Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50589
Total
4065
Critical
14978
High
14744
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-14930 | HIGH | 7.5 | The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users … | Jul 31, 2026 |
| CVE-2026-14929 | MEDIUM | 4.3 | The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and … | Jul 31, 2026 |
| CVE-2026-14928 | MEDIUM | 6.5 | The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing … | Jul 31, 2026 |
| CVE-2026-14927 | LOW | 3.7 | The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed … | Jul 31, 2026 |
| CVE-2026-14922 | MEDIUM | 6.1 | WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 through a decode-after-sanitize (double-encoding) flaw in the … | Jul 31, 2026 |
| CVE-2026-14921 | MEDIUM | 6.1 | The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_VC_Addons::uavc_link_init(), | Jul 31, 2026 |
| CVE-2026-14919 | CRITICAL | 9.8 | The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied … | Jul 31, 2026 |
| CVE-2026-14862 | LOW | 3.7 | The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file … | Jul 31, 2026 |
| CVE-2026-14849 | LOW | 3.7 | The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the … | Jul 31, 2026 |
| CVE-2026-14847 | MEDIUM | 4.3 | The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its payment-related AJAX actions, allowing any authenticated … | Jul 31, 2026 |
| CVE-2026-14845 | MEDIUM | 6.1 | The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor requests before storing it and later outputting it in … | Jul 31, 2026 |
| CVE-2026-14843 | MEDIUM | 5.3 | The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated … | Jul 31, 2026 |
| CVE-2026-14834 | MEDIUM | 6.5 | The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the … | Jul 31, 2026 |
| CVE-2026-14833 | MEDIUM | 6.8 | The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendering it into the image lightbox caption … | Jul 31, 2026 |
| CVE-2026-14830 | HIGH | 7.5 | The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order … | Jul 31, 2026 |
| CVE-2026-14554 | MEDIUM | 6.5 | The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing users with … | Jul 31, 2026 |
| CVE-2026-14483 | CRITICAL | 9.8 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, … | Jul 31, 2026 |
| CVE-2026-14333 | HIGH | 7.5 | The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing … | Jul 31, 2026 |
| CVE-2026-14319 | HIGH | 7.5 | The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve … | Jul 31, 2026 |
| CVE-2026-14317 | MEDIUM | 5.3 | The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part … | Jul 31, 2026 |
| CVE-2026-13609 | HIGH | 8.8 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags … | Jul 31, 2026 |
| CVE-2026-13393 | LOW | 3.5 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the … | Jul 31, 2026 |
| CVE-2026-13392 | HIGH | 7.2 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim … | Jul 31, 2026 |
| CVE-2026-12721 | HIGH | 8.6 | The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, … | Jul 31, 2026 |
| CVE-2026-12720 | HIGH | 7.5 | The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to … | Jul 31, 2026 |