Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-85132 — WPLP Cookie Consent 4.0.2 - 4.4.1 - Subscriber+ Cookie Scan Schedule Disclosure via gcc_g…

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to…

| Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-85037 — Sunshine Photo Cart < 3.7 - Unauthenticated Price Manipulation via IDOR

The Sunshine Photo Cart WordPress plugin before 3.7 does not validate that a client-supplied price identifier belongs to the item being purchased when it is added to the cart, allowing unauthenticat…

| Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.3 MEDIUM
CVE-2026-84908 — WPFunnels <= 3.12.13 - Missing Authorization to Unauthenticated Arbitrary Product Price M…

The WPFunnels plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.12.13. This is due to the plugin registering the 'wpfnl_load_payment' AJAX action for bot…

Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-84222 — Kirki 6.2.1 - 6.2.5 - Unauthenticated Non-Public Post Content Disclosure via 'kirki_data'…

The Kirki WordPress plugin before 6.3.0 does not check whether the requester is allowed to read a post before rendering and returning its page content, allowing unauthenticated users to retrieve the…

| Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-84113 — Quentn WP < 1.2.15 - Admin+ SQLi via 'orderby'/'order' Parameter

The Quentn WP WordPress plugin before 1.2.15 does not properly sanitise and escape a parameter before using it in an SQL query, allowing high privilege users such as administrators to perform SQL inj…

| Injection
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-84068 — Quentn WP 1.2.13 - 1.2.14 - Unauthenticated SQLi via 'qntn_wp' Parameter

The Quentn WP WordPress plugin before 1.2.15 does not adequately escape a request parameter before using it in an unprepared SQL query, allowing unauthenticated attackers to extract arbitrary data fr…

| Injection
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.2 HIGH
CVE-2026-83593 — WPBot <= 8.7.3 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conversation' parameter in all versions up to, and inc…

Remote | Cross-Site Scripting
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-83541 — Sina Extension for Elementor 3.7.1 - 3.10.3 - Contributor+ Stored XSS via Table Widget

The Sina Extension for Elementor WordPress plugin before 3.10.4 does not properly escape a Table widget setting before outputting it within an HTML attribute, which could allow users with the Contrib…

| Cross-Site Scripting
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-82848 — Masteriyo LMS 1.3.1 - 2.3.3 - Unauthenticated Course Enrollment Disclosure

The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any lear…

| Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-82185 — WPLP Cookie Consent < 4.4.2 - Subscriber+ Banner Settings Overwrite and A/B Test Data Res…

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have capability or nonce checks on some of its A/B testing actions, allowing any authenticated user, such as a subscriber, to overwrite…

| Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-82184 — WPLP Cookie Consent < 4.4.2 - Unauthenticated IAB TCF Consent Option Update

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, …

| Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-81741 — Groundhogg < 4.7.2 - Open Redirect via 'redirect_to' Parameter

The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect target of its email preference confirmation flow to the site's own host, allow…

| Server-Side Request Forgery
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-81022 — SupportCandy 3.3.6 - 3.5.2 - Unauthenticated Ticket Content Disclosure via Auth Code Leak

The SupportCandy WordPress plugin before 3.5.3 does not validate a submitted per-ticket authorization code before disclosing the real code to the requester, allowing unauthenticated users to read th…

| Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-81021 — SupportCandy 3.2.9 - 3.5.2 - Unauthenticated Ticket Attachment Disclosure

The SupportCandy WordPress plugin before 3.5.3 does not perform an authorization check on one of its support-ticket attachment download paths, allowing unauthenticated attackers to read protected cu…

| Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-80341 — Payment Plugins for PayPal WooCommerce < 2.0.26 - Subscriber+ Stored Payment Method Assig…

The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method belongs to the user attaching it, allowing any authenticated user, such as a sub…

| Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-80340 — Payment Plugins for PayPal WooCommerce < 2.0.26 - Unauthenticated Customer PII Disclosure…

The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowin…

| Information Disclosure
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-80339 — Payment Plugins for Stripe WooCommerce < 4.0.12 - Unauthenticated Customer PII Disclosure…

The Payment Plugins for Stripe WooCommerce WordPress plugin before 4.0.12 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowin…

| Information Disclosure
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.1 HIGH
CVE-2026-76009 — Next-Cart Store to WooCommerce Migration <= 3.9.8 - Unauthenticated Authentication Bypass…

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is…

Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
4.3 MEDIUM
CVE-2026-75905 — WP Recipe Maker <= 10.8.0 - Missing Authorization to Authenticated (Contributor+) Arbitra…

The WP Recipe Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.8.0. This is due to the plugin not properly verifying that a user is authorized…

Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-75861 — Ultimate Gift Cards for WooCommerce < 3.2.10 - Subscriber+ Gift Card Theft and Destructio…

The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not verify that the user redeeming a gift card is its intended recipient, allowing any authenticated user, such as a subscr…

| Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
Showing 20 of 14271 Results