Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41893
Total
3420
Critical
12384
High
12282
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-83543 | UNKNOWN | — | The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make … | Sep 05, 2026 |
| CVE-2026-82846 | UNKNOWN | — | The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, … | Sep 05, 2026 |
| CVE-2026-82304 | UNKNOWN | — | The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL … | Sep 05, 2026 |
| CVE-2026-81424 | UNKNOWN | — | The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative … | Sep 05, 2026 |
| CVE-2026-81423 | UNKNOWN | — | The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect … | Sep 05, 2026 |
| CVE-2026-81404 | UNKNOWN | — | The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated … | Sep 05, 2026 |
| CVE-2026-81348 | UNKNOWN | — | The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to … | Sep 05, 2026 |
| CVE-2026-78438 | HIGH | 7.2 | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, … | Sep 05, 2026 |
| CVE-2026-78362 | UNKNOWN | — | The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be … | Sep 05, 2026 |
| CVE-2026-78150 | UNKNOWN | — | The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users … | Sep 05, 2026 |
| CVE-2026-78149 | UNKNOWN | — | The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through … | Sep 05, 2026 |
| CVE-2026-77830 | HIGH | 7.2 | The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all versions up … | Sep 05, 2026 |
| CVE-2026-77826 | UNKNOWN | — | The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, … | Sep 05, 2026 |
| CVE-2026-4361 | MEDIUM | 5.0 | The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` … | Sep 05, 2026 |
| CVE-2026-3853 | MEDIUM | 6.4 | The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider_item` shortcode in all versions up to, … | Sep 05, 2026 |
| CVE-2026-19887 | HIGH | 8.8 | The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input … | Sep 05, 2026 |
| CVE-2026-19861 | UNKNOWN | — | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in … | Sep 05, 2026 |
| CVE-2026-19858 | UNKNOWN | — | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated … | Sep 05, 2026 |
| CVE-2026-19769 | HIGH | 7.2 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' … | Sep 05, 2026 |
| CVE-2026-18843 | MEDIUM | 6.1 | The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all versions up to, and … | Sep 05, 2026 |
| CVE-2026-18406 | HIGH | 7.2 | The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field … | Sep 05, 2026 |
| CVE-2026-16649 | HIGH | 7.2 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 … | Sep 05, 2026 |
| CVE-2026-15984 | HIGH | 7.2 | The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and including, 1.0.20 due to … | Sep 05, 2026 |
| CVE-2026-15247 | UNKNOWN | — | The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its … | Sep 05, 2026 |
| CVE-2026-14975 | MEDIUM | 6.5 | The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter. This … | Sep 05, 2026 |