Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-9832 — Payment Gateway of Stripe for WooCommerce <= 5.0.8 - Unauthenticated Improper Verificatio…

The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the pu…

Remote | Authentication
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.3 MEDIUM
CVE-2026-9615 — Flex Import <= 3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modif…

The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. This is due to the license_activate_fleximp() and license_deactivate_fleximp() f…

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.5 MEDIUM
CVE-2026-9232 — Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Contributor+) Sens…

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for auth…

Remote | Information Disclosure
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.1 MEDIUM
CVE-2026-87917 — MC4WP: Mailchimp for WordPress <= 4.14.0 - Reflected Cross-Site Scripting via 'data' Dyna…

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data' Dynamic Content Tag in all versions up to, and including, 4.14.0 due to insufficient…

Remote | Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
8.1 HIGH
CVE-2026-85658 — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Res…

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all ve…

Remote | Injection
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.7 MEDIUM
CVE-2026-7527 — WP Ghost (Hide My WP Ghost) <= 7.0.02 - Unauthenticated Open Redirect via 'redirect_to' P…

The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 7.0.02. This is due to the plugin not properly validati…

Remote | Misconfiguration
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.9 MEDIUM
CVE-2026-75959 — GoPay for WooCommerce <= 1.0.36 - Authenticated (Shop Manager+) SQL Injection via 'log_ta…

The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'log_table_filter' parameter in all versions up to, and including, 1.0.36 due to insufficient escaping on…

Remote | Injection
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.9 MEDIUM
CVE-2026-6295 — WP Optimizer <= 2.5.0 - Authenticated (Administrator+) SQL Injection via 's' Parameter

The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.0. This is due to an unsafe subquery-detection branch in the Query::…

Remote | Injection
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.4 MEDIUM
CVE-2026-5400 — Redux Framework <= 4.5.13 - Authenticated (Subscriber+) Cross-Site Scripting via User Inp…

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media field filter values in versions up to, and including, 4.5.13 This is due to insufficient input sani…

Remote | Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
5.3 MEDIUM
CVE-2026-4792 — Bread <= 2.9.12 - Missing Authorization to Unauthenticated Information Exposure

The Bread plugin for WordPress is vulnerable to information exposure in versions up to and including 2.9.12. This is due to the lack of authentication and authorization checks on the settings export …

Remote | Information Disclosure
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
8.8 HIGH
CVE-2026-4327 — The Welcomizer <= 2.8.1 - Missing Authorization to Authenticated (Subscriber+) Remote Cod…

The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX ac…

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.4 MEDIUM
CVE-2026-2422 — WP Composer <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pbwp…

The WP Composer – The Easiest Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pbwp_raw_shortcode' shortcode in all versions up to, and including, 1.0.5. This i…

Remote | Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.3 MEDIUM
CVE-2026-2278 — VW Writer Blog <= 1.3.8 - Missing Authorization to Authenticated (Subscriber+) Theme Sett…

The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in all versions up to, …

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
5.3 MEDIUM
CVE-2026-1984 — Ibtana – Ecommerce Product Addons <= 0.4.7.7 - Missing Authorization to Authenticated (Su…

The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on the 'iepa_use_gt_editor' AJAX action in all versio…

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.5 MEDIUM
CVE-2026-1641 — Wow Elements Addons for Elementor <= 1.11.2 - Authenticated (Contributor+) Server-Side Re…

The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2. This is due to the plugin passing user-controlled…

Remote | Server-Side Request Forgery
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.3 MEDIUM
CVE-2026-1242 — BlockSpare - Gutenberg Site Builder Blocks & Starter Sites <= 4.2.6 - Incorrect Authoriza…

The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) o…

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.3 MEDIUM
CVE-2026-15947 — Search Atlas SEO <= 2.6.23 - Missing Authorization to Authenticated (Subscriber+) Site-Wi…

The Metasync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_instant_indexing_settings() function in versions up to, and includin…

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.3 MEDIUM
CVE-2026-15946 — Search Atlas SEO <= 2.6.23 - Missing Authorization to Authenticated (Subscriber+) Whitela…

The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6…

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
7.2 HIGH
CVE-2026-15664 — Quill Forms | Conversational Multi Step Forms, Surveys & quizzes <= 5.7.1 - Unauthenticat…

The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple Choice 'Other' Value in all versions up to, and inc…

Remote | Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.1 MEDIUM
CVE-2026-15463 — SSL Zen <= 4.7.42 - Reflected Cross-Site Scripting via 'uri' and 'host' Parameters

The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'host' parameter in all versions up to, and including, 4.7.42 du…

Remote | Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
Showing 20 of 14311 Results