Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42028
Total
3422
Critical
12413
High
12340
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-77788 | MEDIUM | 4.9 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised … | Sep 02, 2026 |
| CVE-2026-77787 | LOW | 2.7 | The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied … | Sep 02, 2026 |
| CVE-2026-77785 | LOW | 2.7 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to read the specific post referenced in a … | Sep 02, 2026 |
| CVE-2026-77784 | LOW | 2.7 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modified before updating its … | Sep 02, 2026 |
| CVE-2026-77783 | LOW | 3.7 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, … | Sep 02, 2026 |
| CVE-2026-77782 | MEDIUM | 5.3 | The Rank Math SEO WordPress plugin before 1.0.277.1 does not check whether a post is password protected before using its content to build publicly generated … | Sep 02, 2026 |
| CVE-2026-77764 | MEDIUM | 4.3 | The GamiPress WordPress plugin before 7.9.9.6 does not properly restrict its video watch-tracking functionality, allowing users with a role as low as Subscriber to award … | Sep 02, 2026 |
| CVE-2026-74927 | MEDIUM | 5.3 | The MultiVendorX WordPress plugin before 5.0.15 does not have proper authorisation controls on one of its REST API listing routes, allowing unauthenticated users to retrieve … | Sep 02, 2026 |
| CVE-2026-19723 | HIGH | 7.1 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before … | Sep 02, 2026 |
| CVE-2026-19719 | MEDIUM | 6.8 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline … | Sep 02, 2026 |
| CVE-2026-19704 | MEDIUM | 5.3 | The Comments WordPress plugin before 7.6.66 does not validate a value used to build a database query, allowing unauthenticated users to inject SQL and read … | Sep 02, 2026 |
| CVE-2026-19453 | HIGH | 7.1 | The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting … | Sep 02, 2026 |
| CVE-2026-19251 | MEDIUM | 5.3 | The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whether the profile it belongs to is private, … | Sep 02, 2026 |
| CVE-2026-19116 | HIGH | 8.8 | The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend … | Sep 02, 2026 |
| CVE-2026-16983 | MEDIUM | 4.3 | The Gutentor WordPress plugin before 4.0.6 does not apply the correct context restriction to one of its REST endpoints, exposing the plaintext passwords of password-protected … | Sep 02, 2026 |
| CVE-2026-16966 | MEDIUM | 5.3 | The Solace Extra WordPress plugin before 1.7.0 does not perform any authorization or post-status checks in one of its AJAX actions, allowing unauthenticated visitors to … | Sep 02, 2026 |
| CVE-2026-15232 | MEDIUM | 5.3 | The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated … | Sep 02, 2026 |
| CVE-2026-14357 | HIGH | 8.8 | The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability … | Sep 02, 2026 |
| CVE-2026-14215 | MEDIUM | 6.5 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action … | Sep 02, 2026 |
| CVE-2026-12865 | HIGH | 7.1 | The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting them into input-attribute values on its admin pages … | Sep 02, 2026 |
| CVE-2026-12526 | HIGH | 8.1 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the … | Sep 02, 2026 |
| CVE-2025-15664 | MEDIUM | 6.8 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script … | Sep 02, 2026 |
| CVE-2025-15663 | MEDIUM | 6.8 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's after-label value before its bundled client-side script … | Sep 02, 2026 |
| CVE-2026-9055 | CRITICAL | 9.8 | The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is … | Sep 02, 2026 |
| CVE-2025-46418 | HIGH | 7.6 | Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition. | Sep 02, 2026 |