Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-18510 — TranslatePress <= 3.2.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versio…

Remote | Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.4 MEDIUM
CVE-2026-18400 — Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Author+) Stored C…

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and…

Remote | Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-18395 — Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes

The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before outputting them back in a page, allowing users with the contributor role and abo…

| Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-18050 — Events Manager < 7.4 - Unauthenticated Pending Upload Disclosure via events-manager/v1/up…

The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve anothe…

| Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-16954 — AI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and Bearer Tokens

The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admin page's inline script data, allowing users with the Editor role to read the si…

| Information Disclosure
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-16734 — Stripe Payment Forms by WP Full Pay < 8.5.2 - Unauthenticated Payment Intent Amount Manip…

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allo…

| Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-16537 — Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode

The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputting it in an HTML attribute, allowing users with the Contributor role and above t…

| Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-16290 — ProfileGrid < 6.0.0.0 - Unauthenticated Group Member List Disclosure via pm_get_all_users…

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauth…

| Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-16268 — Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler

The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the server side, allowing unauthenticated attackers t…

| Server-Side Request Forgery
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-16065 — Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import

The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and a…

| Injection
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-16054 — Drag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated File Deletio…

The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-delet…

| Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-14829 — Checkimate <= 1.0.13 - Unauthenticated License Deactivation via Hardcoded Secret

The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a sh…

| Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-14547 — Estatik Real Estate Plugin < 4.3.3 - Unauthenticated Arbitrary-Recipient Mail Relay via R…

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated use…

| Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-14314 — PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Image Attachment Disclos…

The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated atta…

| Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-14313 — PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Order Receipt Tampering …

PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (l…

| Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-14240 — Tourmaster < 5.4.9 - Unauthenticated Sensitive Data Disclosure via Order Export

The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its publicly accessible directory with no access control, allowing unauthenticated use…

| Information Disclosure
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-14204 — Google Authenticator < 0.56 - 2FA Secret Overwrite via CSRF

The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret…

| Cross-Site Request Forgery
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-13703 — SEO Redirection Plugin – 301 Redirect Manager < 9.19 - Subscriber+ Redirect Rule Disclosu…

The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any logged-in user such as a subscriber to read the sit…

| Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-13154 — Essential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Content Disclosure…

The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing un…

| Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-13153 — Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST pro…

The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the res…

| Information Disclosure
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
Showing 20 of 9854 Results