Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56907
Total
4512
Critical
16897
High
16715
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-86449 | UNKNOWN | — | The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user supplied post status filter in one of its REST … | Sep 16, 2026 |
| CVE-2026-86448 | UNKNOWN | — | The LearnPress WordPress plugin before 4.4.7 does not perform any authentication, capability or nonce check before serving a previously generated order export file, allowing unauthenticated … | Sep 16, 2026 |
| CVE-2026-86447 | UNKNOWN | — | The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative course tools, allowing unauthenticated attackers to list every … | Sep 16, 2026 |
| CVE-2026-86445 | UNKNOWN | — | The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative template handlers, allowing unauthenticated attackers to retrieve the … | Sep 16, 2026 |
| CVE-2026-86444 | UNKNOWN | — | The LearnPress WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attribute on a public page, allowing … | Sep 16, 2026 |
| CVE-2026-85641 | UNKNOWN | — | The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user last edited a form entry, and relies … | Sep 16, 2026 |
| CVE-2026-85572 | UNKNOWN | — | The Tutor LMS WordPress plugin before 4.0.8 does not check that a user has access to a course before returning its lesson discussion content, allowing … | Sep 16, 2026 |
| CVE-2026-85569 | UNKNOWN | — | The Tutor LMS WordPress plugin before 4.0.8 does not correctly determine whether an incoming request is addressed to its own REST API, and does not … | Sep 16, 2026 |
| CVE-2026-85530 | UNKNOWN | — | The GiveWP WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between the value it stores and the value it later uses … | Sep 16, 2026 |
| CVE-2026-85349 | UNKNOWN | — | The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a user belongs to, allowing any authenticated user, … | Sep 16, 2026 |
| CVE-2026-85131 | UNKNOWN | — | The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk actions on its administration screens, and does … | Sep 16, 2026 |
| CVE-2026-84907 | UNKNOWN | — | The Eventin WordPress plugin before 4.1.24 does not properly authorise order finalisation when its offline (local) payment method is enabled, relying on a nonce that … | Sep 16, 2026 |
| CVE-2026-84905 | UNKNOWN | — | The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker, allowing users with contributor-level access and … | Sep 16, 2026 |
| CVE-2026-84829 | UNKNOWN | — | The Optimole WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to build an image tag attribute, allowing unauthenticated … | Sep 16, 2026 |
| CVE-2026-84088 | UNKNOWN | — | The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link setting before storing and using … | Sep 16, 2026 |
| CVE-2026-82126 | UNKNOWN | — | The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check that a user is allowed to edit the specific … | Sep 16, 2026 |
| CVE-2026-82125 | UNKNOWN | — | The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the moderation status of a … | Sep 16, 2026 |
| CVE-2026-82124 | UNKNOWN | — | The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protected before including its … | Sep 16, 2026 |
| CVE-2026-78474 | UNKNOWN | — | The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated … | Sep 16, 2026 |
| CVE-2026-78472 | UNKNOWN | — | The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated … | Sep 16, 2026 |
| CVE-2026-77702 | UNKNOWN | — | The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to change that order's tickets … | Sep 16, 2026 |
| CVE-2026-76559 | UNKNOWN | — | The WP Import Export Lite WordPress plugin before 3.9.33 does not properly validate URLs before requesting them during the import process, allowing users with the … | Sep 16, 2026 |
| CVE-2026-76558 | UNKNOWN | — | The WP Import Export Lite WordPress plugin before 3.9.33 does not escape custom field names retrieved from the database before inserting them into the DOM … | Sep 16, 2026 |
| CVE-2026-76557 | UNKNOWN | — | The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configuration values before using them in SQL statements, … | Sep 16, 2026 |
| CVE-2026-76556 | UNKNOWN | — | The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some export filter values before using them in SQL statements, … | Sep 16, 2026 |