Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-18443 — Smart Manager <= 8.97.0 - Authenticated (Subscriber+) SQL Injection to Privilege Escalati…

The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and …

Remote | Injection
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.4 MEDIUM
CVE-2026-15795 — Responsive Plus <= 3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via S…

The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.5.3 due to…

Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.3 MEDIUM
CVE-2026-11601 — WPCafe <= 3.0.19 - Missing Authorization to Unauthenticated Arbitrary Email Notification …

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.19. This is due to the p…

wpcafe | Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.1 MEDIUM
CVE-2026-104313 — WPC Estimated Delivery Date for WooCommerce <= 4.0.1 - Reflected Cross-Site Scripting via…

The WPC Estimated Delivery Date for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'rule_data' parameter in all versions up to, and including, 4.0.1 due to i…

Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.4 MEDIUM
CVE-2026-103519 — WP Ultimate Review <= 2.4.3 - Authenticated (Subscriber+) Arbitrary Shortcode Execution v…

The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an ac…

wp_ultimate_review | Remote | Injection
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.4 MEDIUM
CVE-2026-103421 — WPMobile.App <= 11.84 - Unauthenticated Stored Cross-Site Scripting via '/android_json/se…

The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment after /android_json/search/)' parameter in all vers…

Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.5 MEDIUM
CVE-2026-100157 — WP Ultimate Review <= 2.4.3 - Unauthenticated Arbitrary Shortcode Execution via 'xs_reviw…

The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an ac…

wp_ultimate_review | Remote | Injection
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.4 MEDIUM
CVE-2026-97344 — Wp Social Login and Register Social Counter <= 3.2.1 - Authenticated (Subscriber+) Stored…

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User Meta Write in all versions up to, and inc…

wp_social_login_and_register_social_counter | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.2 HIGH
CVE-2026-97341 — Visitor Traffic Real Time Statistics <= 8.16 - Unauthenticated Stored DOM-Based Cross-Sit…

The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP Header in all versions up to, and including, 8.16 due to insu…

visitor_traffic_real_time_statistics | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.5 HIGH
CVE-2026-97337 — Simple Membership <= 4.8.3 - Missing Authorization to Unauthenticated Account Takeover an…

The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation an…

simple_membership | Remote | Authentication
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
3.7 LOW
CVE-2026-96962 — Pie Register < 3.8.4.14 - Unauthenticated User Email Disclosure via Invitation Code

The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid invitation code to obtain the username and…

Remote | Information Disclosure
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.2 HIGH
CVE-2026-96650 — Strong Testimonials <= 3.3.11 - Unauthenticated Stored Cross-Site Scripting via 'platform…

The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due to insufficient input…

strong_testimonials | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.2 HIGH
CVE-2026-96575 — Transliterator <= 2.5.8 - Unauthenticated Stored Cross-Site Scripting via Comment Content…

The Transliterator – Multilingual and Multi-script Text Conversion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Predictable {rstr_keep} Placeholder in all…

Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.2 HIGH
CVE-2026-96564 — SEOPress <= 10.2 - Unauthenticated Stored Cross-Site Scripting via Author Display Name

The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Author Display Name in all versions up to, and including, 10.2 due to insufficient inp…

Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.8 MEDIUM
CVE-2026-94239 — Loco Translate < 2.8.9 - Translator+ Stored XSS via Bundle Configuration

The Loco Translate WordPress plugin before 2.8.9 does not sanitise and escape some bundle configuration values before outputting them back in an admin page, allowing users with the translator capabil…

loco_translate | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.8 MEDIUM
CVE-2026-94238 — Loco Translate < 2.8.9 - Translator+ Limited File Read via 'path' Parameter

The Loco Translate WordPress plugin before 2.8.9 does not restrict which file paths its translation file routes will read, allowing users granted the Loco Translate WordPress plugin before 2.8.9's tr…

loco_translate | Remote | Path Traversal
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.2 HIGH
CVE-2026-93430 — GD Rating System <= 3.7.1 - Unauthenticated Stored Cross-Site Scripting via 'title' and '…

The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title' and 'url' Render Args in gdrts_live_handler AJAX in all versions up to, and including, 3.7.1 due to …

gd_rating_system | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.3 MEDIUM
CVE-2026-92923 — Unlimited Elements For Elementor 1.5.142 - 2.0.20 - Subscriber+ SQLi via get_addon_output…

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users with a role as low as subscriber to per…

Remote | Injection
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.3 MEDIUM
CVE-2026-92437 — Mailchimp for WooCommerce < 6.3 - Unauthenticated Abandoned Cart Modification and Deletion

The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-s…

mailchimp_for_woocommerce | Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
4.3 MEDIUM
CVE-2026-91108 — Alt Text AI <= 1.10.41 - Missing Authorization to Authenticated (Subscriber+) Arbitrary P…

The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.10.41. This is due…

Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
Showing 20 of 14777 Results