Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-97318 | MEDIUM | 6.1 | The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting … | Oct 02, 2026 |
| CVE-2026-97317 | MEDIUM | 5.3 | The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public … | Oct 02, 2026 |
| CVE-2026-94298 | MEDIUM | 6.2 | The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in … | Oct 02, 2026 |
| CVE-2026-92820 | HIGH | 8.1 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the … | Oct 02, 2026 |
| CVE-2026-92174 | HIGH | 7.5 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter … | Oct 02, 2026 |
| CVE-2026-91828 | HIGH | 7.5 | The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that … | Oct 02, 2026 |
| CVE-2026-91023 | LOW | 3.1 | The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing … | Oct 02, 2026 |
| CVE-2026-91022 | MEDIUM | 6.8 | The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with … | Oct 02, 2026 |
| CVE-2026-90988 | MEDIUM | 5.3 | The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to … | Oct 02, 2026 |
| CVE-2026-90438 | HIGH | 7.2 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) … | Oct 02, 2026 |
| CVE-2026-85016 | MEDIUM | 6.8 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared … | Oct 02, 2026 |
| CVE-2026-85004 | MEDIUM | 4.3 | The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated … | Oct 02, 2026 |
| CVE-2026-84925 | MEDIUM | 6.1 | The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in all versions … | Oct 02, 2026 |
| CVE-2026-81740 | MEDIUM | 5.3 | The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has … | Oct 02, 2026 |
| CVE-2026-78471 | MEDIUM | 5.4 | The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15.1 due to … | Oct 02, 2026 |
| CVE-2026-15897 | HIGH | 8.8 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. … | Oct 02, 2026 |
| CVE-2026-15896 | CRITICAL | 9.1 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 … | Oct 02, 2026 |
| CVE-2026-13718 | MEDIUM | 6.8 | The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager … | Oct 02, 2026 |
| CVE-2026-19660 | CRITICAL | 9.8 | The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the … | Oct 02, 2026 |
| CVE-2026-10026 | HIGH | 7.2 | The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 7.6.12. This is due to insufficient … | Oct 02, 2026 |
| CVE-2026-93367 | HIGH | 7.2 | The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 … | Oct 02, 2026 |
| CVE-2026-14378 | CRITICAL | 9.8 | The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This … | Oct 02, 2026 |
| CVE-2026-104123 | HIGH | 7.3 | A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation … | Oct 02, 2026 |
| CVE-2026-104120 | HIGH | 7.3 | A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the … | Oct 02, 2026 |
| CVE-2026-21140 | UNKNOWN | — | Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications. | Oct 02, 2026 |