Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42028
Total
3422
Critical
12413
High
12340
Medium
CVE ID Severity Score Description Published
CVE-2026-77788 MEDIUM 4.9 The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised … Sep 02, 2026
CVE-2026-77787 LOW 2.7 The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied … Sep 02, 2026
CVE-2026-77785 LOW 2.7 The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to read the specific post referenced in a … Sep 02, 2026
CVE-2026-77784 LOW 2.7 The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modified before updating its … Sep 02, 2026
CVE-2026-77783 LOW 3.7 The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, … Sep 02, 2026
CVE-2026-77782 MEDIUM 5.3 The Rank Math SEO WordPress plugin before 1.0.277.1 does not check whether a post is password protected before using its content to build publicly generated … Sep 02, 2026
CVE-2026-77764 MEDIUM 4.3 The GamiPress WordPress plugin before 7.9.9.6 does not properly restrict its video watch-tracking functionality, allowing users with a role as low as Subscriber to award … Sep 02, 2026
CVE-2026-74927 MEDIUM 5.3 The MultiVendorX WordPress plugin before 5.0.15 does not have proper authorisation controls on one of its REST API listing routes, allowing unauthenticated users to retrieve … Sep 02, 2026
CVE-2026-19723 HIGH 7.1 The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before … Sep 02, 2026
CVE-2026-19719 MEDIUM 6.8 The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline … Sep 02, 2026
CVE-2026-19704 MEDIUM 5.3 The Comments WordPress plugin before 7.6.66 does not validate a value used to build a database query, allowing unauthenticated users to inject SQL and read … Sep 02, 2026
CVE-2026-19453 HIGH 7.1 The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting … Sep 02, 2026
CVE-2026-19251 MEDIUM 5.3 The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whether the profile it belongs to is private, … Sep 02, 2026
CVE-2026-19116 HIGH 8.8 The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend … Sep 02, 2026
CVE-2026-16983 MEDIUM 4.3 The Gutentor WordPress plugin before 4.0.6 does not apply the correct context restriction to one of its REST endpoints, exposing the plaintext passwords of password-protected … Sep 02, 2026
CVE-2026-16966 MEDIUM 5.3 The Solace Extra WordPress plugin before 1.7.0 does not perform any authorization or post-status checks in one of its AJAX actions, allowing unauthenticated visitors to … Sep 02, 2026
CVE-2026-15232 MEDIUM 5.3 The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated … Sep 02, 2026
CVE-2026-14357 HIGH 8.8 The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability … Sep 02, 2026
CVE-2026-14215 MEDIUM 6.5 The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action … Sep 02, 2026
CVE-2026-12865 HIGH 7.1 The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting them into input-attribute values on its admin pages … Sep 02, 2026
CVE-2026-12526 HIGH 8.1 The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the … Sep 02, 2026
CVE-2025-15664 MEDIUM 6.8 The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script … Sep 02, 2026
CVE-2025-15663 MEDIUM 6.8 The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's after-label value before its bundled client-side script … Sep 02, 2026
CVE-2026-9055 CRITICAL 9.8 The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is … Sep 02, 2026
CVE-2025-46418 HIGH 7.6 Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition. Sep 02, 2026