Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49853
Total
4028
Critical
14819
High
14575
Medium
CVE ID Severity Score Description Published
CVE-2026-16746 UNKNOWN The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, … Aug 05, 2026
CVE-2026-16736 HIGH 7.5 The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create … Aug 05, 2026
CVE-2026-16613 MEDIUM 4.3 The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, … Aug 05, 2026
CVE-2026-16605 HIGH 7.2 The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated … Aug 05, 2026
CVE-2026-16604 HIGH 7.5 The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the … Aug 05, 2026
CVE-2026-16603 HIGH 7.5 The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated users to read the full … Aug 05, 2026
CVE-2026-16602 HIGH 7.5 The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint, allowing unauthenticated users to … Aug 05, 2026
CVE-2026-16583 MEDIUM 6.1 The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded SVG files … Aug 05, 2026
CVE-2026-16573 HIGH 7.5 The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upload a crafted SVG … Aug 05, 2026
CVE-2026-16561 HIGH 7.5 The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve … Aug 05, 2026
CVE-2026-16055 HIGH 7.5 The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after … Aug 05, 2026
CVE-2026-16036 HIGH 7.5 The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing … Aug 05, 2026
CVE-2026-15372 HIGH 7.5 The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing … Aug 05, 2026
CVE-2026-15360 CRITICAL 9.1 The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated … Aug 05, 2026
CVE-2026-15230 HIGH 8.1 The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing … Aug 05, 2026
CVE-2026-15210 CRITICAL 9.1 The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time … Aug 05, 2026
CVE-2026-14553 HIGH 8.1 The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the original file extension, allowing any … Aug 05, 2026
CVE-2025-15677 LOW 3.5 The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users … Aug 05, 2026
CVE-2026-9273 CRITICAL 9.3 The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all … Aug 05, 2026
CVE-2026-8790 MEDIUM 6.1 The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in all versions up … Aug 05, 2026
CVE-2026-8761 HIGH 8.8 The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization … Aug 05, 2026
CVE-2026-7753 MEDIUM 6.5 The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cost-calculator-custom-export-run` AJAX … Aug 05, 2026
CVE-2026-71192 UNKNOWN In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An attacker can … Aug 05, 2026
CVE-2026-71191 UNKNOWN In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An … Aug 05, 2026
CVE-2026-71190 UNKNOWN In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The "qdtext" pattern (?:[^"]|\\.)* allows … Aug 05, 2026