Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54243
Total
4300
Critical
16125
High
15819
Medium
CVE ID Severity Score Description Published
CVE-2026-97318 MEDIUM 6.1 The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting … Oct 02, 2026
CVE-2026-97317 MEDIUM 5.3 The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public … Oct 02, 2026
CVE-2026-94298 MEDIUM 6.2 The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in … Oct 02, 2026
CVE-2026-92820 HIGH 8.1 The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the … Oct 02, 2026
CVE-2026-92174 HIGH 7.5 The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter … Oct 02, 2026
CVE-2026-91828 HIGH 7.5 The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that … Oct 02, 2026
CVE-2026-91023 LOW 3.1 The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing … Oct 02, 2026
CVE-2026-91022 MEDIUM 6.8 The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with … Oct 02, 2026
CVE-2026-90988 MEDIUM 5.3 The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to … Oct 02, 2026
CVE-2026-90438 HIGH 7.2 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) … Oct 02, 2026
CVE-2026-85016 MEDIUM 6.8 The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared … Oct 02, 2026
CVE-2026-85004 MEDIUM 4.3 The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated … Oct 02, 2026
CVE-2026-84925 MEDIUM 6.1 The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in all versions … Oct 02, 2026
CVE-2026-81740 MEDIUM 5.3 The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has … Oct 02, 2026
CVE-2026-78471 MEDIUM 5.4 The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15.1 due to … Oct 02, 2026
CVE-2026-15897 HIGH 8.8 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. … Oct 02, 2026
CVE-2026-15896 CRITICAL 9.1 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 … Oct 02, 2026
CVE-2026-13718 MEDIUM 6.8 The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager … Oct 02, 2026
CVE-2026-19660 CRITICAL 9.8 The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the … Oct 02, 2026
CVE-2026-10026 HIGH 7.2 The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 7.6.12. This is due to insufficient … Oct 02, 2026
CVE-2026-93367 HIGH 7.2 The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 … Oct 02, 2026
CVE-2026-14378 CRITICAL 9.8 The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This … Oct 02, 2026
CVE-2026-104123 HIGH 7.3 A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation … Oct 02, 2026
CVE-2026-104120 HIGH 7.3 A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the … Oct 02, 2026
CVE-2026-21140 UNKNOWN — Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications. Oct 02, 2026