Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56672
Total
4490
Critical
16802
High
16633
Medium
CVE ID Severity Score Description Published
CVE-2026-91015 MEDIUM 5.3 The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, … Sep 17, 2026
CVE-2026-91014 HIGH 7.1 The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them … Sep 17, 2026
CVE-2026-91011 MEDIUM 6.8 The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level … Sep 17, 2026
CVE-2026-91010 MEDIUM 4.3 The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion … Sep 17, 2026
CVE-2026-91009 MEDIUM 4.3 The Active Woot Products Tables for WooCommerce. 100% FREE WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX … Sep 17, 2026
CVE-2026-91008 LOW 3.7 The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated … Sep 17, 2026
CVE-2026-90923 MEDIUM 6.5 The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the … Sep 17, 2026
CVE-2026-90922 MEDIUM 5.3 The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment … Sep 17, 2026
CVE-2026-88904 HIGH 8.8 The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken … Sep 17, 2026
CVE-2026-88795 CRITICAL 9.0 The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating … Sep 17, 2026
CVE-2026-88792 HIGH 8.8 The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to … Sep 17, 2026
CVE-2026-87836 LOW 2.7 The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export … Sep 17, 2026
CVE-2026-87786 HIGH 8.8 The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated users … Sep 17, 2026
CVE-2026-86824 MEDIUM 4.8 The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed … Sep 17, 2026
CVE-2026-86788 MEDIUM 6.8 The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several … Sep 17, 2026
CVE-2026-86710 CRITICAL 9.8 The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching … Sep 17, 2026
CVE-2026-86709 CRITICAL 9.8 The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in … Sep 17, 2026
CVE-2026-86707 CRITICAL 9.8 The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching … Sep 17, 2026
CVE-2026-86446 LOW 3.7 The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is checked, allowing unauthenticated attackers to obtain … Sep 17, 2026
CVE-2026-85130 HIGH 8.8 The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for the JavaScript context it is later … Sep 17, 2026
CVE-2026-85128 HIGH 7.5 The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to … Sep 17, 2026
CVE-2025-15697 HIGH 7.1 The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated … Sep 17, 2026
CVE-2026-87935 HIGH 8.1 The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This … Sep 17, 2026
CVE-2026-87796 CRITICAL 9.8 The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the … Sep 17, 2026
CVE-2026-50604 UNKNOWN — A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication … Sep 17, 2026