Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.4 HIGH
CVE-2026-59546 — WordPress Hide My WP Ghost plugin <= 7.0.06 - 2FA Bypass vulnerability

Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.

Remote | Authentication
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.5 HIGH
CVE-2026-59539 — WordPress Paid Member Subscriptions plugin <= 3.0.7 - Insecure Direct Object References (…

Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.

Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
9.3 CRITICAL
CVE-2026-59538 — WordPress GamiPress plugin <= 7.9.7 - SQL Injection vulnerability

Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.

Remote | Injection
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.6 HIGH
CVE-2026-59537 — WordPress Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin …

Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions.

Remote | Injection
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.5 HIGH
CVE-2026-59536 — WordPress CoCart – Headless ecommerce plugin <= 4.8.4 - Broken Access Control vulnerabili…

Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.

Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.3 HIGH
CVE-2026-59535 — WordPress Thrive Product Manager plugin <= 10.9.2 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.

Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.5 HIGH
CVE-2026-59534 — WordPress Post My CF7 Form plugin <= 6.2.0 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.

Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
9.3 CRITICAL
CVE-2026-59533 — WordPress Relevanssi Light plugin <= 1.2.2 - SQL Injection vulnerability

Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.

Remote | Injection
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.5 HIGH
CVE-2026-59532 — WordPress Booking and Rental Manager plugin <= 2.7.2 - Price Manipulation vulnerability

Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.

Remote | Authentication
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.5 HIGH
CVE-2026-59531 — WordPress Falcon – WordPress Optimizations & Tweaks plugin <= 2.10.0 - Unknown vulnerabil…

Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.

Remote | Authentication
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.5 HIGH
CVE-2026-59530 — WordPress Stripe For WooCommerce plugin <= 4.0.7 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.

stripe_for_woocommerce | Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.5 HIGH
CVE-2026-59529 — WordPress Ebook Store plugin <= 6.19 - Sensitive Data Exposure vulnerability

Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.

Remote | Information Disclosure
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.5 HIGH
CVE-2026-59528 — WordPress ShipTime: Discounted Shipping Rates plugin <= 1.1.1 - Sensitive Data Exposure v…

Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.

Remote | Information Disclosure
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
9.3 CRITICAL
CVE-2026-59527 — WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

Remote | Injection
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.5 MEDIUM
CVE-2026-10819 — Mattermost Server Denial of Service via Animated GIF Emoji Upload

Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an…

Remote | Denial of Service
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
4.3 MEDIUM
CVE-2026-10600 — Denial of service via unbounded document content extraction in Mattermost Server

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows a…

Remote | Denial of Service
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
4.8 MEDIUM
CVE-2025-59181 — Path traversal Vulnerability

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, deny…

packet_core_controller | Path Traversal
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
5.1 MEDIUM
CVE-2025-59180 — Use of Hard-coded Credentials Vulnerability

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded c…

packet_core_controller | Authentication
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
4.8 MEDIUM
CVE-2025-59178 — Exposure of Sensitive System Information to an Unauthorized Control Sphere Vulnerability

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other user…

packet_core_controller | Information Disclosure
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.8 MEDIUM
CVE-2025-59177 — Generation of Error Message Containing Sensitive Information Vulnerability

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret…

packet_core_controller | Information Disclosure
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Showing 20 of 9091 Results