Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-87981 — Paymob for WooCommerce < 4.1.14 - Contributor+ Payment Gateway Configuration Deletion and…

The Paymob for WooCommerce WordPress plugin before 4.1.14 does not perform a capability check on several admin AJAX actions that manage its payment-gateway configuration, allowing users with contribu…

| Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-87979 — Paymob for WooCommerce < 4.1.14 - Unauthenticated Saved Card Token Write to Any User via …

The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch of its payment webhook, allowing unauthenticated attackers to write a card-tok…

| Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-87074 — Forminator Forms < 1.57.2.1 - Unauthenticated Arbitrary Recipient Email Sending with Atta…

The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into …

| Information Disclosure
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-87069 — Forminator Forms < 1.57.2.1 - Subscriber+ Form Stripe Field Migration via migrate_stripe

The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction of one of its …

| Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-86842 — Real3D Flipbook Lite < 5.4 - Author+ Content Deletion and Stored XSS via Global Settings …

The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flipbook management actions, allowing users with Author-level access and above to d…

| Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-86785 — Social Commerce for WooCommerce <= 2.5.4 - Unauthenticated Plugin Option and Product Sync…

The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its REST API endpoints, allowing unauthenticated users to update Social Commerce for W…

| Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-86783 — PostX < 5.0.41 - Unauthenticated Custom Field Key Disclosure via REST API

The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allow…

| Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-86608 — WP Recipe Maker 9.8.0 - 10.8.1 - Unauthenticated DoS via Unbounded User Meta Insertion

The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what that route stores, allowing unauthenticated users to write u…

wp_recipe_maker | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-86603 — WP Recipe Maker < 10.8.2 - Subscriber+ Non-Public List Title Disclosure via wprm_search_l…

The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and tit…

wp_recipe_maker | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-86602 — WP Recipe Maker 10.3.0 - 10.8.1 - Subscriber+ Draft and Private Recipe Content Disclosure…

The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the full content of…

wp_recipe_maker | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-85006 — Happy Addons for Elementor < 3.50.0 - Contributor+ Stored XSS via Creative Button Widget

The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an HTML attribute, allowing users with Contributor…

| Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-84743 — The Events Calendar 6.15.16.1 - 6.17.4.1 - Contributor+ Event/Venue/Organizer Update, Tra…

The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor …

| Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-84742 — The Events Calendar 6.15.0 - 6.17.4.1 - Contributor+ Content Publication via TEC V1 REST …

The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, allowing users with a role that canno…

the_events_calendar | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-84741 — The Events Calendar 4.5 - 6.17.4.1 - Unauthenticated Non-Public Venue and Organizer Discl…

The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated use…

the_events_calendar | Information Disclosure
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-84168 — Easy Hide Login < 1.7 - Login Page Protection Bypass / Hidden URL Disclosure

The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthenticated attacker to reach the standard login page through certain password-rese…

| Information Disclosure
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-84150 — Directorist < 8.9.5 - Subscriber+ Cross-User Favorites Read and Write via REST Favorites …

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not verify that the target user of a REST route matches the authenticated caller before re…

| Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-84098 — Directorist 3.1.0 - 8.9.4 - Subscriber+ Arbitrary Listing Deletion via remove_listing

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated attac…

| Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-84046 — Directorist < 8.9.5 - Subscriber+ SSRF via Avatar URL

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validate a user-supplied URL before fetching it server-side, allowing users with the s…

| Server-Side Request Forgery
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-84027 — Directorist 8.9.1 - 8.9.4 - Subscriber+ Paid Order and Payment Record Forgery via REST Or…

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, allowing users with…

| Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-84026 — Directorist 8.1 - 8.9.4 - Unauthenticated Sensitive Data Disclosure via REST Users Endpoi…

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restrict access to a REST endpoint that returns user records, allowing unauthenticated…

| Information Disclosure
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Showing 20 of 14247 Results