Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.4 HIGH
CVE-2026-50605 — Privilege Escalation Vulnerability in NitroSense and PredatorSense Software

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insufficient access controls within a privileged service may allow an authenticated…

| Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
3.7 LOW
CVE-2026-91017 — Robokassa payment gateway for Woocommerce < 1.8.9 - Unauthenticated Payment Bypass via Fo…

The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled…

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.3 MEDIUM
CVE-2026-90982 — @fastify/static vulnerable to route guard bypass via path case-folding

@fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4, on a case-insensitive filesystem such as Windows or the default macOS volume,…

fastify-static | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.6 HIGH
CVE-2026-87963 — Yo 1.1 - 1.3.1 - Unauthenticated SQL Injection via username Parameter

The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escap…

Remote | Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.8 HIGH
CVE-2026-86801 — To Do List Member 1.4 - 1.6 - Unauthenticated Stored XSS, File Listing and Deletion via U…

The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no authentication, capability or nonce check of any kind, a…

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.7 MEDIUM
CVE-2026-44940 — Service token exposure and potential privilege escalation in SUSE Observability

The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal acces…

Remote | Misconfiguration
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-91019 — Event Booking Manager for WooCommerce < 5.6.0 - Contributor+ Payment Gateway Credential D…

The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and abov…

| Information Disclosure
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-91016 — Motors < 1.4.121 - Unauthenticated Draft/Private Listing Disclosure

The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any …

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-91015 — Master Addons for Elementor < 3.1.9 - Unauthenticated Popup Deactivation via jltma_popup_…

The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on a nonce that is pu…

master_addons_for_elementor | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-91014 — Realtyna Organic IDX plugin + WPL Real Estate < 5.4.2 - Reflected XSS via Location Select…

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated a…

| Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-91011 — EWWW Image Optimizer < 8.7.7 - Author+ Stored XSS via Image Class Attribute Backreference…

The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to…

| Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-91010 — Invisible Anti-Spam & CAPTCHA < 5.1.1 - Subscriber+ Arbitrary Form Submission Deletion

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion AJAX action, and only tests that a…

| Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-91009 — Active Products Tables for WooCommerce < 2.1.3 - Subscriber+ Arbitrary Post Title Modific…

The Active Woot Products Tables for WooCommerce. 100% FREE  WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, su…

| Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-91008 — Event Booking Manager for WooCommerce < 5.3.8 - Unauthenticated Attendee PII Disclosure v…

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated a…

| Information Disclosure
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-90923 — Autopay < 5.0.1 - Unauthenticated Cross-Customer Order Payment Parameter Disclosure and D…

The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other …

| Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-90922 — Paid Member Subscriptions < 3.0.9 - Unauthenticated Membership Payment Bypass via PayPal …

The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing…

| Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-88904 — PuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Priv…

The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authen…

| Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-88795 — wpShopGermany IT-RECHT KANZLEI < 2.4 - Unauthenticated RCE via Predictable API Token

The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating it as a side effect o…

| Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-88792 — Dictionary <= 1.0 - Unauthenticated Stored XSS via Direct Dictionary Update

The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to store arbitrar…

| Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-87836 — Comments Import & Export 2.1.11 - 2.5.3 - Author+ Comment PII Disclosure via Export

The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export to content owned by the requesting user, allow…

| Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Showing 20 of 14837 Results