Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56334
Total
4455
Critical
16700
High
16518
Medium
CVE ID Severity Score Description Published
CVE-2026-13471 MEDIUM 4.3 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, … Sep 18, 2026
CVE-2026-12954 HIGH 8.8 The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` … Sep 18, 2026
CVE-2026-12739 MEDIUM 4.3 The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, … Sep 18, 2026
CVE-2026-12384 HIGH 8.8 Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. This issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026. NOTE: The vendor … Sep 18, 2026
CVE-2026-11757 MEDIUM 6.1 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Technologies Ltd. Co. Bar Association Website allows Reflected XSS. This issue … Sep 18, 2026
CVE-2026-92714 MEDIUM 6.5 The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked … Sep 18, 2026
CVE-2026-92619 HIGH 7.2 The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action. The … Sep 18, 2026
CVE-2026-92561 MEDIUM 6.1 The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to, and including, 11.8.2 due … Sep 18, 2026
CVE-2026-91707 MEDIUM 5.3 The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.11.1. This is due to the … Sep 18, 2026
CVE-2026-90977 MEDIUM 5.3 The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass … Sep 18, 2026
CVE-2026-90976 MEDIUM 5.3 The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an account in its registration handler, allowing unauthenticated … Sep 18, 2026
CVE-2026-89413 HIGH 8.1 The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin … Sep 18, 2026
CVE-2026-89330 MEDIUM 6.1 The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Reflected Cross-Site … Sep 18, 2026
CVE-2026-89278 MEDIUM 5.3 The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Information Exposure in all … Sep 18, 2026
CVE-2026-89138 MEDIUM 4.3 The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin … Sep 18, 2026
CVE-2026-88994 MEDIUM 6.6 The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included … Sep 18, 2026
CVE-2026-86800 MEDIUM 5.3 The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disabling its login and URL hiding protection, … Sep 18, 2026
CVE-2026-86796 MEDIUM 5.3 The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection … Sep 18, 2026
CVE-2026-84909 MEDIUM 6.4 The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute … Sep 18, 2026
CVE-2026-79713 MEDIUM 6.5 The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested … Sep 18, 2026
CVE-2026-75017 MEDIUM 4.3 The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to authorization … Sep 18, 2026
CVE-2026-75016 MEDIUM 6.4 The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's clientId attribute in versions up to, and including, … Sep 18, 2026
CVE-2026-18317 MEDIUM 4.3 The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to authorization bypass in all versions up to, and … Sep 18, 2026
CVE-2026-17576 MEDIUM 6.5 The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, and including, 1.13.9. This is due … Sep 18, 2026
CVE-2026-12106 MEDIUM 6.4 The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the downloadImage … Sep 18, 2026