Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55204
Total
4355
Critical
16406
High
16086
Medium
CVE ID Severity Score Description Published
CVE-2026-87979 MEDIUM 5.3 The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch of its payment webhook, allowing unauthenticated attackers … Sep 23, 2026
CVE-2026-87074 LOW 3.7 The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient … Sep 23, 2026
CVE-2026-87069 LOW 3.1 The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction … Sep 23, 2026
CVE-2026-86842 MEDIUM 6.8 The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flipbook management actions, allowing users with Author-level access … Sep 23, 2026
CVE-2026-86785 MEDIUM 5.3 The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its REST API endpoints, allowing unauthenticated users to … Sep 23, 2026
CVE-2026-86783 MEDIUM 5.3 The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the … Sep 23, 2026
CVE-2026-86608 HIGH 8.2 The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what … Sep 23, 2026
CVE-2026-86603 MEDIUM 4.3 The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such … Sep 23, 2026
CVE-2026-86602 MEDIUM 4.3 The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such … Sep 23, 2026
CVE-2026-85006 MEDIUM 6.8 The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an … Sep 23, 2026
CVE-2026-84743 LOW 3.8 The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with … Sep 23, 2026
CVE-2026-84742 LOW 2.7 The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, … Sep 23, 2026
CVE-2026-84741 MEDIUM 5.3 The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST … Sep 23, 2026
CVE-2026-84168 MEDIUM 5.3 The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthenticated attacker to reach the standard login page … Sep 23, 2026
CVE-2026-84150 MEDIUM 5.4 The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not verify that the target user of a REST route matches … Sep 23, 2026
CVE-2026-84098 MEDIUM 6.5 The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated … Sep 23, 2026
CVE-2026-84046 MEDIUM 5.0 The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validate a user-supplied URL before fetching it server-side, allowing users … Sep 23, 2026
CVE-2026-84027 MEDIUM 4.3 The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, … Sep 23, 2026
CVE-2026-84026 MEDIUM 5.3 The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restrict access to a REST endpoint that returns user records, … Sep 23, 2026
CVE-2026-83555 MEDIUM 5.3 The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token before changing a subscriber's subscription status, allowing unauthenticated users … Sep 23, 2026
CVE-2026-82843 CRITICAL 9.0 The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the … Sep 23, 2026
CVE-2026-81339 MEDIUM 4.3 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when returning a quiz attempt result, allowing any authenticated … Sep 23, 2026
CVE-2026-81338 MEDIUM 4.6 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in user-submitted content before storing it and rendering it … Sep 23, 2026
CVE-2026-80342 MEDIUM 6.5 The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the … Sep 23, 2026
CVE-2026-77766 MEDIUM 4.3 The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting … Sep 23, 2026