Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

52066
Total
4132
Critical
15433
High
15137
Medium
CVE ID Severity Score Description Published
CVE-2026-15099 MEDIUM 6.4 The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute in versions up to, and including, 1.10.2. This … Jul 16, 2026
CVE-2026-15022 MEDIUM 6.5 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all … Jul 16, 2026
CVE-2026-15021 MEDIUM 6.4 The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including, 3.1.1 due … Jul 16, 2026
CVE-2026-15008 HIGH 8.1 The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file … Jul 16, 2026
CVE-2026-15005 HIGH 8.8 The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing … Jul 16, 2026
CVE-2026-13767 MEDIUM 6.5 The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This … Jul 16, 2026
CVE-2026-13755 MEDIUM 6.4 The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute in all versions up … Jul 16, 2026
CVE-2026-13754 MEDIUM 6.5 The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up … Jul 16, 2026
CVE-2026-13741 HIGH 8.8 The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.0.5. This … Jul 16, 2026
CVE-2026-15925 UNKNOWN — Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname … Jul 16, 2026
CVE-2026-12979 MEDIUM 5.5 The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator privileges … Jul 16, 2026
CVE-2026-12978 HIGH 7.1 The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX … Jul 16, 2026
CVE-2026-12907 LOW 2.7 The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions, allowing users with at least … Jul 16, 2026
CVE-2026-12906 LOW 2.7 The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a request-supplied post identifier directly, … Jul 16, 2026
CVE-2026-12869 MEDIUM 6.1 The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for its dashboard template-import action (it allows any edit_posts … Jul 16, 2026
CVE-2026-12684 MEDIUM 6.5 The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions … Jul 16, 2026
CVE-2026-12585 HIGH 8.1 The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting … Jul 16, 2026
CVE-2026-12525 HIGH 8.8 The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with … Jul 16, 2026
CVE-2026-12510 MEDIUM 5.9 The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with … Jul 16, 2026
CVE-2026-12492 CRITICAL 9.8 The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user … Jul 16, 2026
CVE-2026-12395 MEDIUM 6.5 The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated … Jul 16, 2026
CVE-2026-11866 MEDIUM 5.4 The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing … Jul 16, 2026
CVE-2026-11371 MEDIUM 6.1 The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the feature that generates it is … Jul 16, 2026
CVE-2026-53366 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation path In __ip_append_data(), when the paged-allocation branch … Jul 16, 2026
CVE-2026-15458 MEDIUM 4.9 The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versions up to, and including, 7.3.1 due … Jul 16, 2026