultimate Addons for Gutenberg) < 2.20.0 - Contributor+ Stored CSS Injection via …

The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before using them to build the CSS it outputs on the front end, allowing users with the C…

| Cross-Site Scripting
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
0.0 NA
CVE-2025-15669 — Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label

The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as adm…

| Cross-Site Scripting
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
9.1 CRITICAL
CVE-2026-3141 — FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via '…

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versi…

Remote | Path Traversal
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.4 MEDIUM
CVE-2026-7623 — SureForms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'headin…

The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headingWrapper' parameter in all versions up to, and …

Remote | Cross-Site Scripting
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
8.8 HIGH
CVE-2026-15414 — Subscriptions for WooCommerce <= 2.0.0 - Authenticated (Contributor+) Privilege Escalatio…

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_…

Remote | Authorization
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
4.9 MEDIUM
CVE-2026-15403 — Pinpoint Booking System <= 2.9.9.6.9 - Authenticated (Administrator+) SQL Injection via '…

The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parameter in all versions up to, and including, 2.9.9.6.9 due to insufficient escapin…

Remote | Injection
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.5 HIGH
CVE-2026-15006 — Bit integrations <= 2.9.0 - Unauthenticated Arbitrary File Read via Optional CF7 File Fie…

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via t…

Remote | Path Traversal
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.4 MEDIUM
CVE-2026-13362 — SendPulse Email Marketing Newsletter <= 2.2.5 - Authenticated (Contributor+) Stored Cross…

The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient …

Remote | Cross-Site Scripting
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
8.5 HIGH
CVE-2026-9044 — Command Injection Vulnerability in OpenVPN of TP-Link Archer AXE75

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device b…

| Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.3 MEDIUM
CVE-2026-54909 — Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-…

pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed short XOR-MAPPED-ADDRESS attribute in STUN or ICE Binding-response parsing pat…

Remote | Denial of Service
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
3.1 LOW
CVE-2026-54787 — sigstore-go fails to check signature timestamps against a signing key's validity period

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-…

sigstore-go | Remote | Cryptography
Jul 31, 2026 Aug 01, 2026
Jul 31, 2026
Aug 01, 2026
6.2 MEDIUM
CVE-2026-54785 — gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inlin…

gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied i…

| Path Traversal
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
Showing 20 of 9406 Results