Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-87759 — Add User Autocomplete < 1.2 - Subscriber+ Privilege Escalation

The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any…

Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.8 MEDIUM
CVE-2026-86790 — WP Highlight Box <= 1.0 - Contributor+ Stored XSS via highlight-box Shortcode

The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contribu…

Remote | Cross-Site Scripting
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
9.8 CRITICAL
CVE-2026-85681 — WP Component <= 2.2.4 - Unauthenticated Privilege Escalation via Arbitrary Blog Option Up…

The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and t…

Remote | Authentication
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
9.8 CRITICAL
CVE-2026-84171 — WP Images Upload on Piclect <= 1.0 - Unauthenticated Arbitrary File Upload

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated atta…

Remote | Authentication
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
8.1 HIGH
CVE-2026-84099 — IDB Ecommerce (wpStoreCart 5) <= 5.0.7 - Unauthenticated PHP Object Injection via bundled…

The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, all…

Remote | Injection
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
8.6 HIGH
CVE-2026-84047 — Album Cover Finder <= 0.7.0 - Unauthenticated SQLi via and_action

The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

Remote | Injection
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
2.2 LOW
CVE-2026-84025 — BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authentica…

The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own pr…

Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
4.3 MEDIUM
CVE-2026-84024 — BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Meta Field…

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration by tricking a logged-in administr…

Remote | Cross-Site Request Forgery
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.5 MEDIUM
CVE-2026-84023 — BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Taxonomy T…

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in …

Remote | Cross-Site Request Forgery
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.8 MEDIUM
CVE-2026-83532 — Custom Menu Wizard <= 3.3.1 - Contributor+ Stored XSS via Shortcode Attributes

The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with contributor-level access an…

Remote | Cross-Site Scripting
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
2.7 LOW
CVE-2026-82851 — Masteriyo LMS 1.14.0 - 3.4.0 - Instructor+ Arbitrary Post Disclosure via IDOR

The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve t…

Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.8 MEDIUM
CVE-2026-82847 — Masteriyo LMS < 3.4.1 - Instructor+ Stored XSS via Course Highlights

The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perfo…

Remote | Cross-Site Scripting
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
9.9 CRITICAL
CVE-2026-82845 — Masteriyo LMS < 3.4.1 - Subscriber+ PHP Object Injection

The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to injec…

Remote | Injection
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
8.8 HIGH
CVE-2026-81742 — BE REST Endpoints <= 1.0.0 - Unauthenticated Stored XSS and Widget Manipulation

The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it sto…

Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
7.1 HIGH
CVE-2026-81429 — Export & Import WPBakery Page Builder <= 1.0.2 - Stored XSS via CSRF

The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and e…

Remote | Cross-Site Request Forgery
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
9.8 CRITICAL
CVE-2026-81402 — DS Ad Rotator <= 0.8 - Unauthenticated Arbitrary File Upload

The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to up…

Remote | Authentication
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
7.2 HIGH
CVE-2026-81090 — Gpx2Graphics <= 0.3 - Arbitrary File Upload via CSRF

The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrato…

Remote | Cross-Site Request Forgery
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
8.6 HIGH
CVE-2026-80494 — Yogeta WP Cloud <= 1.0 - Unauthenticated Arbitrary File Download

The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowin…

Remote | Path Traversal
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
8.6 HIGH
CVE-2026-80491 — SAMO Forms <= 1.0.0 - Unauthenticated SQLi

The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to…

Remote | Injection
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.3 MEDIUM
CVE-2026-78152 — SureRank 1.6.2 - 1.10.0 - Unauthenticated Author Email Disclosure via Person Schema

The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated vi…

Remote | Information Disclosure
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
Showing 20 of 13192 Results