CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2026-58084

    Last Modified: 31 Aug 2026

    To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer's clock. For a timer using CLOCK_TAI this can fail when no TAI offset has been configured, but the error return was not checked, so the uninitialized output buffer was copied to userspace. An unprivileged local user can obtain uninitialized kernel stack memory by creating a POSIX timer with CLOCK_TAI and calling timer_settime(2), potentially disclosing sensitive kernel data.

    Published: 19 Aug 2026
    6.1
    Medium

    CVE-2026-75900

    Last Modified: 21 Aug 2026

    An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffer length against sizeof(bh), where bh is a pointer, instead of sizeof(*bh), the actual struct size. This allows an undersized buffer to pass validation, causing a 2-byte heap overread on 64-bit systems (6 bytes on 32-bit) when accessing the totlen field. This may cause daemon termination on some platforms and leaks heap data to the log.

    Published: 19 Aug 2026
    8.4
    High

    CVE-2026-58083

    Last Modified: 31 Aug 2026

    While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be enqueued on the kqueue's active list before the copy was complete. The copy routine did not account for this and could enqueue the new knote a second time, corrupting the active list. In addition, the copy routine did not hold the appropriate locks while reading knote state, allowing further races. An unprivileged local user can trigger a use-after-free in the kernel, potentially leading to privilege escalation.

    Published: 19 Aug 2026
    7.5
    High

    CVE-2026-75589

    Last Modified: 26 Aug 2026

    Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. Each of the three compares the signature carried in the message against the locally computed one with the eq operator, which returns as soon as the two strings differ. The time taken to reject a signature varies with the length of the matching prefix. RSA-SHA1 is not affected, as it verifies through the RSA key object rather than by comparing strings. A client that can submit messages and time the replies may recover a valid signature one byte at a time rather than searching the whole signature space. Under PLAINTEXT the value compared against is the signature key itself, so the search recovers consumer_secret and token_secret.

    Published: 19 Aug 2026
    9.8
    Critical

    CVE-2026-58082

    Last Modified: 31 Aug 2026

    The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate character output. Some ISO-2022 variants can require up to 10 bytes per character, in which case conversions can trigger a stack buffer overflow of up to four bytes. An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses one of the affected encoding modules.

    Published: 19 Aug 2026
    9.8
    Critical

    CVE-2026-58081

    Last Modified: 31 Aug 2026

    Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters. An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses one of the affected encoding modules.

    Published: 19 Aug 2026
    9.8
    Critical

    CVE-2026-72889

    Last Modified: 26 Aug 2026

    Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is required on every request, so the algorithm used to check a signature is chosen by whoever sent it, and nothing lets the verifying party pin the method instead. When a message names HMAC-SHA1 or HMAC-SHA256, the key is derived from consumer_secret and token_secret rather than from the key the provider deployed. A provider deployed on RSA-SHA1 holds only the consumer public key, and RFC 5849 does not use consumer_secret for that method, so the required parameter is filled with a placeholder. A client that names HMAC-SHA1 instead has its signature checked against that placeholder, so a guessable one is enough to forge requests for any consumer key and token.

    Published: 19 Aug 2026
    5.5
    Medium

    CVE-2026-49425

    Last Modified: 31 Aug 2026

    The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first zero the stack struct. An unprivileged user may observe a small amount of uninitialized kernel stack data, which may contain sensitive information.

    Published: 19 Aug 2026
    5.5
    Medium

    CVE-2026-49424

    Last Modified: 31 Aug 2026

    The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did not first zero the stack struct. An unprivileged user may observe 104 bytes of uninitialized kernel stack data, which may contain sensitive information.

    Published: 19 Aug 2026
    3.3
    Low

    CVE-2026-49423

    Last Modified: 31 Aug 2026

    When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremented the iovec index for every mbuf in the chain, including mbufs that were skipped because they contained only TLS header bytes. This left uninitialized entries in the iovec array. The iovec array was allocated without zeroing. A remote TLS peer can cause the kernel to read from uninitialized iovec entries during HMAC computation, resulting in a kernel panic. The peer must be able to control TCP segmentation such that the first mbuf of a CBC record contains only the 5-byte TLS record header.

    Published: 19 Aug 2026
    7.2
    High

    CVE-2026-75981

    Last Modified: 19 Aug 2026

    The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting in versions up to and including 3.2.5. The special gettext markers '#!trpst#' and '#!trpen#' are unconditionally rewritten to '<' and '>' by translate_page() in includes/class-translation-render.php (lines 538-539). Because those markers are plain text with no HTML-special characters, an unauthenticated attacker can embed them in a comment; the markers survive wp_kses, and when the post is viewed in a secondary language the substitution turns the attacker's '#!trpst#img ... #!trpen#' into a real <img> tag. remove_tags_from_output() only strips <script>/<style>, so an <img onerror=...> executes in the visitor's browser.

