Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-78159 — The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution v…

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation o…

the_events_calendar | Remote | Injection
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
9.8 CRITICAL
CVE-2026-78006 — The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execu…

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient …

the_events_calendar | Remote | Injection
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.5 MEDIUM
CVE-2026-77161 — Smart Marketing SMS and Newsletters Forms <= 5.1.24 - Authenticated (Subscriber+) SQL Inj…

The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and including, 5.1.24 due to insufficient escaping …

Remote | Injection
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.3 MEDIUM
CVE-2026-17585 — Royal Addons for Elementor <= 1.7.1066 - Unauthenticated Sensitive Information Exposure v…

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wp…

royal_elementor_addons | Remote | Information Disclosure
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
7.5 HIGH
CVE-2026-16482 — rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 - Unauthenticated SQL Injection v…

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to …

Remote | Injection
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.3 MEDIUM
CVE-2026-11355 — DT LMS <= 1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modifi…

The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX handlers (including dtlms_save_poc_set…

Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
4.9 MEDIUM
CVE-2026-87919 — Product XML Feed Manager for WooCommerce < 3.1.1 - Contributor+ Arbitrary Product Deletio…

The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted pro…

Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.3 MEDIUM
CVE-2026-87918 — WPBot < 8.5.7 - Unauthenticated AI Provider API Abuse via Multiple AJAX Actions

The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attacker…

Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.3 MEDIUM
CVE-2026-87916 — WPBot 8.4.9 - 8.5.9 - Unauthenticated Chat Visitor PII Disclosure

The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, em…

Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.3 MEDIUM
CVE-2026-87894 — Rox Appointment Booking 1.0.9 - 1.2.2 - Unauthenticated Customer PII Disclosure via IDOR

The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a s…

Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.3 MEDIUM
CVE-2026-87892 — Rox Appointment Booking < 1.2.0 - Unauthenticated Price Manipulation and Payment Method R…

The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthe…

Remote | Misconfiguration
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.5 MEDIUM
CVE-2026-87891 — Rox Appointment Booking < 1.2.0 - Unauthenticated Holiday Schedule Modification via REST …

The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the…

Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
8.0 HIGH
CVE-2026-87888 — YayPricing < 3.5.7 - Subscriber+ Stored XSS via save_page_data REST Route

The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScri…

Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
7.5 HIGH
CVE-2026-87842 — Zonify < 1.0.5 - Unauthenticated Account Login Token Disclosure

The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retriev…

Remote | Authentication
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
4.3 MEDIUM
CVE-2026-87797 — Client Invoicing by Sprout Invoices < 20.8.16 - Subscriber+ Private Note Overwrite via si…

The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any au…

Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
8.8 HIGH
CVE-2026-87759 — Add User Autocomplete < 1.2 - Subscriber+ Privilege Escalation

The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any…

Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.8 MEDIUM
CVE-2026-86790 — WP Highlight Box <= 1.0 - Contributor+ Stored XSS via highlight-box Shortcode

The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contribu…

Remote | Cross-Site Scripting
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
9.8 CRITICAL
CVE-2026-85681 — WP Component <= 2.2.4 - Unauthenticated Privilege Escalation via Arbitrary Blog Option Up…

The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and t…

Remote | Authentication
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
9.8 CRITICAL
CVE-2026-84171 — WP Images Upload on Piclect <= 1.0 - Unauthenticated Arbitrary File Upload

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated atta…

Remote | Authentication
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
8.1 HIGH
CVE-2026-84099 — IDB Ecommerce (wpStoreCart 5) <= 5.0.7 - Unauthenticated PHP Object Injection via bundled…

The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, all…

Remote | Injection
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
Showing 20 of 13189 Results