Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-3666 — wpForo Forum <= 2.4.16 - Authenticated (Subscriber+) Arbitrary File Deletion via Post Body

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal …

wpforo_forum | Remote | Path Traversal
Apr 04, 2026 Apr 24, 2026
Apr 04, 2026
Apr 24, 2026
6.5 MEDIUM
CVE-2026-3309 — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Res…

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all ve…

profilepress | Remote | Injection
Apr 04, 2026 Apr 24, 2026
Apr 04, 2026
Apr 24, 2026
7.2 HIGH
CVE-2026-2936 — Visitor Traffic Real Time Statistics <= 8.4 - Unauthenticated Stored Cross-Site Scripting

The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_title' parameter in all versions up to, and including, 8.4 due to insufficient…

visitor_traffic_real_time_statistics | Remote | Cross-Site Scripting
Apr 04, 2026 Apr 24, 2026
Apr 04, 2026
Apr 24, 2026
7.5 HIGH
CVE-2026-1233 — Text to Speech (TTS) by Mementor <= 1.9.8 - Use of Hardcoded Password to Unauthenticated …

The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containin…

Remote | Information Disclosure
Apr 04, 2026 Apr 24, 2026
Apr 04, 2026
Apr 24, 2026
6.4 MEDIUM
CVE-2026-0626 — WPFunnels <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpf_op…

The WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpf_optin_form' shortcode in all v…

Remote | Cross-Site Scripting
Apr 04, 2026 Apr 24, 2026
Apr 04, 2026
Apr 24, 2026
5.3 MEDIUM
CVE-2025-14938 — Listeo-Core - Directory Plugin by Purethemes <= 2.0.27 - Unauthenticated Arbitrary Media …

The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and including, 2.0.27 via the "listeo_core_handle_dropped_media" function. This is …

Remote | Authorization
Apr 04, 2026 Apr 24, 2026
Apr 04, 2026
Apr 24, 2026
Showing 20 of 5526 Results