CVE-2026-66580
— WordPress Product Feed Manager plugin <= 7.12.0 - SQL Injection vulnerability
Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.
Remote
|
Injection
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-66579
— WordPress JetElements For Elementor plugin <= 2.9.2.1 - Cross Site Scripting (XSS) vulner…
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.
Remote
|
Cross-Site Scripting
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-66578
— WordPress PropertyHive plugin <= 2.2.6 - Cross Site Scripting (XSS) vulnerability
Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.
Remote
|
Cross-Site Scripting
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-66577
— WordPress JetSearch plugin <= 3.6.3 - Cross Site Scripting (XSS) vulnerability
Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.
Remote
|
Cross-Site Scripting
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-66576
— WordPress JetBlocks For Elementor plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerabil…
Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.
Remote
|
Cross-Site Scripting
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-66575
— WordPress King Addons for Elementor plugin <= 51.1.81 - Insecure Direct Object References…
Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.
Remote
|
Authentication
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-66574
— WordPress Element Pack Elementor Addons plugin <= 8.8.3 - Cross Site Scripting (XSS) vuln…
Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.
Remote
|
Cross-Site Scripting
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-66573
— WordPress JetTabs plugin <= 2.3.3.1 - Cross Site Scripting (XSS) vulnerability
Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.
Remote
|
Cross-Site Scripting
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-66572
— WordPress JetBlog plugin <= 2.4.10 - Cross Site Scripting (XSS) vulnerability
Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.
Remote
|
Cross-Site Scripting
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-66571
— WordPress Asset CleanUp: Page Speed Booster plugin <= 1.4.0.5 - Cross Site Request Forger…
Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.
Remote
|
Cross-Site Request Forgery
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-62108
— WordPress Headless Single Sign On plugin <= 1.7.0 - Broken Authentication vulnerability
Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.
Remote
|
Authentication
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-62104
— WordPress Migratico Lite plugin <= 2.6.8 - Remote Code Execution (RCE) vulnerability
Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.
Remote
|
Authentication
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-62101
— WordPress EduAdmin Booking plugin <= 5.4.2 - Broken Authentication vulnerability
Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.
Remote
|
Authentication
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-90986
— WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.21 - Cross Site Scripting…
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions.
Remote
|
Cross-Site Scripting
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-92932
— MISP sachertortephp Xml::build() Operator Precedence Bypass Allows Unintended HTTPS SSRF …
In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The original condition …
Remote
|
Server-Side Request Forgery
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-92921
— admin3 through 3.0.0 Weak Password Hashing via Single-Round MD5
admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database access can recover plaintext passwords thro…
Remote
|
Cryptography
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-92920
— admin3 through 3.0.0 Session Not Invalidated When a User Account Is Disabled
admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue using bea…
Remote
|
Authentication
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-92919
— admin3 through 3.0.0 Arbitrary File Write via Path Traversal in Storage Upload Filename
admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use …
Remote
|
Path Traversal
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-92918
— admin3 through 3.0.0 Session Token Disclosure via Audit Log
admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /l…
Remote
|
Information Disclosure
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
CVE-2026-92904
— Rubygem-foreman_remote_execution: job output readable without object-level view_job_invoc…
A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller'…
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Sep 17, 2026