Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54999
Total
4345
Critical
16386
High
16069
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-86783 | MEDIUM | 5.3 | The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the … | Sep 23, 2026 |
| CVE-2026-86608 | HIGH | 8.2 | The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what … | Sep 23, 2026 |
| CVE-2026-86603 | MEDIUM | 4.3 | The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such … | Sep 23, 2026 |
| CVE-2026-86602 | MEDIUM | 4.3 | The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such … | Sep 23, 2026 |
| CVE-2026-85006 | MEDIUM | 6.8 | The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an … | Sep 23, 2026 |
| CVE-2026-84743 | LOW | 3.8 | The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with … | Sep 23, 2026 |
| CVE-2026-84742 | LOW | 2.7 | The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, … | Sep 23, 2026 |
| CVE-2026-84741 | MEDIUM | 5.3 | The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST … | Sep 23, 2026 |
| CVE-2026-84168 | MEDIUM | 5.3 | The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthenticated attacker to reach the standard login page … | Sep 23, 2026 |
| CVE-2026-84150 | MEDIUM | 5.4 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not verify that the target user of a REST route matches … | Sep 23, 2026 |
| CVE-2026-84098 | MEDIUM | 6.5 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated … | Sep 23, 2026 |
| CVE-2026-84046 | MEDIUM | 5.0 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validate a user-supplied URL before fetching it server-side, allowing users … | Sep 23, 2026 |
| CVE-2026-84027 | MEDIUM | 4.3 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, … | Sep 23, 2026 |
| CVE-2026-84026 | MEDIUM | 5.3 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restrict access to a REST endpoint that returns user records, … | Sep 23, 2026 |
| CVE-2026-83555 | MEDIUM | 5.3 | The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token before changing a subscriber's subscription status, allowing unauthenticated users … | Sep 23, 2026 |
| CVE-2026-82843 | CRITICAL | 9.0 | The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the … | Sep 23, 2026 |
| CVE-2026-81339 | MEDIUM | 4.3 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when returning a quiz attempt result, allowing any authenticated … | Sep 23, 2026 |
| CVE-2026-81338 | MEDIUM | 4.6 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in user-submitted content before storing it and rendering it … | Sep 23, 2026 |
| CVE-2026-80342 | MEDIUM | 6.5 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the … | Sep 23, 2026 |
| CVE-2026-77766 | MEDIUM | 4.3 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting … | Sep 23, 2026 |
| CVE-2026-77765 | MEDIUM | 5.3 | The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant's configured fixed price before building the gateway … | Sep 23, 2026 |
| CVE-2026-75799 | CRITICAL | 9.0 | The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated … | Sep 23, 2026 |
| CVE-2026-19438 | HIGH | 7.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Mint Workbench I. This issue affects Mint Workbench I: through 5876. | Sep 23, 2026 |
| CVE-2026-18365 | MEDIUM | 4.3 | The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on one of its AJAX actions, allowing users with a subscriber-level … | Sep 23, 2026 |
| CVE-2026-18364 | MEDIUM | 4.3 | The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on several of its AJAX actions, allowing users with a subscriber-level … | Sep 23, 2026 |