Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-85302 — WordPress WPKoi Templates for Elementor plugin <= 3.7.2 - Cross Site Scripting (XSS) vuln…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects WP…

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.9 MEDIUM
CVE-2026-85242 — Server-Side Request Forgery via Favicon Redirect to Local Network Resources in Playwright…

PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application validates the initial favicon…

playwright_capture | Remote | Server-Side Request Forgery
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-85186 — itsourcecode Online Medicine Delivery System Customer Controller controller.php doupdatei…

A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function doupdateimage of the file /customer/controller.php?action=photos of …

online_medicine_delivery_system | Remote | Misconfiguration
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-84849 — WordPress Pre-Orders for WooCommerce plugin <= 2.3 - Bypass Vulnerability vulnerability

Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.

Remote | Authentication
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-84848 — WordPress Quick Event Manager plugin <= 9.17 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-84847 — WordPress Quick Event Manager plugin <= 9.17 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-84836 — WordPress WC Ukraine Shipping plugin <= 1.22.3 - Insecure Direct Object References (IDOR)…

Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions.

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-84834 — WordPress JobSearch plugin <= 3.2.0 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.

jobsearch_wp_job_board jobsearch | Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-84814 — WordPress Bricksforge plugin <= 3.1.8.8 - Privilege Escalation vulnerability

Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.3 CRITICAL
CVE-2026-84813 — WordPress GeoDirectory plugin <= 2.8.174 - SQL Injection vulnerability

Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.

geodirectory | Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-84812 — WordPress BP Better Messages plugin <= 2.15.27 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.1 HIGH
CVE-2026-84779 — WordPress Agentimus – AI SEO, llms.txt & MCP for AI Agents plugin <= 1.51.0 - Broken Acce…

Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt &amp; MCP for AI Agents <= 1.51.0 versions.

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-84778 — WordPress Migrate Guru – Site Migration & Cloning plugin <= 6.65 - Denial of Service Atta…

Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration &amp; Cloning <= 6.65 versions.

Remote | Denial of Service
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.4 HIGH
CVE-2026-84777 — WordPress Really Simple SSL plugin <= 9.8.0 - 2FA Bypass vulnerability

Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.

Remote | Authentication
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-84776 — WordPress MalCare Security plugin <= 6.69 - Denial of Service Attack vulnerability

Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions.

Remote | Denial of Service
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.1 MEDIUM
CVE-2026-84774 — WordPress WP Statistics plugin <= 14.16.11 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.

wp_statistics | Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.2 HIGH
CVE-2026-84773 — WordPress EWWW Image Optimizer plugin <= 8.7.6 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions.

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-84769 — WordPress Business Directory plugin <= 6.4.26 - Insecure Direct Object References (IDOR) …

Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.3 CRITICAL
CVE-2026-84768 — WordPress VikAppointments Services Booking Calendar plugin <= 1.2.20 - SQL Injection vuln…

Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.

Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.3 MEDIUM
CVE-2026-84767 — WordPress BookIt plugin <= 2.6.0.3 - Bypass Vulnerability vulnerability

Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.

Remote | Authentication
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Showing 20 of 12623 Results