CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2026-25330

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in PublishPress PublishPress Authors publishpress-authors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Authors: from n/a through <= 4.10.1.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25329

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.4.

    Published: 19 Feb 2026
    7.5
    High

    CVE-2026-25326

    Last Modified: 16 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PHP Local File Inclusion.This issue affects CMSMasters Content Composer: from n/a through <= 1.4.5.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25325

    Last Modified: 17 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Retrieve Embedded Sensitive Data.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through <= 4.7.8.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25324

    Last Modified: 16 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.4.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25323

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in MiKa OSM osm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects OSM: from n/a through <= 6.1.12.

    Published: 19 Feb 2026
    5.4
    Medium

    CVE-2026-25322

    Last Modified: 16 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in PublishPress PublishPress Revisions revisionary allows Cross Site Request Forgery.This issue affects PublishPress Revisions: from n/a through <= 3.7.22.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25321

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in PSM Plugins SupportCandy supportcandy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SupportCandy: from n/a through <= 3.4.4.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25320

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Cool Plugins Elementor Contact Form DB sb-elementor-contact-form-db allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Contact Form DB: from n/a through <= 2.1.3.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25319

    Last Modified: 16 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wpzita Zita Elementor Site Library zita-site-library allows Cross Site Request Forgery.This issue affects Zita Elementor Site Library: from n/a through <= 1.6.6.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25318

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Wisernotify team WiserReview Product Reviews for WooCommerce wiser-review allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WiserReview Product Reviews for WooCommerce: from n/a through <= 2.9.

    Published: 19 Feb 2026
    7.2
    High

    CVE-2026-25316

    Last Modified: 16 Apr 2026

    Deserialization of Untrusted Data vulnerability in Brainstorm Force CartFlows cartflows allows Object Injection.This issue affects CartFlows: from n/a through <= 2.1.19.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25315

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in hcaptcha hCaptcha for WP hcaptcha-for-forms-and-more allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects hCaptcha for WP: from n/a through <= 4.21.1.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25314

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in WP Messiah TOP Table Of Contents top-table-of-contents allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TOP Table Of Contents: from n/a through <= 1.3.31.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25313

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Shahjahan Jewel FluentForm fluentform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentForm: from n/a through <= 6.1.14.

    Published: 19 Feb 2026
    5.4
    Medium

    CVE-2026-25311

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in 10up Autoshare for Twitter autoshare-for-twitter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoshare for Twitter: from n/a through <= 2.3.1.

    Published: 19 Feb 2026
    4.9
    Medium

    CVE-2026-25310

    Last Modified: 16 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Alobaidi Extend Link extend-link allows Server Side Request Forgery.This issue affects Extend Link: from n/a through <= 2.0.0.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25308

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in wp.insider Simple Membership simple-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Membership: from n/a through <= 4.6.9.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-25307

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows DOM-Based XSS.This issue affects XStore Core: from n/a through < 5.7.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-25305

    Last Modified: 17 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore xstore allows DOM-Based XSS.This issue affects XStore: from n/a through <= 9.6.4.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25008

    Last Modified: 16 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows Retrieve Embedded Sensitive Data.This issue affects Ninja Tables: from n/a through <= 5.2.5.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25006

    Last Modified: 24 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore xstore allows Code Injection.This issue affects XStore: from n/a through <= 9.6.4.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25005

    Last Modified: 16 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.5.

    Published: 19 Feb 2026
    5.9
    Medium

    CVE-2026-25004

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Business Directory cm-business-directory allows Stored XSS.This issue affects CM Business Directory: from n/a through <= 1.5.3.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-25003

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in madalin.ungureanu Client Portal client-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Portal: from n/a through <= 1.2.1.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-25000

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Kraft Plugins Wheel of Life wheel-of-life allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wheel of Life: from n/a through <= 1.2.0.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-24999

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Alma Alma alma-gateway-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Alma: from n/a through <= 5.16.1.

    Published: 19 Feb 2026
    5.9
    Medium

    CVE-2026-24392

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nabil Lemsieh HurryTimer hurrytimer allows Stored XSS.This issue affects HurryTimer: from n/a through <= 2.14.2.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-24375

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in WP Swings Ultimate Gift Cards For WooCommerce woo-gift-cards-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Gift Cards For WooCommerce: from n/a through <= 3.2.4.

