Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-15345 — ShortPixel Adaptive Images <= 3.11.5 - Missing Authorization to Authenticated (Subscriber…

The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.11.5. This is due to the plugin…

shortpixel_adaptive_images | Remote | Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-15056 — StoreEngine <= 2.1.1 - Authenticated (Vendor+) Arbitrary File Read via Path Traversal in …

The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.1 via …

Remote | Path Traversal
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-13712 — Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL

The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attributes, allowing users with a role as low as contribu…

| Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.6 MEDIUM
CVE-2026-10035 — Turnkey bbPress by WeaverTheme <= 1.7.1 - Authenticated (Administrator+) PHP Object Injec…

The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deserialization of untrusted input in the wvrbbp_set_to_s…

Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-19933 — DefaultFuction Customer-Relationship-Management-In-C-Project Customer Search gets stack-b…

A weakness has been identified in DefaultFuction Customer-Relationship-Management-In-C-Project 2.0. Impacted is the function gets of the component Customer Search Module. This manipulation causes sta…

customer-relationship-management-in-c-project | Remote | Memory Corruption
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-19932 — DefaultFuction Notice-System-Managent NoticeController execute GroovyShell.evaluate code …

A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects the function GroovyShell.evaluate of the file /execute of the component NoticeController. The mani…

notice-system-managent | Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
9.8 CRITICAL
CVE-2026-18432 — Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_i…

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logi…

frontend_admin | Remote | Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
5.4 MEDIUM
CVE-2026-18385 — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Res…

The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in al…

profilepress | Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
8.8 HIGH
CVE-2026-17123 — Royal Addons for Elementor <= 1.7.1064 - Authenticated (Contributor+) Server-Side Request…

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget…

royal_elementor_addons | Remote | Server-Side Request Forgery
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
4.3 MEDIUM
CVE-2026-16779 — Kubio AI Page Builder <= 2.8.5 - Missing Authorization to Authenticated (Contributor+) Fr…

The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.5. This is due to the plugin not properly verifying that a user is autho…

Remote | Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
8.8 HIGH
CVE-2026-16099 — Podlove Podcast Publisher <= 4.5.3 - Authenticated (Contributor+) PHP Object Injection to…

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and includ…

podlove_podcast_publisher | Remote | Path Traversal
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
9.8 CRITICAL
CVE-2026-16098 — ProSolution WP Client <= 2.0.10 - Unauthenticated Arbitrary File Upload via Content-Dispo…

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing val…

Remote | Authentication
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-16079 — Fullscreen Galleria <= 1.6.12 - Authenticated (Contributor+) SQL Injection via 'href' Att…

The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content in all versions up to, and including, 1.6.12 due to insufficient escaping on t…

Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-15963 — Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) SQL Injection via '…

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz Option in all versions up to, and including, 11.2.…

Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.4 MEDIUM
CVE-2026-15726 — Serious Slider <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 't…

The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in all versions up to, and including, 1.4.0 due to insufficient input sanitization…

Remote | Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
4.9 MEDIUM
CVE-2026-15602 — NEX-Forms <= 9.2.4 - Authenticated (Admin+) SQL Injection via 'additional_params' Paramet…

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.2.4 due t…

nex-forms | Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
5.3 MEDIUM
CVE-2026-15441 — Product Table & List Builder For WooCommerce <= 5.6.0 - Unauthenticated CSS Injection via…

The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and including, 5.6.0 via the 'laptop_scroll_offset' shortcode attribute exposed through the unauthenti…

Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.4 MEDIUM
CVE-2026-15066 — Loco Translate <= 2.8.7 - Authenticated (Translator+) Stored Cross-Site Scripting via PO …

The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and including, 2.8.7 due to insufficient input sanitization …

Remote | Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.1 MEDIUM
CVE-2026-15009 — Advanced File Manager <= 5.4.12 - Reflected Cross-Site Scripting via postMessage 'soundFi…

The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'soundFile' parameter in all ve…

advanced_file_manager | Remote | Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
7.2 HIGH
CVE-2026-15002 — Autopay <= 5.0.0 - Unauthenticated Stored Cross-Site Scripting via 'bm_woocommerce_css_ed…

The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 via the 'bm_woocommerce_css_editor_content' POST pa…

Remote | Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
Showing 20 of 11171 Results