Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-104803 — WPCOM Member <= 1.7.27 - Unauthenticated Authentication Bypass via 'uuid' and 'code' Para…

The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via the `uuid` and `code` parameters of the social-login callback handler reg…

wpcom_member | Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-104759 — WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenti…

The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Authentication Bypass via OIDC Nonce Replay in all versions up to, and including, 44.1 T…

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
4.3 MEDIUM
CVE-2026-104728 — AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Inf…

The AutomatorWP – No-Code Workflow Automation, Integration & Webhooks Plugin, now with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This …

Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.4 MEDIUM
CVE-2026-103478 — Premium Packages <= 7.2.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via '…

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkout[billing][phone] (and state / taxid / email)' parameter in all…

premium_packages_-_sell_digital_products_securely | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.4 MEDIUM
CVE-2026-102774 — SureDash <= 1.12.1 - Authenticated (Subscriber+) Stored DOM-Based Cross-Site Scripting vi…

The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Image 'alt' Attribute in Community Post Content in all versions up…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.4 MEDIUM
CVE-2026-102291 — Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.3.1 - Authenticated (Sub…

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.3.1 This is due to the plug…

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
4.7 MEDIUM
CVE-2026-101921 — WPForms <= 2.0.2.1 - Reflected Cross-Site Scripting via 'query_var' Smart Tag in iframe s…

The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'attacker-chosen key …

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-101920 — Molongui Authorship <= 5.2.12 - Unauthenticated Stored DOM-Based Cross-Site Scripting via…

The Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'comment (href attribute inside co…

molongui_authorship | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-100178 — WPAdverts <= 2.3.4 - Unauthenticated Stored Cross-Site Scripting via 'adverts_location' P…

The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'adverts_location' parameter in all versions up to, and including, 2.3.4 due to insufficie…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-100147 — FunnelKit <= 3.16.0.5 - Unauthenticated Stored Cross-Site Scripting via Order Fields (shi…

The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shipping_first_name' parameter in all versions up to, and including,…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.5 MEDIUM
CVE-2026-97348 — SiteOrigin Widgets Bundle <= 1.74.3 - Authenticated (Contributor+) Arbitrary File Read vi…

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.74.3 via the get_instance_css function. This makes it possible for auth…

siteorigin_widgets_bundle | Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-96840 — Post Grid Gutenberg Blocks <= 5.1.0 - Unauthenticated Stored Cross-Site Scripting via dis…

The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via display_name User Field in all versions up to, and including, 5.1.0 due to insufficient in…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.4 MEDIUM
CVE-2026-96574 — User Frontend <= 4.3.12 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wp…

The User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission plugin for WordPress is vulnerable to Stored Cross-Site Scripting v…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-96572 — WP Meteor Website Speed Optimization Addon <= 3.4.18 - Unauthenticated Stored Cross-Site …

The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.4.18 due to insufficie…

wp_meteor | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-96558 — Quiz and Survey Master (QSM) <= 11.2.6 - Unauthenticated Stored DOM-Based Cross-Site Scri…

The Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'qsm_hidden_questions' parameter in all versions up to…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-95684 — VikBooking Hotel Booking Engine & PMS <= 1.8.15 - Unauthenticated Stored Cross-Site Scrip…

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'attachments[name]' Parameter in all versions up to, and including, 1.8.15 due to insuf…

vikbooking_hotel_booking_engine_\&_pms | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-94538 — WP File Download <= 6.3.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrar…

The WP File Download plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.3.9. This is due to the plugin not properly verifying that a user is authorized…

wp_file_download | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.1 MEDIUM
CVE-2026-89100 — Payment Plugins for Stripe WooCommerce <= 4.0.17 - Reflected DOM-Based Cross-Site Scripti…

The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '#response' URL Fragment in all versions up to, and including, 4.0.17 due to insuff…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.4 MEDIUM
CVE-2026-6243 — Frontend Admin by DynamiApps <= 3.28.36 - Authenticated (Contributor+) Stored Cross-Site …

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kses bypass / mutation XSS in all versions up to, and including, 3.28.36. This is due to the 'ge…

frontend_admin | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.1 MEDIUM
CVE-2026-5725 — Favicon Rotator <= 1.2.11 - Reflected Cross-Site Scripting via 'fvrt_' prefix

The Favicon Rotator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fvrt_' prefixed request parameters in all versions up to, and including, 1.2.11 due to insufficient i…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Showing 20 of 14171 Results