Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54367
Total
4306
Critical
16164
High
15850
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-96525 | LOW | 2.7 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check on its workflow create, update and delete … | Sep 26, 2026 |
| CVE-2026-96524 | HIGH | 8.8 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an … | Sep 26, 2026 |
| CVE-2026-92411 | MEDIUM | 6.8 | The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied recipe block data before rendering it … | Sep 26, 2026 |
| CVE-2026-89237 | MEDIUM | 6.8 | The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers in a SQL query, allowing unauthenticated attackers … | Sep 26, 2026 |
| CVE-2026-85081 | HIGH | 7.5 | The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin … | Sep 26, 2026 |
| CVE-2026-84097 | MEDIUM | 6.5 | The wp-review-slider-pro WordPress plugin before 12.7.12 does not sanitize a value stored through one of its AJAX handlers, which lacks a capability check, before using … | Sep 26, 2026 |
| CVE-2026-84096 | HIGH | 8.0 | The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the AJAX handler that saves its review submission forms, and the nonce … | Sep 26, 2026 |
| CVE-2026-84095 | HIGH | 8.0 | The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers, and the nonce protecting it is generated … | Sep 26, 2026 |
| CVE-2026-19708 | MEDIUM | 5.9 | The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under … | Sep 26, 2026 |
| CVE-2026-18143 | CRITICAL | 9.8 | The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the … | Sep 26, 2026 |
| CVE-2026-16591 | HIGH | 7.2 | The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category and location fields before outputting them in page … | Sep 26, 2026 |
| CVE-2026-11871 | MEDIUM | 5.3 | The Team Members WordPress plugin through 9.2 does not perform any authorization or visibility check in an unauthenticated AJAX action that returns full team member … | Sep 26, 2026 |
| CVE-2026-15273 | MEDIUM | 6.4 | The Automatic.css plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI in all version 4.0.0 due to insufficient input sanitization and output escaping. … | Sep 26, 2026 |
| CVE-2026-100599 | HIGH | 8.8 | OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied audio command … | Sep 26, 2026 |
| CVE-2026-100598 | HIGH | 7.1 | OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versions, a reaction intended to resolve a structured approval request could instead … | Sep 26, 2026 |
| CVE-2026-100597 | HIGH | 7.8 | OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remove, mkdir, and … | Sep 26, 2026 |
| CVE-2026-100596 | HIGH | 8.8 | OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary … | Sep 26, 2026 |
| CVE-2026-100595 | MEDIUM | 6.5 | OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the diagnostics export command that allows non-owner channel senders to access owner-only host diagnostic bundles. … | Sep 26, 2026 |
| CVE-2026-100594 | MEDIUM | 6.5 | OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that allows non-owner senders to request and receive owner-only trajectory bundles. Attackers … | Sep 26, 2026 |
| CVE-2026-100593 | MEDIUM | 5.4 | OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent `/activation` policy changes in group channels. An authorized non-owner channel … | Sep 26, 2026 |
| CVE-2026-100592 | MEDIUM | 6.3 | OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mutations omit owner permission checks. An authorized … | Sep 26, 2026 |
| CVE-2026-100591 | MEDIUM | 6.3 | OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations could omit owner checks. An authorized non-owner external-channel sender … | Sep 26, 2026 |
| CVE-2026-100590 | MEDIUM | 4.3 | OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner external-channel senders to persist Gateway voice configuration. Attackers with … | Sep 26, 2026 |
| CVE-2026-100589 | HIGH | 8.3 | OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false … | Sep 26, 2026 |
| CVE-2026-100588 | HIGH | 8.3 | OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although … | Sep 26, 2026 |