Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-62034 — WordPress Before After Image Comparison – Image comparison for WP plugin <= 1.1.21 - Cros…

Unauthenticated Cross Site Scripting (XSS) in Before After Image Comparison – Image comparison for WP <= 1.1.21 versions.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.6 HIGH
CVE-2026-62033 — WordPress uListing plugin <= 2.2.0 - Settings Change vulnerability

Subscriber Settings Change in uListing <= 2.2.0 versions.

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-62032 — WordPress DirectoryPress plugin <= 3.6.27 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in DirectoryPress <= 3.6.27 versions.

directorypress | Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.3 CRITICAL
CVE-2026-62031 — WordPress uListing plugin <= 2.2.0 - SQL Injection vulnerability

Unauthenticated SQL Injection in uListing <= 2.2.0 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-62030 — WordPress StreamCast plugin <= 2.4.5 - Server Side Request Forgery (SSRF) vulnerability

Unauthenticated Server Side Request Forgery (SSRF) in StreamCast <= 2.4.5 versions.

Remote | Server-Side Request Forgery
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-62027 — WordPress Team Section Block plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Team Section Block <= 2.0.4 versions.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.0 CRITICAL
CVE-2026-62025 — WordPress Tailored Tools plugin <= 3.0.3 - Arbitrary File Upload vulnerability

Unauthenticated Arbitrary File Upload in Tailored Tools <= 3.0.3 versions.

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.9 CRITICAL
CVE-2026-62024 — WordPress CodeBard Help Desk plugin <= 1.1.2 - Arbitrary File Upload vulnerability

Subscriber Arbitrary File Upload in CodeBard Help Desk <= 1.1.2 versions.

codebard_help_desk | Remote | Misconfiguration
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-62022 — WordPress Tonda Membership plugin <= 1.0.1 - Privilege Escalation vulnerability

Unauthenticated Privilege Escalation in Tonda Membership <= 1.0.1 versions.

Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.8 HIGH
CVE-2026-62021 — WordPress Angio theme <= 1.1.1 - PHP Object Injection vulnerability

Subscriber PHP Object Injection in Angio <= 1.1.1 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-62020 — WordPress TouchUp theme < 1.4 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in TouchUp < 1.4 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-57742 — WordPress Kids Planet theme <= 2.2.14.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group Kids Planet allows Reflected XSS. This issue affects Kids Planet: from n/a throug…

kids_planet | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-48194 — WordPress DukaMarket theme <= 1.3.0 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in DukaMarket <= 1.3.0 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-48193 — WordPress Uminex theme <= 1.0.9 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in Uminex <= 1.0.9 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.6 HIGH
CVE-2026-45440 — WordPress WP Ultimate CSV Importer plugin <= 9.2 - SQL Injection vulnerability

Administrator SQL Injection in WP Ultimate CSV Importer <= 9.2 versions.

wp_ultimate_csv_importer | Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-42777 — WordPress Aalto theme <= 1.8 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in Aalto <= 1.8 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-42724 — WordPress CleanSkin theme <= 1.5.0 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in CleanSkin <= 1.5.0 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-42723 — WordPress CleanSkin theme <= 1.5.0 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in CleanSkin <= 1.5.0 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.6 HIGH
CVE-2026-42722 — WordPress Frontend Admin by DynamiApps plugin <= 3.29.13 - SQL Injection vulnerability

Administrator SQL Injection in Frontend Admin by DynamiApps <= 3.29.13 versions.

frontend_admin | Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-42719 — WordPress Dynamic User Directory plugin <= 2.4 - PHP Object Injection vulnerability

Subscriber PHP Object Injection in Dynamic User Directory <= 2.4 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Showing 20 of 14131 Results