Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45656
Total
3653
Critical
13500
High
13451
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19712 | UNKNOWN | — | The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its … | Aug 16, 2026 |
| CVE-2026-19711 | UNKNOWN | — | The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including … | Aug 16, 2026 |
| CVE-2026-19613 | UNKNOWN | — | The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater data sources reads custom field values … | Aug 16, 2026 |
| CVE-2026-18653 | UNKNOWN | — | The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrators to … | Aug 16, 2026 |
| CVE-2026-18402 | MEDIUM | 6.4 | The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'draweropenverposition' Block/Shortcode Attribute in all versions up … | Aug 16, 2026 |
| CVE-2026-18316 | CRITICAL | 9.1 | The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function … | Aug 16, 2026 |
| CVE-2026-17582 | MEDIUM | 4.9 | The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7 via the qcld_sliderhero_duplicate() function. Slide data … | Aug 16, 2026 |
| CVE-2026-17581 | HIGH | 7.2 | The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the 'thermal' Template Engine in all … | Aug 16, 2026 |
| CVE-2026-17533 | UNKNOWN | — | The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, allowing an … | Aug 16, 2026 |
| CVE-2026-16775 | MEDIUM | 6.4 | The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id' Shortcode Attribute … | Aug 16, 2026 |
| CVE-2026-16758 | MEDIUM | 6.4 | The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.2.0 due to … | Aug 16, 2026 |
| CVE-2026-15790 | MEDIUM | 6.4 | The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.4 via the 'emd_mb_meta' shortcode. This is … | Aug 16, 2026 |
| CVE-2026-15604 | MEDIUM | 6.4 | The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10 via the 'series_bg_color' post meta field. … | Aug 16, 2026 |
| CVE-2026-15384 | UNKNOWN | — | The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that crops attachment … | Aug 16, 2026 |
| CVE-2026-15351 | MEDIUM | 4.9 | The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to generic SQL Injection via the 'status' parameter in all … | Aug 16, 2026 |
| CVE-2026-15345 | MEDIUM | 4.3 | The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, … | Aug 16, 2026 |
| CVE-2026-15056 | MEDIUM | 6.5 | The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversal in all versions up to, … | Aug 16, 2026 |
| CVE-2026-13712 | UNKNOWN | — | The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attributes, allowing … | Aug 16, 2026 |
| CVE-2026-10035 | MEDIUM | 6.6 | The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deserialization of … | Aug 16, 2026 |
| CVE-2026-19933 | MEDIUM | 6.3 | A weakness has been identified in DefaultFuction Customer-Relationship-Management-In-C-Project 2.0. Impacted is the function gets of the component Customer Search Module. This manipulation causes stack-based buffer … | Aug 16, 2026 |
| CVE-2026-19932 | MEDIUM | 6.3 | A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects the function GroovyShell.evaluate of the file /execute of the component NoticeController. The … | Aug 16, 2026 |
| CVE-2026-18432 | CRITICAL | 9.8 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because … | Aug 16, 2026 |
| CVE-2026-18385 | MEDIUM | 5.4 | The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary … | Aug 16, 2026 |
| CVE-2026-17123 | HIGH | 8.8 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's … | Aug 16, 2026 |
| CVE-2026-16779 | MEDIUM | 4.3 | The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.5. This is due to … | Aug 16, 2026 |