CVE-2026-59546
— WordPress Hide My WP Ghost plugin <= 7.0.06 - 2FA Bypass vulnerability
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
Remote
|
Authentication
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
CVE-2026-59539
— WordPress Paid Member Subscriptions plugin <= 3.0.7 - Insecure Direct Object References (…
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
Remote
|
Authorization
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
CVE-2026-59538
— WordPress GamiPress plugin <= 7.9.7 - SQL Injection vulnerability
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
Remote
|
Injection
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
CVE-2026-59537
— WordPress Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin …
Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions.
Remote
|
Injection
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
CVE-2026-59536
— WordPress CoCart – Headless ecommerce plugin <= 4.8.4 - Broken Access Control vulnerabili…
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
Remote
|
Authorization
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
CVE-2026-59535
— WordPress Thrive Product Manager plugin <= 10.9.2 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
Remote
|
Authorization
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
CVE-2026-59534
— WordPress Post My CF7 Form plugin <= 6.2.0 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
Remote
|
Authorization
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
CVE-2026-59533
— WordPress Relevanssi Light plugin <= 1.2.2 - SQL Injection vulnerability
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
Remote
|
Injection
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
CVE-2026-59532
— WordPress Booking and Rental Manager plugin <= 2.7.2 - Price Manipulation vulnerability
Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
Remote
|
Authentication
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
CVE-2026-59531
— WordPress Falcon – WordPress Optimizations & Tweaks plugin <= 2.10.0 - Unknown vulnerabil…
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
Remote
|
Authentication
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
CVE-2026-59530
— WordPress Stripe For WooCommerce plugin <= 4.0.7 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
CVE-2026-59529
— WordPress Ebook Store plugin <= 6.19 - Sensitive Data Exposure vulnerability
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
Remote
|
Information Disclosure
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
CVE-2026-59528
— WordPress ShipTime: Discounted Shipping Rates plugin <= 1.1.1 - Sensitive Data Exposure v…
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
Remote
|
Information Disclosure
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
CVE-2026-59527
— WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
Remote
|
Injection
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
CVE-2026-10819
— Mattermost Server Denial of Service via Animated GIF Emoji Upload
Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an…
Remote
|
Denial of Service
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
CVE-2026-10600
— Denial of service via unbounded document content extraction in Mattermost Server
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows a…
Remote
|
Denial of Service
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, deny…
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded c…
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
CVE-2025-59178
— Exposure of Sensitive System Information to an Unauthorized Control Sphere Vulnerability
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other user…
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
CVE-2025-59177
— Generation of Error Message Containing Sensitive Information Vulnerability
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret…
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Jul 27, 2026