CVE-2026-62034
— WordPress Before After Image Comparison – Image comparison for WP plugin <= 1.1.21 - Cros…
Unauthenticated Cross Site Scripting (XSS) in Before After Image Comparison – Image comparison for WP <= 1.1.21 versions.
Remote
|
Cross-Site Scripting
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62033
— WordPress uListing plugin <= 2.2.0 - Settings Change vulnerability
Subscriber Settings Change in uListing <= 2.2.0 versions.
Remote
|
Authentication
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62032
— WordPress DirectoryPress plugin <= 3.6.27 - Local File Inclusion vulnerability
Unauthenticated Local File Inclusion in DirectoryPress <= 3.6.27 versions.
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62031
— WordPress uListing plugin <= 2.2.0 - SQL Injection vulnerability
Unauthenticated SQL Injection in uListing <= 2.2.0 versions.
Remote
|
Injection
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62030
— WordPress StreamCast plugin <= 2.4.5 - Server Side Request Forgery (SSRF) vulnerability
Unauthenticated Server Side Request Forgery (SSRF) in StreamCast <= 2.4.5 versions.
Remote
|
Server-Side Request Forgery
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62027
— WordPress Team Section Block plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Team Section Block <= 2.0.4 versions.
Remote
|
Cross-Site Scripting
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62025
— WordPress Tailored Tools plugin <= 3.0.3 - Arbitrary File Upload vulnerability
Unauthenticated Arbitrary File Upload in Tailored Tools <= 3.0.3 versions.
Remote
|
Authentication
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62024
— WordPress CodeBard Help Desk plugin <= 1.1.2 - Arbitrary File Upload vulnerability
Subscriber Arbitrary File Upload in CodeBard Help Desk <= 1.1.2 versions.
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62022
— WordPress Tonda Membership plugin <= 1.0.1 - Privilege Escalation vulnerability
Unauthenticated Privilege Escalation in Tonda Membership <= 1.0.1 versions.
Remote
|
Authorization
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62021
— WordPress Angio theme <= 1.1.1 - PHP Object Injection vulnerability
Subscriber PHP Object Injection in Angio <= 1.1.1 versions.
Remote
|
Injection
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-62020
— WordPress TouchUp theme < 1.4 - Local File Inclusion vulnerability
Unauthenticated Local File Inclusion in TouchUp < 1.4 versions.
Remote
|
Path Traversal
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-57742
— WordPress Kids Planet theme <= 2.2.14.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group Kids Planet allows Reflected XSS.
This issue affects Kids Planet: from n/a throug…
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-48194
— WordPress DukaMarket theme <= 1.3.0 - Local File Inclusion vulnerability
Unauthenticated Local File Inclusion in DukaMarket <= 1.3.0 versions.
Remote
|
Path Traversal
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-48193
— WordPress Uminex theme <= 1.0.9 - Local File Inclusion vulnerability
Unauthenticated Local File Inclusion in Uminex <= 1.0.9 versions.
Remote
|
Path Traversal
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-45440
— WordPress WP Ultimate CSV Importer plugin <= 9.2 - SQL Injection vulnerability
Administrator SQL Injection in WP Ultimate CSV Importer <= 9.2 versions.
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-42777
— WordPress Aalto theme <= 1.8 - Local File Inclusion vulnerability
Unauthenticated Local File Inclusion in Aalto <= 1.8 versions.
Remote
|
Path Traversal
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-42724
— WordPress CleanSkin theme <= 1.5.0 - Local File Inclusion vulnerability
Unauthenticated Local File Inclusion in CleanSkin <= 1.5.0 versions.
Remote
|
Path Traversal
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-42723
— WordPress CleanSkin theme <= 1.5.0 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in CleanSkin <= 1.5.0 versions.
Remote
|
Injection
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-42722
— WordPress Frontend Admin by DynamiApps plugin <= 3.29.13 - SQL Injection vulnerability
Administrator SQL Injection in Frontend Admin by DynamiApps <= 3.29.13 versions.
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-42719
— WordPress Dynamic User Directory plugin <= 2.4 - PHP Object Injection vulnerability
Subscriber PHP Object Injection in Dynamic User Directory <= 2.4 versions.
Remote
|
Injection
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026