    Published: 19 Feb 2026
    7.6
    High

    CVE-2026-23805

    Last Modified: 16 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yoren Chang Media Search Enhanced media-search-enhanced allows SQL Injection.This issue affects Media Search Enhanced: from n/a through <= 0.9.1.

    Published: 19 Feb 2026
    5.4
    Medium

    CVE-2026-23804

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in BBR Plugins Better Business Reviews better-business-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Business Reviews: from n/a through <= 0.1.1.

    Published: 19 Feb 2026
    6.4
    Medium

    CVE-2026-23803

    Last Modified: 24 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Burhan Nasir Smart Auto Upload Images smart-auto-upload-images allows Server Side Request Forgery.This issue affects Smart Auto Upload Images: from n/a through <= 1.2.2.

    Published: 19 Feb 2026
    9.8
    Critical

    CVE-2026-23549

    Last Modified: 16 Apr 2026

    Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.1.1.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-23548

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Designinvento DirectoryPress directorypress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DirectoryPress: from n/a through <= 3.6.25.

    Published: 19 Feb 2026
    7.1
    High

    CVE-2026-23547

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CMSMasters Content Composer: from n/a through <= 2.5.8.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-23545

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aruba HiSpeed Cache: from n/a through <= 3.0.4.

    Published: 19 Feb 2026
    8.8
    High

    CVE-2026-23544

    Last Modified: 16 Apr 2026

    Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects Valenti: from n/a through <= 5.6.3.5.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-23543

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from n/a through <= 6.5.5.

    Published: 19 Feb 2026
    9.8
    Critical

    CVE-2026-23542

    Last Modified: 16 Apr 2026

    Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through <= 7.0.10.

    Published: 19 Feb 2026
    7.5
    High

    CVE-2026-23541

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WPFunnels Mail Mint mail-mint allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Mail Mint: from n/a through <= 1.19.4.

    Published: 19 Feb 2026
    5.3
    Medium

    CVE-2026-22422

    Last Modified: 16 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in wpeverest Everest Forms everest-forms allows Code Injection.This issue affects Everest Forms: from n/a through <= 3.4.1.

    Published: 19 Feb 2026
    7.2
    High

    CVE-2026-22333

    Last Modified: 16 Apr 2026

    Deserialization of Untrusted Data vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare allows Object Injection.This issue affects YITH WooCommerce Compare: from n/a through <= 3.6.0.

    Published: 19 Feb 2026
    8.1
    High

    CVE-2026-26362

    Last Modified: 17 Apr 2026

    Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized modification of critical system files.

    Published: 19 Feb 2026
    4.3
    Medium

    CVE-2026-27056

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in StellarWP iThemes Sync ithemes-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iThemes Sync: from n/a through <= 3.2.8.

    Published: 19 Feb 2026
    6.5
    Medium

    CVE-2026-26361

    Last Modified: 17 Apr 2026

    Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

    Published: 19 Feb 2026
    2.9
    Low

    CVE-2026-2711

    Last Modified: 18 Apr 2026

    A vulnerability has been found in zhutoutoutousan worldquant-miner up to 1.0.9. The impacted element is an unknown function of the file worldquant-miner-master/agent-dify-api/core/helper/ssrf_proxy.py of the component URL Handler. The manipulation of the argument make_request leads to server-side request forgery. The attack can be initiated remotely. The attack's complexity is rated as high. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 19 Feb 2026
    9.8
    Critical

    CVE-2026-1994

    Last Modified: 15 Apr 2026

    The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 260127. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

    Published: 19 Feb 2026
    10
    Critical

    CVE-2026-2731

    Last Modified: 17 Apr 2026

    Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allows unauthenticated attackers to execute code via simple web requests

    Published: 19 Feb 2026
    2
    Low

    CVE-2026-2709

    Last Modified: 18 Apr 2026

    A flaw has been found in busy up to 2.5.5. The affected element is an unknown function of the file source-code/busy-master/src/server/app.js of the component Callback Handler. Executing a manipulation of the argument state can lead to open redirect. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 19 Feb 2026
    2.1
    Low

    CVE-2026-2706

    Last Modified: 17 Apr 2026

    A flaw has been found in code-projects Patient Record Management System 1.0. This affects an unknown function of the file /fecalysis_not.php. This manipulation of the argument comp_id causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.

    Published: 19 Feb 2026