Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45156
Total
3619
Critical
13387
High
13301
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19842 | HIGH | 8.8 | The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, and … | Aug 19, 2026 |
| CVE-2026-19782 | MEDIUM | 5.4 | The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJAX action, allowing any authenticated user, such as a subscriber, … | Aug 19, 2026 |
| CVE-2026-19709 | MEDIUM | 5.3 | The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the … | Aug 19, 2026 |
| CVE-2026-19417 | MEDIUM | 6.5 | The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level users … | Aug 19, 2026 |
| CVE-2026-19416 | MEDIUM | 4.3 | The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment being modified, allowing authenticated patient-level users to cancel and … | Aug 19, 2026 |
| CVE-2026-19406 | LOW | 2.7 | The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing … | Aug 19, 2026 |
| CVE-2026-19056 | HIGH | 7.1 | The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one of … | Aug 19, 2026 |
| CVE-2026-19055 | HIGH | 7.1 | The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes on its public pages, … | Aug 19, 2026 |
| CVE-2026-18937 | CRITICAL | 9.0 | The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing … | Aug 19, 2026 |
| CVE-2026-18779 | MEDIUM | 5.3 | The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment … | Aug 19, 2026 |
| CVE-2026-18778 | MEDIUM | 5.3 | The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to retrieve the personal … | Aug 19, 2026 |
| CVE-2026-18777 | MEDIUM | 5.3 | The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to change the status … | Aug 19, 2026 |
| CVE-2026-18776 | CRITICAL | 9.8 | The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email … | Aug 19, 2026 |
| CVE-2026-18466 | MEDIUM | 5.4 | The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users … | Aug 19, 2026 |
| CVE-2026-18231 | MEDIUM | 5.3 | The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database … | Aug 19, 2026 |
| CVE-2026-18202 | MEDIUM | 6.8 | The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing users with the … | Aug 19, 2026 |
| CVE-2026-18051 | CRITICAL | 10.0 | The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers … | Aug 19, 2026 |
| CVE-2026-18031 | CRITICAL | 9.8 | The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated with the referenced order, … | Aug 19, 2026 |
| CVE-2026-17565 | HIGH | 7.2 | The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side … | Aug 19, 2026 |
| CVE-2026-16979 | MEDIUM | 4.3 | The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with … | Aug 19, 2026 |
| CVE-2026-16950 | HIGH | 8.6 | The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers … | Aug 19, 2026 |
| CVE-2026-16617 | HIGH | 8.8 | The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, … | Aug 19, 2026 |
| CVE-2026-16616 | HIGH | 8.6 | The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to … | Aug 19, 2026 |
| CVE-2026-16570 | HIGH | 7.1 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin … | Aug 19, 2026 |
| CVE-2026-16058 | MEDIUM | 5.3 | The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers that are reachable by … | Aug 19, 2026 |