CVE-2026-73398
Last Modified: 18 Aug 2026Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
CVE-2026-73397
Last Modified: 21 Aug 2026Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
CVE-2026-73396
Last Modified: 21 Aug 2026Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
CVE-2026-73395
Last Modified: 24 Aug 2026Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.
CVE-2026-73393
Last Modified: 18 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
CVE-2026-73392
Last Modified: 11 Sept 2026This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-12965.
CVE-2026-73383
Last Modified: 18 Aug 2026Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.
CVE-2026-73382
Last Modified: 18 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
CVE-2026-73381
Last Modified: 24 Aug 2026Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
CVE-2026-73380
Last Modified: 24 Aug 2026Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
CVE-2026-73379
Last Modified: 24 Aug 2026Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
CVE-2026-73378
Last Modified: 24 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions.
CVE-2026-73377
Last Modified: 21 Aug 2026Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
CVE-2026-73376
Last Modified: 21 Aug 2026Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
CVE-2026-73375
Last Modified: 21 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
CVE-2026-73367
Last Modified: 18 Aug 2026Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
CVE-2026-73366
Last Modified: 18 Aug 2026Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
CVE-2026-73365
Last Modified: 24 Aug 2026Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.
CVE-2026-73362
Last Modified: 18 Aug 2026Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions.
CVE-2026-73361
Last Modified: 18 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions.
CVE-2026-73360
Last Modified: 18 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.
CVE-2026-73359
Last Modified: 21 Aug 2026Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.
CVE-2026-73358
Last Modified: 18 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions.
CVE-2026-73356
Last Modified: 18 Aug 2026Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.
CVE-2026-73355
Last Modified: 18 Aug 2026Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
CVE-2026-73352
Last Modified: 18 Aug 2026Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.
CVE-2026-73351
Last Modified: 18 Aug 2026Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.
CVE-2026-73350
Last Modified: 18 Aug 2026Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.
CVE-2026-73348
Last Modified: 18 Aug 2026Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
CVE-2026-73345
Last Modified: 24 Aug 2026Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.
CVE-2026-73343
Last Modified: 18 Aug 2026Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
CVE-2026-75784
Last Modified: 20 Aug 2026A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.
CVE-2026-73342
Last Modified: 21 Aug 2026Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.
CVE-2026-73341
Last Modified: 18 Aug 2026Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
CVE-2026-73339
Last Modified: 18 Aug 2026Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
CVE-2026-73338
Last Modified: 21 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.
CVE-2026-73190
Last Modified: 24 Aug 2026Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.
CVE-2026-73189
Last Modified: 25 Aug 2026This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-14858
CVE-2026-73187
Last Modified: 18 Aug 2026Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
CVE-2026-73181
Last Modified: 21 Aug 2026Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.
CVE-2026-68568
Last Modified: 24 Aug 2026Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.
CVE-2026-68567
Last Modified: 21 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions.
CVE-2026-68565
Last Modified: 18 Aug 2026Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.
CVE-2026-66679
Last Modified: 18 Aug 2026Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions.
CVE-2026-66667
Last Modified: 24 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions.
CVE-2026-66651
Last Modified: 18 Aug 2026Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions.
CVE-2026-66646
Last Modified: 21 Aug 2026Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions.
CVE-2026-66645
Last Modified: 21 Aug 2026Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
CVE-2026-66644
Last Modified: 18 Aug 2026Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions.
CVE-2026-66643
Last Modified: 21 Aug 2026Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.
