Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48851
Total
3923
Critical
14488
High
14228
Medium
CVE ID Severity Score Description Published
CVE-2026-18391 CRITICAL 9.8 The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a … Aug 12, 2026
CVE-2026-18366 CRITICAL 9.8 The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress already made for unrelated privileged … Aug 12, 2026
CVE-2026-18230 HIGH 8.1 The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one of … Aug 12, 2026
CVE-2026-18057 HIGH 8.1 The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with … Aug 12, 2026
CVE-2026-18049 HIGH 7.5 The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public endpoint actions and … Aug 12, 2026
CVE-2026-18048 HIGH 7.5 The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a file path in one of its … Aug 12, 2026
CVE-2026-18046 MEDIUM 4.3 The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability check on the REST route that stores its geolocation service … Aug 12, 2026
CVE-2026-18035 MEDIUM 5.3 The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content … Aug 12, 2026
CVE-2026-17013 MEDIUM 6.1 The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into an inline script block, which … Aug 12, 2026
CVE-2026-16977 HIGH 8.1 The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built … Aug 12, 2026
CVE-2026-16737 MEDIUM 5.3 The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its … Aug 12, 2026
CVE-2026-16538 CRITICAL 9.1 The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wallet, allowing customers … Aug 12, 2026
CVE-2026-16294 HIGH 7.1 The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side request … Aug 12, 2026
CVE-2026-16253 HIGH 7.5 The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-restore functionality and exposes it to unauthenticated users, allowing … Aug 12, 2026
CVE-2026-16066 MEDIUM 5.4 The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it on the product pages, allowing users with … Aug 12, 2026
CVE-2026-16051 CRITICAL 9.8 The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those requests against … Aug 12, 2026
CVE-2026-15388 MEDIUM 4.3 The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability check on its consent-settings REST routes, so they fall back … Aug 12, 2026
CVE-2026-15249 MEDIUM 5.4 The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts it into the page, allowing users with … Aug 12, 2026
CVE-2026-15039 CRITICAL 9.8 The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload … Aug 12, 2026
CVE-2026-14925 HIGH 7.5 The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file download handlers, allowing unauthenticated attackers to download … Aug 12, 2026
CVE-2026-14859 MEDIUM 4.3 The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX actions, allowing any authenticated users such as … Aug 12, 2026
CVE-2026-14858 MEDIUM 4.3 The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing any authenticated users such as Subscribers to read … Aug 12, 2026
CVE-2026-14857 UNKNOWN The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update history to be modified and a notification … Aug 12, 2026
CVE-2026-13613 HIGH 8.8 The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with … Aug 12, 2026
CVE-2026-13612 UNKNOWN The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, allowing authenticated patient-level users to read other … Aug 12, 2026