Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-78584 — Kibana Osquery Information Disclosure Vulnerability

Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-quer…

kibana | Remote | Information Disclosure
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-78153 — Restrict User Access 2.6 - 2.8 - Unauthenticated Content Protection Bypass via REST API R…

The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to byp…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-77794 — RegistrationMagic 6.0.0.0 - 6.0.9.8 - Unauthenticated Payment Bypass via Zero Quantity

The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users t…

registrationmagic | Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-77793 — RegistrationMagic < 6.0.9.9 - Unauthenticated Payment Bypass via Omitted Price Field

The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without payi…

registrationmagic | Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
9.9 CRITICAL
CVE-2026-77009 — WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console

The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to r…

Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
10.0 CRITICAL
CVE-2026-4357 — Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload

The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to …

Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.4 MEDIUM
CVE-2026-2811 — Ajaxify Comments < 3.2 - Unauthenticated HTTP Header Injection

The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. This makes it possible for un…

Remote | Injection
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.5 MEDIUM
CVE-2026-2688 — CM HIPAA Forms < 3.2.0 - Unauthenticated Authorization Bypass

The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip non…

Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
3.5 LOW
CVE-2026-19698 — GutenKit < 2.5.1 - Contributor+ Stored CSS Injection

The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it outputs on the front end, allowing users with the Cont…

Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-17563 — WP User Frontend < 4.3.11 - Unauthenticated Post Creation via Subscription-Gated Form

The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticat…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
3.8 LOW
CVE-2026-14326 — Timetics <= 1.0.61 - Staff+ Cross-Staff Appointment Modification via IDOR

The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or ta…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.5 MEDIUM
CVE-2026-14255 — IFC File Parsing Uncontrolled Recursion in Certain Autodesk Products

A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the appl…

shared_components | Denial of Service
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.6 MEDIUM
CVE-2026-10821 — Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCE

The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file when the file-based redirec…

Remote | Injection
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
9.8 CRITICAL
CVE-2025-9314 — Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload

The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component

Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2025-8945 — Wp Edit Password Protected < 1.3.5 - Protection Bypass via REST API

The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API.

Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
3.5 LOW
CVE-2025-15692 — Icegram Express < 5.8.6 - Admin+ Stored XSS

The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users with the Administrator rol…

icegram_express | Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2025-15490 — Passster < 4.2.26 - Global Protection Bypass

The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs

passster | Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2025-15489 — Passster < 4.2.24 - Password Protection Bypass

The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content

passster | Remote | Information Disclosure
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.2 HIGH
CVE-2025-15485 — Auto x LINE <= 1.0.0 – Unauthenticated REST API Endpoints Call

The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2025-15481 — Notification Bar for WordPress <= 1.1.8 – Unauthenticated Subscriber Data Disclosure

The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails.

Remote | Information Disclosure
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
Showing 20 of 12630 Results