Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-62043 — WordPress Contact Form 7 – Dynamic Text Extension plugin <= 5.0.7 - Sensitive Data Exposu…

Unauthenticated Sensitive Data Exposure in Contact Form 7 – Dynamic Text Extension <= 5.0.7 versions.

contact_form_7_-_dynamic_text_extension | Remote | Information Disclosure
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.3 HIGH
CVE-2026-62038 — WordPress eRoom plugin <= 1.7.1 - Broken Authentication vulnerability

Unauthenticated Broken Authentication in eRoom <= 1.7.1 versions.

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-62037 — WordPress Document Embedder plugin <= 2.4.0 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Document Embedder <= 2.4.0 versions.

document_embedder | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.3 MEDIUM
CVE-2026-62035 — WordPress AWS S3 for WordPress Plugin – Upcasted plugin <= 3.1.0 - Broken Access Control …

Subscriber Broken Access Control in AWS S3 for WordPress Plugin – Upcasted <= 3.1.0 versions.

Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-62034 — WordPress Before After Image Comparison – Image comparison for WP plugin <= 1.1.21 - Cros…

Unauthenticated Cross Site Scripting (XSS) in Before After Image Comparison – Image comparison for WP <= 1.1.21 versions.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.6 HIGH
CVE-2026-62033 — WordPress uListing plugin <= 2.2.0 - Settings Change vulnerability

Subscriber Settings Change in uListing <= 2.2.0 versions.

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-62032 — WordPress DirectoryPress plugin <= 3.6.27 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in DirectoryPress <= 3.6.27 versions.

directorypress | Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.3 CRITICAL
CVE-2026-62031 — WordPress uListing plugin <= 2.2.0 - SQL Injection vulnerability

Unauthenticated SQL Injection in uListing <= 2.2.0 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-62030 — WordPress StreamCast plugin <= 2.4.5 - Server Side Request Forgery (SSRF) vulnerability

Unauthenticated Server Side Request Forgery (SSRF) in StreamCast <= 2.4.5 versions.

Remote | Server-Side Request Forgery
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-62027 — WordPress Team Section Block plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Team Section Block <= 2.0.4 versions.

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.0 CRITICAL
CVE-2026-62025 — WordPress Tailored Tools plugin <= 3.0.3 - Arbitrary File Upload vulnerability

Unauthenticated Arbitrary File Upload in Tailored Tools <= 3.0.3 versions.

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.9 CRITICAL
CVE-2026-62024 — WordPress CodeBard Help Desk plugin <= 1.1.2 - Arbitrary File Upload vulnerability

Subscriber Arbitrary File Upload in CodeBard Help Desk <= 1.1.2 versions.

codebard_help_desk | Remote | Misconfiguration
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-62022 — WordPress Tonda Membership plugin <= 1.0.1 - Privilege Escalation vulnerability

Unauthenticated Privilege Escalation in Tonda Membership <= 1.0.1 versions.

Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.8 HIGH
CVE-2026-62021 — WordPress Angio theme <= 1.1.1 - PHP Object Injection vulnerability

Subscriber PHP Object Injection in Angio <= 1.1.1 versions.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-62020 — WordPress TouchUp theme < 1.4 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in TouchUp < 1.4 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-57742 — WordPress Kids Planet theme <= 2.2.14.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group Kids Planet allows Reflected XSS. This issue affects Kids Planet: from n/a throug…

kids_planet | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-48194 — WordPress DukaMarket theme <= 1.3.0 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in DukaMarket <= 1.3.0 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-48193 — WordPress Uminex theme <= 1.0.9 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in Uminex <= 1.0.9 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.6 HIGH
CVE-2026-45440 — WordPress WP Ultimate CSV Importer plugin <= 9.2 - SQL Injection vulnerability

Administrator SQL Injection in WP Ultimate CSV Importer <= 9.2 versions.

wp_ultimate_csv_importer | Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-42777 — WordPress Aalto theme <= 1.8 - Local File Inclusion vulnerability

Unauthenticated Local File Inclusion in Aalto <= 1.8 versions.

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Showing 20 of 14125 Results