Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-18432 — Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_i…

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logi…

Remote | Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
5.4 MEDIUM
CVE-2026-18385 — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Res…

The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in al…

Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
8.8 HIGH
CVE-2026-17123 — Royal Addons for Elementor <= 1.7.1064 - Authenticated (Contributor+) Server-Side Request…

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget…

Remote | Server-Side Request Forgery
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
4.3 MEDIUM
CVE-2026-16779 — Kubio AI Page Builder <= 2.8.5 - Missing Authorization to Authenticated (Contributor+) Fr…

The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.5. This is due to the plugin not properly verifying that a user is autho…

Remote | Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
8.8 HIGH
CVE-2026-16099 — Podlove Podcast Publisher <= 4.5.3 - Authenticated (Contributor+) PHP Object Injection to…

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and includ…

Remote | Path Traversal
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
9.8 CRITICAL
CVE-2026-16098 — ProSolution WP Client <= 2.0.10 - Unauthenticated Arbitrary File Upload via Content-Dispo…

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing val…

Remote | Authentication
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-16079 — Fullscreen Galleria <= 1.6.12 - Authenticated (Contributor+) SQL Injection via 'href' Att…

The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content in all versions up to, and including, 1.6.12 due to insufficient escaping on t…

Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-15963 — Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) SQL Injection via '…

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz Option in all versions up to, and including, 11.2.…

Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.4 MEDIUM
CVE-2026-15726 — Serious Slider <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 't…

The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in all versions up to, and including, 1.4.0 due to insufficient input sanitization…

Remote | Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
4.9 MEDIUM
CVE-2026-15602 — NEX-Forms <= 9.2.4 - Authenticated (Admin+) SQL Injection via 'additional_params' Paramet…

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.2.4 due t…

Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
5.3 MEDIUM
CVE-2026-15441 — Product Table & List Builder For WooCommerce <= 5.6.0 - Unauthenticated CSS Injection via…

The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and including, 5.6.0 via the 'laptop_scroll_offset' shortcode attribute exposed through the unauthenti…

Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.4 MEDIUM
CVE-2026-15066 — Loco Translate <= 2.8.7 - Authenticated (Translator+) Stored Cross-Site Scripting via PO …

The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and including, 2.8.7 due to insufficient input sanitization …

Remote | Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.1 MEDIUM
CVE-2026-15009 — Advanced File Manager <= 5.4.12 - Reflected Cross-Site Scripting via postMessage 'soundFi…

The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'soundFile' parameter in all ve…

Remote | Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
7.2 HIGH
CVE-2026-15002 — Autopay <= 5.0.0 - Unauthenticated Stored Cross-Site Scripting via 'bm_woocommerce_css_ed…

The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 via the 'bm_woocommerce_css_editor_content' POST pa…

Remote | Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
9.1 CRITICAL
CVE-2026-14524 — ProSolution WP Client <= 2.0.8 - Unauthenticated Arbitrary File Deletion via 'newfilename…

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and in…

Remote | Path Traversal
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
8.8 HIGH
CVE-2026-14498 — Query Wrangler <= 1.5.57 - Authenticated (Subscriber+) Remote Code Execution via 'options…

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability ch…

Remote | Authentication
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-13358 — Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.10 -…

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.10 v…

Remote | Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
4.3 MEDIUM
CVE-2026-13167 — Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <=…

The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.2. This…

Remote | Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
4.3 MEDIUM
CVE-2026-12905 — Online Scheduling and Appointment Booking System – Bookly <= 27.7 - Authenticated (Staff+…

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appoint…

Remote | Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
4.4 MEDIUM
CVE-2026-12477 — Gravity Booster <= 5.26 - Authenticated (Editor+) Stored Cross-Site Scripting via 'styler…

The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.26 due to insuffi…

Remote | Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
Showing 20 of 11267 Results