Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41893
Total
3420
Critical
12384
High
12282
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-76573 | MEDIUM | 6.4 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'not_found' Shortcode Attribute in all versions up … | Sep 05, 2026 |
| CVE-2024-11080 | CRITICAL | 9.8 | The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions … | Sep 05, 2026 |
| CVE-2026-85414 | MEDIUM | 6.4 | The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute in all versions up to, and including, 3.3.2 … | Sep 05, 2026 |
| CVE-2026-83625 | HIGH | 7.2 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all versions up to, and including, … | Sep 05, 2026 |
| CVE-2026-81543 | HIGH | 8.8 | The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due … | Sep 05, 2026 |
| CVE-2026-75586 | MEDIUM | 6.1 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'formData[id]' Parameter in all versions up to, and including, 2.0.17 … | Sep 05, 2026 |
| CVE-2026-75018 | MEDIUM | 4.3 | The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due to the … | Sep 05, 2026 |
| CVE-2026-84937 | UNKNOWN | — | The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing … | Sep 05, 2026 |
| CVE-2026-84936 | UNKNOWN | — | The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make … | Sep 05, 2026 |
| CVE-2026-84935 | UNKNOWN | — | The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those … | Sep 05, 2026 |
| CVE-2026-84934 | UNKNOWN | — | The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose … | Sep 05, 2026 |
| CVE-2026-84931 | UNKNOWN | — | The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's … | Sep 05, 2026 |
| CVE-2026-84930 | UNKNOWN | — | The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag … | Sep 05, 2026 |
| CVE-2026-84927 | UNKNOWN | — | The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with … | Sep 05, 2026 |
| CVE-2026-84926 | UNKNOWN | — | The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user … | Sep 05, 2026 |
| CVE-2026-84901 | UNKNOWN | — | The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above … | Sep 05, 2026 |
| CVE-2026-84899 | UNKNOWN | — | The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the … | Sep 05, 2026 |
| CVE-2026-84898 | UNKNOWN | — | The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with … | Sep 05, 2026 |
| CVE-2026-84896 | UNKNOWN | — | The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users … | Sep 05, 2026 |
| CVE-2026-84745 | UNKNOWN | — | The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing … | Sep 05, 2026 |
| CVE-2026-84225 | UNKNOWN | — | The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing … | Sep 05, 2026 |
| CVE-2026-84221 | UNKNOWN | — | The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and … | Sep 05, 2026 |
| CVE-2026-84022 | UNKNOWN | — | The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML attributes, allowing users with … | Sep 05, 2026 |
| CVE-2026-84021 | UNKNOWN | — | The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a … | Sep 05, 2026 |
| CVE-2026-83544 | UNKNOWN | — | The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it within an HTML attribute, allowing users with contributor-level … | Sep 05, 2026 |