Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

46113
Total
3679
Critical
13638
High
13568
Medium
CVE ID Severity Score Description Published
CVE-2026-2283 MEDIUM 4.9 The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions up to, and including, 2.1.7. This … Aug 16, 2026
CVE-2026-19934 MEDIUM 6.3 A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /vieworder.php. The manipulation of the argument … Aug 16, 2026
CVE-2026-19728 UNKNOWN The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploaded file before serving … Aug 16, 2026
CVE-2026-19726 UNKNOWN The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contributor role and above … Aug 16, 2026
CVE-2026-19725 UNKNOWN The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to … Aug 16, 2026
CVE-2026-19717 UNKNOWN The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API endpoints, allowing unauthenticated … Aug 16, 2026
CVE-2026-19714 UNKNOWN The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate … Aug 16, 2026
CVE-2026-19712 UNKNOWN The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its … Aug 16, 2026
CVE-2026-19711 UNKNOWN The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including … Aug 16, 2026
CVE-2026-19613 UNKNOWN The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater data sources reads custom field values … Aug 16, 2026
CVE-2026-18653 UNKNOWN The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrators to … Aug 16, 2026
CVE-2026-18402 MEDIUM 6.4 The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'draweropenverposition' Block/Shortcode Attribute in all versions up … Aug 16, 2026
CVE-2026-18316 CRITICAL 9.1 The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function … Aug 16, 2026
CVE-2026-17582 MEDIUM 4.9 The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7 via the qcld_sliderhero_duplicate() function. Slide data … Aug 16, 2026
CVE-2026-17581 HIGH 7.2 The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the 'thermal' Template Engine in all … Aug 16, 2026
CVE-2026-17533 UNKNOWN The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, allowing an … Aug 16, 2026
CVE-2026-16775 MEDIUM 6.4 The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id' Shortcode Attribute … Aug 16, 2026
CVE-2026-16758 MEDIUM 6.4 The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.2.0 due to … Aug 16, 2026
CVE-2026-15790 MEDIUM 6.4 The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.4 via the 'emd_mb_meta' shortcode. This is … Aug 16, 2026
CVE-2026-15604 MEDIUM 6.4 The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10 via the 'series_bg_color' post meta field. … Aug 16, 2026
CVE-2026-15384 UNKNOWN The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that crops attachment … Aug 16, 2026
CVE-2026-15351 MEDIUM 4.9 The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to generic SQL Injection via the 'status' parameter in all … Aug 16, 2026
CVE-2026-15345 MEDIUM 4.3 The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, … Aug 16, 2026
CVE-2026-15056 MEDIUM 6.5 The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversal in all versions up to, … Aug 16, 2026
CVE-2026-13712 UNKNOWN The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attributes, allowing … Aug 16, 2026