Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56672
Total
4490
Critical
16802
High
16633
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-91015 | MEDIUM | 5.3 | The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, … | Sep 17, 2026 |
| CVE-2026-91014 | HIGH | 7.1 | The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them … | Sep 17, 2026 |
| CVE-2026-91011 | MEDIUM | 6.8 | The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level … | Sep 17, 2026 |
| CVE-2026-91010 | MEDIUM | 4.3 | The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion … | Sep 17, 2026 |
| CVE-2026-91009 | MEDIUM | 4.3 | The Active Woot Products Tables for WooCommerce. 100% FREE WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX … | Sep 17, 2026 |
| CVE-2026-91008 | LOW | 3.7 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated … | Sep 17, 2026 |
| CVE-2026-90923 | MEDIUM | 6.5 | The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the … | Sep 17, 2026 |
| CVE-2026-90922 | MEDIUM | 5.3 | The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment … | Sep 17, 2026 |
| CVE-2026-88904 | HIGH | 8.8 | The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken … | Sep 17, 2026 |
| CVE-2026-88795 | CRITICAL | 9.0 | The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating … | Sep 17, 2026 |
| CVE-2026-88792 | HIGH | 8.8 | The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to … | Sep 17, 2026 |
| CVE-2026-87836 | LOW | 2.7 | The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export … | Sep 17, 2026 |
| CVE-2026-87786 | HIGH | 8.8 | The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated users … | Sep 17, 2026 |
| CVE-2026-86824 | MEDIUM | 4.8 | The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed … | Sep 17, 2026 |
| CVE-2026-86788 | MEDIUM | 6.8 | The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several … | Sep 17, 2026 |
| CVE-2026-86710 | CRITICAL | 9.8 | The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching … | Sep 17, 2026 |
| CVE-2026-86709 | CRITICAL | 9.8 | The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in … | Sep 17, 2026 |
| CVE-2026-86707 | CRITICAL | 9.8 | The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching … | Sep 17, 2026 |
| CVE-2026-86446 | LOW | 3.7 | The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is checked, allowing unauthenticated attackers to obtain … | Sep 17, 2026 |
| CVE-2026-85130 | HIGH | 8.8 | The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for the JavaScript context it is later … | Sep 17, 2026 |
| CVE-2026-85128 | HIGH | 7.5 | The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to … | Sep 17, 2026 |
| CVE-2025-15697 | HIGH | 7.1 | The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated … | Sep 17, 2026 |
| CVE-2026-87935 | HIGH | 8.1 | The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This … | Sep 17, 2026 |
| CVE-2026-87796 | CRITICAL | 9.8 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the … | Sep 17, 2026 |
| CVE-2026-50604 | UNKNOWN | — | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication … | Sep 17, 2026 |