Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56102
Total
4437
Critical
16640
High
16418
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92403 | LOW | 3.7 | The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to … | Sep 19, 2026 |
| CVE-2026-92099 | MEDIUM | 6.5 | The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persisted query from a … | Sep 19, 2026 |
| CVE-2026-91847 | MEDIUM | 4.8 | The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its … | Sep 19, 2026 |
| CVE-2026-88926 | HIGH | 8.6 | The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, … | Sep 19, 2026 |
| CVE-2026-88824 | HIGH | 8.8 | The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including … | Sep 19, 2026 |
| CVE-2026-86814 | HIGH | 8.1 | The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to … | Sep 19, 2026 |
| CVE-2026-86591 | CRITICAL | 9.8 | The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary … | Sep 19, 2026 |
| CVE-2026-85680 | HIGH | 8.8 | The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, … | Sep 19, 2026 |
| CVE-2026-85574 | HIGH | 8.0 | The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any … | Sep 19, 2026 |
| CVE-2026-84750 | MEDIUM | 6.5 | The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uploaded through one of its … | Sep 19, 2026 |
| CVE-2026-76790 | HIGH | 7.1 | The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back … | Sep 19, 2026 |
| CVE-2026-76554 | HIGH | 7.2 | The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to create or modify user … | Sep 19, 2026 |
| CVE-2026-19860 | MEDIUM | 5.5 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation … | Sep 19, 2026 |
| CVE-2026-16557 | MEDIUM | 4.3 | The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any … | Sep 19, 2026 |
| CVE-2025-15698 | LOW | 3.5 | The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as … | Sep 19, 2026 |
| CVE-2026-93741 | CRITICAL | 10.0 | A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of … | Sep 19, 2026 |
| CVE-2026-92967 | MEDIUM | 6.1 | The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' parameter in versions up to, and including, 1.20.2. This is due … | Sep 19, 2026 |
| CVE-2026-92807 | HIGH | 8.8 | The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via … | Sep 19, 2026 |
| CVE-2026-92229 | CRITICAL | 9.1 | The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions … | Sep 19, 2026 |
| CVE-2026-89334 | MEDIUM | 6.5 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions … | Sep 19, 2026 |
| CVE-2026-89333 | MEDIUM | 6.5 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and … | Sep 19, 2026 |
| CVE-2026-89274 | CRITICAL | 9.1 | The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because … | Sep 19, 2026 |
| CVE-2026-89093 | MEDIUM | 5.3 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in … | Sep 19, 2026 |
| CVE-2026-89081 | MEDIUM | 6.1 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions … | Sep 19, 2026 |
| CVE-2026-88944 | MEDIUM | 4.3 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.8. … | Sep 19, 2026 |