    Published: 19 Aug 2026
    6.4
    Medium

    CVE-2026-15446

    Last Modified: 21 Aug 2026

    The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit is achieved by embedding a crafted img element with class='lazyload' and a data-script attribute pointing to an attacker-controlled URL in post content, which the plugin's bundled lazysizes ls.unveilhooks addon then uses to dynamically create and insert a script element into the DOM at page view time.

    Published: 19 Aug 2026
    7.2
    High

    CVE-2026-15780

    Last Modified: 19 Aug 2026

    The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions up to, and including, 14.16.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload can be planted without authentication via the public /wp-statistics/v2/hit REST endpoint, because the required signature is exposed on the public homepage and a base64-encoded page_uri POST parameter overrides the previously sanitized REQUEST_URI, allowing the malicious utm_campaign value to bypass sanitization and be stored in the database.

    Published: 19 Aug 2026
    3.3
    Low

    CVE-2026-49426

    Last Modified: 1 Sept 2026

    When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed the return value of an internal setup function to AUDIT_SYSCALL_EXIT() rather than the actual result of the executed system call. As a result, committed audit records for system calls which returned an error do not reflect the true outcome of the operation. That is, they indicate that the operation succeeded when it in fact failed. Audit records for system calls executed via ptrace(PT_SC_REMOTE) may show an incorrect error status. An attacker with the ability to debug a process could use this to produce misleading audit trails, potentially undermining audit-based Intrusion Detection Systems (IDS).

    Published: 19 Aug 2026
    6.9
    Medium

    CVE-2026-8810

    Last Modified: 21 Aug 2026

    On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.

    Published: 19 Aug 2026
    8.8
    High

    CVE-2026-19842

    Last Modified: 19 Aug 2026

    The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, and offers an administrator a one-click control that promotes that stored certificate to the site's trusted signing certificate, allowing unauthenticated attackers to have a certificate of their own trusted and then authenticate as any user, including an administrator.

    Published: 19 Aug 2026
    5.4
    Medium

    CVE-2026-19782

    Last Modified: 19 Aug 2026

    The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJAX action, allowing any authenticated user, such as a subscriber, to retrieve the email addresses of all registered users.

    Published: 19 Aug 2026
    5.3
    Medium

    CVE-2026-19709

    Last Modified: 21 Aug 2026

    The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated attackers to reach its REST routes and disclose any user's membership plan details on sites where the API has been enabled but no keys were ever generated.

    Published: 19 Aug 2026
    6.5
    Medium

    CVE-2026-19417

    Last Modified: 19 Aug 2026

    The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level users to download any file in the media library, including other patients' uploaded medical reports.

    Published: 19 Aug 2026
    4.3
    Medium

    CVE-2026-19416

    Last Modified: 19 Aug 2026

    The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment being modified, allowing authenticated patient-level users to cancel and reschedule other patients' appointments.

    Published: 19 Aug 2026
    2.7
    Low

    CVE-2026-19406

    Last Modified: 19 Aug 2026

    The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses.

    Published: 19 Aug 2026
    7.1
    High

    CVE-2026-19056

    Last Modified: 19 Aug 2026

    The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one of its administrative pages, leading to reflected Cross-Site Scripting that runs in the session of an administrator induced to submit a crafted request.

    Published: 19 Aug 2026
    7.1
    High

    CVE-2026-19055

    Last Modified: 19 Aug 2026

    The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes on its public pages, leading to reflected Cross-Site Scripting that can be triggered against any visitor, including a logged-in administrator.

    Published: 19 Aug 2026
    9
    Critical

    CVE-2026-18937

    Last Modified: 19 Aug 2026

    The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary code on the server when a classic (non-block) is active.

    Published: 19 Aug 2026
    5.3
    Medium

    CVE-2026-18779

    Last Modified: 19 Aug 2026

    The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records.

    Published: 19 Aug 2026
    5.3
    Medium

    CVE-2026-18778

    Last Modified: 20 Aug 2026

    The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to retrieve the personal information of customers who booked an appointment, including their name, email address, phone number and postal address.

    Published: 19 Aug 2026
    5.3
    Medium

    CVE-2026-18777

    Last Modified: 19 Aug 2026

    The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to change the status of arbitrary appointments, as well as to trigger notification emails to the affected customers.

    Published: 19 Aug 2026
    9.8
    Critical

    CVE-2026-18776

    Last Modified: 19 Aug 2026

    The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including administrators, and subsequently take over their account via the password reset flow.

