Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50169
Total
4054
Critical
14909
High
14667
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-14822 | UNKNOWN | — | The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users … | Aug 01, 2026 |
| CVE-2026-14596 | UNKNOWN | — | The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the base of the password-reset link … | Aug 01, 2026 |
| CVE-2026-14561 | UNKNOWN | — | The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a … | Aug 01, 2026 |
| CVE-2026-14315 | UNKNOWN | — | The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users … | Aug 01, 2026 |
| CVE-2026-14309 | UNKNOWN | — | The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, … | Aug 01, 2026 |
| CVE-2026-14292 | UNKNOWN | — | The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with … | Aug 01, 2026 |
| CVE-2026-14214 | UNKNOWN | — | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a … | Aug 01, 2026 |
| CVE-2026-14197 | UNKNOWN | — | The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to … | Aug 01, 2026 |
| CVE-2026-14195 | UNKNOWN | — | The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role … | Aug 01, 2026 |
| CVE-2026-13729 | UNKNOWN | — | The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrative create and delete actions, allowing attackers to … | Aug 01, 2026 |
| CVE-2026-13725 | UNKNOWN | — | The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX … | Aug 01, 2026 |
| CVE-2026-13604 | UNKNOWN | — | The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end page, that … | Aug 01, 2026 |
| CVE-2026-13596 | UNKNOWN | — | The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated … | Aug 01, 2026 |
| CVE-2026-13329 | UNKNOWN | — | The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment … | Aug 01, 2026 |
| CVE-2026-13158 | UNKNOWN | — | The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing … | Aug 01, 2026 |
| CVE-2026-13157 | UNKNOWN | — | The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing … | Aug 01, 2026 |
| CVE-2026-12966 | UNKNOWN | — | The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers … | Aug 01, 2026 |
| CVE-2026-12696 | UNKNOWN | — | The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the … | Aug 01, 2026 |
| CVE-2026-11882 | UNKNOWN | — | The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes to the initiating user session, allowing … | Aug 01, 2026 |
| CVE-2026-10827 | UNKNOWN | — | The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before using them to build the CSS it outputs … | Aug 01, 2026 |
| CVE-2025-15669 | UNKNOWN | — | The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege … | Aug 01, 2026 |
| CVE-2026-3141 | CRITICAL | 9.1 | The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in … | Aug 01, 2026 |
| CVE-2026-7623 | MEDIUM | 6.4 | The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headingWrapper' parameter … | Aug 01, 2026 |
| CVE-2026-15414 | HIGH | 8.8 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` … | Aug 01, 2026 |
| CVE-2026-15403 | MEDIUM | 4.9 | The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parameter in all versions up to, … | Aug 01, 2026 |