Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50589
Total
4065
Critical
14978
High
14744
Medium
CVE ID Severity Score Description Published
CVE-2026-14930 HIGH 7.5 The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users … Jul 31, 2026
CVE-2026-14929 MEDIUM 4.3 The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and … Jul 31, 2026
CVE-2026-14928 MEDIUM 6.5 The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing … Jul 31, 2026
CVE-2026-14927 LOW 3.7 The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed … Jul 31, 2026
CVE-2026-14922 MEDIUM 6.1 WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 through a decode-after-sanitize (double-encoding) flaw in the … Jul 31, 2026
CVE-2026-14921 MEDIUM 6.1 The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_VC_Addons::uavc_link_init(), Jul 31, 2026
CVE-2026-14919 CRITICAL 9.8 The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied … Jul 31, 2026
CVE-2026-14862 LOW 3.7 The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file … Jul 31, 2026
CVE-2026-14849 LOW 3.7 The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the … Jul 31, 2026
CVE-2026-14847 MEDIUM 4.3 The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its payment-related AJAX actions, allowing any authenticated … Jul 31, 2026
CVE-2026-14845 MEDIUM 6.1 The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor requests before storing it and later outputting it in … Jul 31, 2026
CVE-2026-14843 MEDIUM 5.3 The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated … Jul 31, 2026
CVE-2026-14834 MEDIUM 6.5 The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the … Jul 31, 2026
CVE-2026-14833 MEDIUM 6.8 The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendering it into the image lightbox caption … Jul 31, 2026
CVE-2026-14830 HIGH 7.5 The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order … Jul 31, 2026
CVE-2026-14554 MEDIUM 6.5 The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing users with … Jul 31, 2026
CVE-2026-14483 CRITICAL 9.8 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, … Jul 31, 2026
CVE-2026-14333 HIGH 7.5 The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing … Jul 31, 2026
CVE-2026-14319 HIGH 7.5 The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve … Jul 31, 2026
CVE-2026-14317 MEDIUM 5.3 The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part … Jul 31, 2026
CVE-2026-13609 HIGH 8.8 The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags … Jul 31, 2026
CVE-2026-13393 LOW 3.5 The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the … Jul 31, 2026
CVE-2026-13392 HIGH 7.2 The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim … Jul 31, 2026
CVE-2026-12721 HIGH 8.6 The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, … Jul 31, 2026
CVE-2026-12720 HIGH 7.5 The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to … Jul 31, 2026