Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2025-15695 — GTranslate < 3.0.10 - Admin+ Stored XSS

The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as h…

| Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
0.0 NA
CVE-2026-83546 — CoolClock < 4.3.8 - Contributor+ Stored XSS via Skin Class Attribute

The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arb…

| Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
0.0 NA
CVE-2026-83545 — CoolClock < 4.3.8 - Contributor+ Stored XSS via Custom Skin JSON

The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inje…

| Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
4.1 MEDIUM
CVE-2026-89169 — live-boot dm-verity Security Bypass

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

| Misconfiguration
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
2.9 LOW
CVE-2026-89162 — PCRE2 Information Disclosure Vulnerability

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

pcre2 | Information Disclosure
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.7 HIGH
CVE-2026-89060 — Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multicl…

A flaw was found in multicluster-observability-addon. This vulnerability allows a managed-cluster identity to reference configuration resources outside its designated namespace. This can lead to the …

Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
9.8 CRITICAL
CVE-2026-8778 — MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Up…

The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_…

Remote | Misconfiguration
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.4 HIGH
CVE-2026-89161 — PCRE2 Memory Corruption Vulnerability

In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.

pcre2 | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
3.7 LOW
CVE-2026-89160 — PCRE2 Out-of-Bounds Read

PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.

pcre2 | Remote | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.5 MEDIUM
CVE-2026-89158 — PCRE2 Integer Overflow and Out-of-Bounds Write

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.

pcre2 | Remote | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.7 MEDIUM
CVE-2026-89157 — PCRE2 Out-of-Bounds Write

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.

pcre2 | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
2.9 LOW
CVE-2026-89156 — PCRE2 Out-of-Bounds Read

PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.

pcre2 | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.1 MEDIUM
CVE-2026-84960 — WP-Members Membership Plugin <= 3.5.6 - Reflected Cross-Site Scripting

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Query String in all versions up to, and including, 3.5.6 due to insufficient input saniti…

wp-members_membership_plugin | Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.2 HIGH
CVE-2026-81825 — Simple Ajax Chat <= 20260811 - Unauthenticated Stored Cross-Site Scripting

The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Chat Message in all versions up to, and including, <= 20260811 due to insuffic…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.2 HIGH
CVE-2026-81754 — Vigilant <= 2.10.2 - Unauthenticated Stored Cross-Site Scripting

The Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and inc…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.4 MEDIUM
CVE-2026-7438 — Bold Timeline Lite <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…

The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, an…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.1 MEDIUM
CVE-2026-78172 — Themify – WooCommerce Product Filter <= 1.5.5 - Reflected Cross-Site Scripting

The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query Parameter Name in all versions up to, and including, 1.5.5 due to insufficient …

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.1 MEDIUM
CVE-2026-77150 — Unlimited Elements For Elementor <= 2.0.16 - Reflected Cross-Site Scripting

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 due to insufficient i…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.1 HIGH
CVE-2026-19991 — UsersWP <= 1.2.70 - Authenticated (Subscriber+) Arbitrary File Deletion

The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account…

Remote | Path Traversal
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.1 MEDIUM
CVE-2026-19985 — Relevanssi <= 4.28.1 - Reflected Cross-Site Scripting

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.28.1 via the 's', 'post_types', and 'orderby' request paramet…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
Showing 20 of 13409 Results