Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-18466 — WP Maps < 4.9.8 - Subscriber+ Unlimited Autoloaded Option Creation

The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with a Subscriber account to create an unlimited numbe…

| Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-18231 — WP Directory Kit < 1.5.7 - Unauthenticated User Email Disclosure via select_2_ajax_user

The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database rows, allowing unauthenticated attackers …

| Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-18202 — JetEngine < 3.8.14 - Author+ Stored XSS via SVG Upload

The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing users with the upload files capability, such as Auth…

| Cross-Site Scripting
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-18051 — W3 Total Cache < 2.10.5 - Unauthenticated Arbitrary Directory File Write and .htaccess Ov…

The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing d…

| Path Traversal
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-18031 — TabaPay Gateway <= 1.4.0 - Unauthenticated Account Takeover via Payment Callback

The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated with the referenced order, allowing unauthenticated …

| Authentication
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-17565 — Animation Addons for Elementor < 2.7.2 - Unauthenticated Server-Side Request Forgery

The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated use…

| Server-Side Request Forgery
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-16979 — SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key E…

The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read…

| Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-16950 — Product Shortlist <= 1.0.4 - Unauthenticated SQL Injection via get_shortlisted_products

The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection …

| Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-16617 — Simple File List <= 6.3.11 - Unauthenticated Stored XSS via File Description

The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when fron…

| Cross-Site Scripting
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-16616 — Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path Traver…

The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to read arbitrary files on the server…

| Path Traversal
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-16570 — NextScripts: Social Networks Auto-Poster < 4.4.8 - Reflected XSS via Facebook OAuth Callb…

The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers to perfor…

| Cross-Site Scripting
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-16058 — YayCurrency < 3.3.5 - Unauthenticated Order and Vendor Financial Data Disclosure via Doka…

The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers that are reachable by unauthenticated users, allo…

| Information Disclosure
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-15253 — Easy Media Replace <= 0.2.0 - Author+ Stored XSS via Attachment Title

The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in the media library list view, allowing users with th…

| Cross-Site Scripting
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-14861 — User Verification <= 2.0.47 - Unauthenticated Arbitrary Account Lockout via IDOR

The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting t…

| Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-14826 — Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Email and Results Configuration…

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuratio…

| Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-14825 — Quiz And Survey Master < 11.2.4 - Contributor+ Arbitrary Quiz Text Settings Update via ID…

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level ac…

| Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-14334 — Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored XSS via S…

The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the B…

| Cross-Site Scripting
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-14287 — TenWeb Speed Optimizer < 2.33.5 - Unauthenticated Stored XSS via Critical CSS Token Bypass

The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated request handler and does not escape attacker-supplied stylesheet content before ren…

| Cross-Site Scripting
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-14196 — WCFM Marketplace < 3.8.1 - Store Vendor+ Cross-Vendor Review Deletion and Status Update v…

The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review before allowing it to be unapproved or deleted, allowing any vendor to modify or permanentl…

| Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-13175 — Eventin < 4.1.21 - Contributor+ Schedule Deletion and Modification via IDOR

The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with contributor-level access and above to alter or de…

| Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Showing 20 of 12341 Results