Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.6 MEDIUM
CVE-2026-5769 — Brocade SANnav Sensitive Information Disclosure via Memory Swap File

A vulnerability in Brocade SANnav before 3.0.1 can have the Brocade Fabric OS switch admin password captured in plaintext within a memory swap file on the server hosting the Brocade SANnav Virtual Ma…

sannav | Information Disclosure
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-94275 — Track Orders for WooCommerce < 1.2.7 - Unauthenticated PII Disclosure via 'email' Paramet…

The Track Orders for WooCommerce WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing unauthenticated attackers to obtain a customer's n…

| Information Disclosure
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-94258 — SMS Alert 3.6.4 - 4.0.0 - Admin+ Network User Billing Phone Disclosure via Bulk User Acti…

The SMS Alert WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning their stored billing phone numbers, allowing an admi…

| Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-94246 — Wallet System for WooCommerce 2.0.0 - 2.7.10 - Subscriber+ Forged Wallet Withdrawal Reque…

The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the wallet account named in a withdrawal submission belongs to the user making it, allowing any authenticated use…

| Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-94245 — Wallet System for WooCommerce 2.0.0 - 2.7.10 - Subscriber+ Arbitrary Wallet Balance Theft…

The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the user submitting a wallet transfer owns the wallet being debited, allowing any authenticated user, including o…

| Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-94244 — Wallet System for WooCommerce < 2.8.0 - Subscriber+ Store-Wide Wallet Transaction Disclos…

The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not perform any capability check, and relies on a token any authenticated user can obtain from a front-end page, before generatin…

| Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-86828 — BackWPup < 5.7.7 - Admin+ Path Traversal to RCE via Restore PclZip Fallback

The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privile…

| Path Traversal
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-86827 — BackWPup 3.3 - 5.7.6 - Unauthenticated Backup Job Execution via wp-cron.php

The BackWPup WordPress plugin before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress's internal scheduled-event dispatch, allow…

| Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-86826 — BackWPup < 5.7.7 - Unauthenticated Sensitive Data Disclosure via Restore Working Director…

The BackWPup WordPress plugin before 5.7.7 does not properly restrict web access to the working directory it uses during backup restores, allowing unauthenticated attackers, on webservers that do no…

| Information Disclosure
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-105260 — Database Addon For WPForms < 1.1.1 - Arbitrary Form Entry Deletion via CSRF

The Database Addon For WPForms ( wpforms entries ) WordPress plugin before 1.1.1 does not verify the CSRF nonce when the field is omitted and performs no capability check of its own, allowing attack…

| Cross-Site Request Forgery
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-105198 — LatePoint < 5.7.3 - Unauthenticated Customer PII Disclosure via IDOR

The Appointment Booking Plugin WordPress plugin before 5.7.3 does not verify that the caller owns the order referenced by an order-item identifier before rendering that order's confirmation summary,…

| Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-105197 — LatePoint < 5.6.5 - Agent+ Arbitrary Order, Customer and Transaction Deletion via IDOR

The Appointment Booking Plugin WordPress plugin before 5.6.5 does not verify that a backend staff user is authorized to act on the specific record targeted for deletion, allowing an authenticated us…

| Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-105196 — LatePoint < 5.6.9 - Agent+ Cross-Agent Data Disclosure and Modification via Abilities API

The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, allowing an authenticated user holding the LatePoin…

| Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-105195 — Booking Calendar 10.15 - 11.8.2 - Editor+ Arbitrary Option Disclosure

The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor ro…

| Information Disclosure
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-105194 — Easy Digital Downloads < 3.7.1 - Subscriber+ Sensitive Information Disclosure via User Do…

The Easy Digital Downloads WordPress plugin before 3.7.1 does not restrict a block's order data to the current user, allowing users with subscriber-level access to view other customers' recent order…

| Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-105193 — Booking Calendar < 11.8 - Unauthenticated Booking Information Disclosure and Modification…

The Booking Calendar WordPress plugin before 11.8 does not generate its per-booking access hashes with sufficient entropy, deriving each from a low-entropy time-seeded value, which can allow unauthen…

| Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-104646 — Image Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Stored XSS via Gallery Short…

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not sanitise several gallery configuration values that can be overridden through its gallery shortcode before printing the…

| Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-104645 — Image Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Arbitrary Gallery Cloning, I…

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not properly verify authorization on several of its gallery and image management actions, checking ownership against a dif…

| Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-103692 — Frontend Dashboard 3.0.0 - 3.0.4 - Unauthenticated Privilege Escalation via Arbitrary Fun…

The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class…

| Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-103646 — Ultimate Multisite < 2.17.0 - Unauthenticated Authentication Bypass via 'email_address' P…

The Ultimate Multisite WordPress plugin before 2.17.0 does not require authentication before a logged-out checkout is linked to, and logged in as, an existing WordPress account matching the submitte…

| Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
Showing 20 of 15563 Results