    Published: 19 Aug 2026
    5.4
    Medium

    CVE-2026-18466

    Last Modified: 19 Aug 2026

    The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with a Subscriber account to create an unlimited number of options in the database, each of which is loaded on every page request.

    Published: 19 Aug 2026
    5.3
    Medium

    CVE-2026-18231

    Last Modified: 20 Aug 2026

    The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database rows, allowing unauthenticated attackers to retrieve the usernames and email addresses of users holding the WP Directory Kit WordPress plugin before 1.5.7's own roles.

    Published: 19 Aug 2026
    6.8
    Medium

    CVE-2026-18202

    Last Modified: 19 Aug 2026

    The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing users with the upload files capability, such as Authors, to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting). On multisite, this also overrides an upload-type restriction set by the network administrator.

    Published: 19 Aug 2026
    10
    Critical

    CVE-2026-18051

    Last Modified: 19 Aug 2026

    The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can strip hardening rules that other security measures rely on.

    Published: 19 Aug 2026
    9.8
    Critical

    CVE-2026-18031

    Last Modified: 19 Aug 2026

    The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated with the referenced order, allowing unauthenticated attackers to log in as any registered user, including an administrator.

    Published: 19 Aug 2026
    7.2
    High

    CVE-2026-17565

    Last Modified: 19 Aug 2026

    The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back.

    Published: 19 Aug 2026
    4.3
    Medium

    CVE-2026-16979

    Last Modified: 20 Aug 2026

    The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.

    Published: 19 Aug 2026
    8.6
    High

    CVE-2026-16950

    Last Modified: 19 Aug 2026

    The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

    Published: 19 Aug 2026
    8.8
    High

    CVE-2026-16617

    Last Modified: 19 Aug 2026

    The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the list.

    Published: 19 Aug 2026
    8.6
    High

    CVE-2026-16616

    Last Modified: 20 Aug 2026

    The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to read arbitrary files on the server and to relocate critical files out of the web root, leading to sensitive information disclosure and potential site takeover.

    Published: 19 Aug 2026
    7.1
    High

    CVE-2026-16570

    Last Modified: 19 Aug 2026

    The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers to perform Reflected Cross-Site Scripting attacks against logged-in users such as administrators who are tricked into opening a crafted link.

    Published: 19 Aug 2026
    5.3
    Medium

    CVE-2026-16058

    Last Modified: 20 Aug 2026

    The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers that are reachable by unauthenticated users, allowing anyone to read the store's order totals and its vendors' earnings, balance ledgers, and withdrawal histories by iterating identifiers.

    Published: 19 Aug 2026
    6.8
    Medium

    CVE-2026-15253

    Last Modified: 19 Aug 2026

    The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in the media library list view, allowing users with the Author role and above to inject arbitrary web scripts that are executed in the browser of a higher privileged user who views the media library.

    Published: 19 Aug 2026
    7.5
    High

    CVE-2026-14861

    Last Modified: 19 Aug 2026

    The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them, including administrators, out of their accounts.

    Published: 19 Aug 2026
    2.7
    Low

    CVE-2026-14826

    Last Modified: 21 Aug 2026

    The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient addresses, of quizzes created by other users.

    Published: 19 Aug 2026
    2.7
    Low

    CVE-2026-14825

    Last Modified: 21 Aug 2026

    The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users.

    Published: 19 Aug 2026
    8.8
    High

    CVE-2026-14334

    Last Modified: 21 Aug 2026

    The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary JavaScript when the SVG is opened, including in the session of an administrator who reviews the submitted booking.

    Published: 19 Aug 2026
    4.7
    Medium

    CVE-2026-14287

    Last Modified: 21 Aug 2026

    The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated request handler and does not escape attacker-supplied stylesheet content before rendering it into the page head, allowing an unauthenticated attacker to store markup that executes as JavaScript in the browser of anonymous visitors to an affected page.

    Published: 19 Aug 2026
    4.3
    Medium

    CVE-2026-14196

    Last Modified: 19 Aug 2026

    The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review before allowing it to be unapproved or deleted, allowing any vendor to modify or permanently delete reviews belonging to other vendors' stores.

    Published: 19 Aug 2026
    6.5
    Medium

    CVE-2026-13175

    Last Modified: 19 Aug 2026

    The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with contributor-level access and above to alter or delete schedule entries created by other users.

    Published: 19 Aug 2026
    7.2
    High

    CVE-2026-13174

    Last Modified: 19 Aug 2026

    The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts.

    Published: 19 Aug 2026
    2.7
    Low

    CVE-2026-13173

    Last Modified: 19 Aug 2026

    The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and metadata.

    Published: 19 Aug 2026