Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-86798 — HootBoard <= 3.1.4 - Unauthenticated Stored XSS via Board Configuration REST Endpoint

The HootBoard WordPress plugin through 3.1.4 does not perform any authorisation check on some of its REST endpoints, and does not escape the values stored through them before outputting them in a pu…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-86717 — Insurify <= 1.0 - Unauthenticated Arbitrary Option Deletion via removeimg_popup

The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to delete arbitrary WordPress options, which can tak…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-86706 — Quick quotes <= 1.0.0 - Unauthenticated Integer-Value Option Update

The Quick quotes WordPress plugin through 1.0.0 does not perform any capability or nonce check on one of its AJAX actions and lets the caller choose which option is written, allowing unauthenticated…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-85126 — Crowdfundly <= 2.2.2 - Crowdfundly Manager+ Privilege Escalation

The Crowdfundly WordPress plugin through 2.2.2 does not have capability checks on some of its AJAX actions, allowing users holding one of its own low privileged roles to grant themselves the administ…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-85121 — Insurify <= 1.0 - Unauthenticated Arbitrary Option Creation and Overwrite via saveemailte…

The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to create and overwrite arbitrary WordPress options …

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-85118 — AI Content Generator Marketing <= 1.0.0 - Unauthenticated Privilege Escalation via Arbitr…

The AI Content Generator Marketing WordPress plugin through 1.0.0 does not enforce a nonce or capability check on some of its AJAX actions, allowing unauthenticated users to update and delete arbitra…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-84737 — Freeton WP <= 1.0.0 - Unauthenticated Account Takeover via 'secod' Parameter

The Freeton WP WordPress plugin through 1.0.0 does not correctly validate the activation code when authenticating a user, allowing unauthenticated attackers to log in as any user whose email address …

| Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-84734 — Mindstien Quick Login <= 1.0 - Unauthenticated Administrator Account Takeover via 'mql_pa…

The Mindstien Quick Login WordPress plugin through 1.0 does not correctly validate a value supplied in the request against the visitor's own session before authenticating them, allowing unauthenticat…

| Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-84261 — click5 CRM add-on to Contact Form 7 <= 1.0.4 - Unauthenticated Stored XSS via post_notifi…

The click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, l…

| Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-84260 — click5 CRM add-on to Gravity Forms <= 1.0.3 - Unauthenticated Stored XSS via post_notific…

The click5 CRM add-on to Gravity Forms WordPress plugin through 1.0.3 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, le…

| Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-84259 — click5 CRM add-on to WPForms <= 1.0.3 - Unauthenticated Stored XSS via post_notifications

The click5 CRM add-on to WPForms WordPress plugin through 1.0.3 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading …

| Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-84258 — click5 CRM add-on to Ninja Forms <= 1.0.1 - Unauthenticated Stored XSS via post_notificat…

The click5 CRM add-on to Ninja Forms WordPress plugin through 1.0.1 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, lead…

| Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-84254 — click5 CRM add-on to Contact Form 7 <= 1.0.4 - Unauthenticated Arbitrary Options Update

The click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-84253 — click5 CRM add-on to Gravity Forms <= 1.0.3 - Unauthenticated Arbitrary Options Update

The click5 CRM add-on to Gravity Forms WordPress plugin through 1.0.3 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be …

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-84252 — click5 CRM add-on to WPForms <= 1.0.3 - Unauthenticated Arbitrary Options Update

The click5 CRM add-on to WPForms WordPress plugin through 1.0.3 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be update…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-84251 — click5 CRM add-on to Ninja Forms <= 1.0.1 - Unauthenticated Arbitrary Options Update

The click5 CRM add-on to Ninja Forms WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be up…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-81649 — Fundiin <= 3.4.0 - Unauthenticated Payment Gateway Settings Update and Credential Disclos…

The Fundiin cho WooCommerce WordPress plugin through 3.4.0 does not have proper authorisation on several of its REST API routes, relying instead on a credential that is identical on every installatio…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-81420 — Tcard WP <= 1.8.0 - Unauthenticated SQLi via group_id Parameter

The Tcard WP WordPress plugin through 1.8.0 does not sanitise and escape a parameter before using it in a SQL statement in one of its unauthenticated AJAX actions, allowing unauthenticated users to p…

| Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-81156 — Robo Gallery < 5.2.6 - Contributor+ Stored XSS via Gallery Settings

The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape some of its gallery settings before outputting them on the gallery edit screen, allowing users with the Contributor role a…

| Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-81155 — Robo Gallery < 5.2.6 - Author+ Stored XSS via Gallery Search Label

The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape a gallery setting before outputting it on a frontend page, allowing users with the Author role and above to perform Stored…

| Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
Showing 20 of 14141 Results