Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56102
Total
4437
Critical
16640
High
16418
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-5400 | MEDIUM | 6.4 | The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media field filter values in versions up to, and including, 4.5.13 … | Sep 19, 2026 |
| CVE-2026-4792 | MEDIUM | 5.3 | The Bread plugin for WordPress is vulnerable to information exposure in versions up to and including 2.9.12. This is due to the lack of authentication … | Sep 19, 2026 |
| CVE-2026-4327 | HIGH | 8.8 | The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing … | Sep 19, 2026 |
| CVE-2026-2422 | MEDIUM | 6.4 | The WP Composer – The Easiest Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pbwp_raw_shortcode' shortcode in all versions up … | Sep 19, 2026 |
| CVE-2026-2278 | MEDIUM | 4.3 | The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in … | Sep 19, 2026 |
| CVE-2026-1984 | MEDIUM | 5.3 | The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on the 'iepa_use_gt_editor' … | Sep 19, 2026 |
| CVE-2026-1641 | MEDIUM | 6.5 | The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2. This is … | Sep 19, 2026 |
| CVE-2026-1242 | MEDIUM | 4.3 | The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, … | Sep 19, 2026 |
| CVE-2026-15947 | MEDIUM | 4.3 | The Metasync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_instant_indexing_settings() function in versions up … | Sep 19, 2026 |
| CVE-2026-15946 | MEDIUM | 4.3 | The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authorization bypass in … | Sep 19, 2026 |
| CVE-2026-15664 | HIGH | 7.2 | The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple Choice 'Other' Value … | Sep 19, 2026 |
| CVE-2026-15463 | MEDIUM | 6.1 | The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'host' parameter in all … | Sep 19, 2026 |
| CVE-2026-15098 | MEDIUM | 6.4 | The Real3D Flipbook Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lightboxtext' shortcode attribute (and other unsanitized attributes handled by on_shortcode()) … | Sep 19, 2026 |
| CVE-2026-13770 | MEDIUM | 6.4 | The AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | Sep 19, 2026 |
| CVE-2026-13200 | MEDIUM | 6.5 | The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 2.5.3 due to … | Sep 19, 2026 |
| CVE-2026-13191 | MEDIUM | 6.5 | The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 2.5.3 due to … | Sep 19, 2026 |
| CVE-2026-12402 | MEDIUM | 4.4 | The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fb-config' Setting in all versions up to, and including, … | Sep 19, 2026 |
| CVE-2026-11899 | MEDIUM | 4.3 | The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, … | Sep 19, 2026 |
| CVE-2026-11608 | MEDIUM | 6.1 | The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.8 … | Sep 19, 2026 |
| CVE-2026-92435 | MEDIUM | 5.3 | The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several … | Sep 19, 2026 |
| CVE-2026-92430 | MEDIUM | 5.3 | The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment … | Sep 19, 2026 |
| CVE-2026-92425 | MEDIUM | 5.5 | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, … | Sep 19, 2026 |
| CVE-2026-92421 | MEDIUM | 4.7 | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the … | Sep 19, 2026 |
| CVE-2026-92420 | LOW | 3.8 | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before … | Sep 19, 2026 |
| CVE-2026-92404 | HIGH | 7.5 | The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored … | Sep 19, 2026 |