Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50169
Total
4054
Critical
14909
High
14667
Medium
CVE ID Severity Score Description Published
CVE-2026-16292 UNKNOWN The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to … Aug 02, 2026
CVE-2026-16291 UNKNOWN The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such … Aug 02, 2026
CVE-2026-16285 UNKNOWN The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download … Aug 02, 2026
CVE-2026-16273 UNKNOWN The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users … Aug 02, 2026
CVE-2026-16261 UNKNOWN The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from … Aug 02, 2026
CVE-2026-16256 UNKNOWN The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create … Aug 02, 2026
CVE-2026-16064 UNKNOWN The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking … Aug 02, 2026
CVE-2026-16063 UNKNOWN The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before … Aug 02, 2026
CVE-2026-16062 UNKNOWN The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, … Aug 02, 2026
CVE-2026-16042 UNKNOWN The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush … Aug 02, 2026
CVE-2026-15939 UNKNOWN The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front … Aug 02, 2026
CVE-2026-15385 UNKNOWN The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-menu-item settings; … Aug 02, 2026
CVE-2026-15248 UNKNOWN The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users … Aug 02, 2026
CVE-2026-15241 UNKNOWN The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated … Aug 02, 2026
CVE-2026-15236 UNKNOWN The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing … Aug 02, 2026
CVE-2026-15206 UNKNOWN The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an … Aug 02, 2026
CVE-2026-15151 UNKNOWN The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the … Aug 02, 2026
CVE-2026-14938 UNKNOWN The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user … Aug 02, 2026
CVE-2026-14920 UNKNOWN ## Summary Aug 02, 2026
CVE-2026-14864 UNKNOWN The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the … Aug 02, 2026
CVE-2026-14841 UNKNOWN The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribute in an … Aug 02, 2026
CVE-2026-14817 UNKNOWN The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library … Aug 02, 2026
CVE-2026-13389 UNKNOWN The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete … Aug 02, 2026
CVE-2026-12586 UNKNOWN The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CSRF nonce, allowing … Aug 02, 2026
CVE-2026-11872 UNKNOWN The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates … Aug 02, 2026