Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41893
Total
3420
Critical
12384
High
12282
Medium
CVE ID Severity Score Description Published
CVE-2026-83543 UNKNOWN The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make … Sep 05, 2026
CVE-2026-82846 UNKNOWN The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, … Sep 05, 2026
CVE-2026-82304 UNKNOWN The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL … Sep 05, 2026
CVE-2026-81424 UNKNOWN The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative … Sep 05, 2026
CVE-2026-81423 UNKNOWN The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect … Sep 05, 2026
CVE-2026-81404 UNKNOWN The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated … Sep 05, 2026
CVE-2026-81348 UNKNOWN The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to … Sep 05, 2026
CVE-2026-78438 HIGH 7.2 The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, … Sep 05, 2026
CVE-2026-78362 UNKNOWN The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be … Sep 05, 2026
CVE-2026-78150 UNKNOWN The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users … Sep 05, 2026
CVE-2026-78149 UNKNOWN The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through … Sep 05, 2026
CVE-2026-77830 HIGH 7.2 The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all versions up … Sep 05, 2026
CVE-2026-77826 UNKNOWN The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, … Sep 05, 2026
CVE-2026-4361 MEDIUM 5.0 The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` … Sep 05, 2026
CVE-2026-3853 MEDIUM 6.4 The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider_item` shortcode in all versions up to, … Sep 05, 2026
CVE-2026-19887 HIGH 8.8 The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input … Sep 05, 2026
CVE-2026-19861 UNKNOWN The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in … Sep 05, 2026
CVE-2026-19858 UNKNOWN The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated … Sep 05, 2026
CVE-2026-19769 HIGH 7.2 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' … Sep 05, 2026
CVE-2026-18843 MEDIUM 6.1 The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all versions up to, and … Sep 05, 2026
CVE-2026-18406 HIGH 7.2 The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field … Sep 05, 2026
CVE-2026-16649 HIGH 7.2 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 … Sep 05, 2026
CVE-2026-15984 HIGH 7.2 The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and including, 1.0.20 due to … Sep 05, 2026
CVE-2026-15247 UNKNOWN The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its … Sep 05, 2026
CVE-2026-14975 MEDIUM 6.5 The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter. This … Sep 05, 2026