Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55204
Total
4355
Critical
16406
High
16086
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-87979 | MEDIUM | 5.3 | The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch of its payment webhook, allowing unauthenticated attackers … | Sep 23, 2026 |
| CVE-2026-87074 | LOW | 3.7 | The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient … | Sep 23, 2026 |
| CVE-2026-87069 | LOW | 3.1 | The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction … | Sep 23, 2026 |
| CVE-2026-86842 | MEDIUM | 6.8 | The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flipbook management actions, allowing users with Author-level access … | Sep 23, 2026 |
| CVE-2026-86785 | MEDIUM | 5.3 | The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its REST API endpoints, allowing unauthenticated users to … | Sep 23, 2026 |
| CVE-2026-86783 | MEDIUM | 5.3 | The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the … | Sep 23, 2026 |
| CVE-2026-86608 | HIGH | 8.2 | The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what … | Sep 23, 2026 |
| CVE-2026-86603 | MEDIUM | 4.3 | The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such … | Sep 23, 2026 |
| CVE-2026-86602 | MEDIUM | 4.3 | The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such … | Sep 23, 2026 |
| CVE-2026-85006 | MEDIUM | 6.8 | The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an … | Sep 23, 2026 |
| CVE-2026-84743 | LOW | 3.8 | The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with … | Sep 23, 2026 |
| CVE-2026-84742 | LOW | 2.7 | The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, … | Sep 23, 2026 |
| CVE-2026-84741 | MEDIUM | 5.3 | The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST … | Sep 23, 2026 |
| CVE-2026-84168 | MEDIUM | 5.3 | The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthenticated attacker to reach the standard login page … | Sep 23, 2026 |
| CVE-2026-84150 | MEDIUM | 5.4 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not verify that the target user of a REST route matches … | Sep 23, 2026 |
| CVE-2026-84098 | MEDIUM | 6.5 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated … | Sep 23, 2026 |
| CVE-2026-84046 | MEDIUM | 5.0 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validate a user-supplied URL before fetching it server-side, allowing users … | Sep 23, 2026 |
| CVE-2026-84027 | MEDIUM | 4.3 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, … | Sep 23, 2026 |
| CVE-2026-84026 | MEDIUM | 5.3 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restrict access to a REST endpoint that returns user records, … | Sep 23, 2026 |
| CVE-2026-83555 | MEDIUM | 5.3 | The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token before changing a subscriber's subscription status, allowing unauthenticated users … | Sep 23, 2026 |
| CVE-2026-82843 | CRITICAL | 9.0 | The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the … | Sep 23, 2026 |
| CVE-2026-81339 | MEDIUM | 4.3 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when returning a quiz attempt result, allowing any authenticated … | Sep 23, 2026 |
| CVE-2026-81338 | MEDIUM | 4.6 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in user-submitted content before storing it and rendering it … | Sep 23, 2026 |
| CVE-2026-80342 | MEDIUM | 6.5 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the … | Sep 23, 2026 |
| CVE-2026-77766 | MEDIUM | 4.3 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting … | Sep 23, 2026 |