CVE Feed

    Dashboard / CVE

    2.7
    Low

    CVE-2026-14821

    Last Modified: 3 Aug 2026

    The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates.

    Published: 28 Jul 2026
    3.5
    Low

    CVE-2026-14819

    Last Modified: 28 Jul 2026

    The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations.

    Published: 28 Jul 2026
    9.8
    Critical

    CVE-2026-14545

    Last Modified: 28 Jul 2026

    The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site.

    Published: 28 Jul 2026
    7.2
    High

    CVE-2026-16585

    Last Modified: 28 Jul 2026

    The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_sticker function in all versions up to, and including, 2.15.19. This makes it possible for authenticated attackers, with administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The prefix check intended to restrict deletion to the uploads directory can be bypassed by crafting a URL that begins with the legitimate uploads base URL but embeds ../ traversal sequences in the path portion, as the normalize_sticker function only applies esc_url_raw(), which does not strip ../ sequences, allowing the traversal payload to be stored verbatim in WordPress options.

    Published: 28 Jul 2026
    4.9
    Medium

    CVE-2026-16811

    Last Modified: 28 Jul 2026

    The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 28 Jul 2026
    4.3
    Medium

    CVE-2026-16587

    Last Modified: 28 Jul 2026

    The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the site's stored MailUp OAuth tokens in the adfoin_mailup_keys option with attacker-controlled tokens, hijacking future form-submission data to a MailUp account they control or nulling the tokens to break the integration entirely. This is exploitable by any authenticated user who can reach /wp-admin/profile.php, as admin_init fires for all logged-in users visiting any wp-admin page.

    Published: 28 Jul 2026
    4.3
    Medium

    CVE-2026-15136

    Last Modified: 28 Jul 2026

    The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3.7. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for unauthenticated attackers to permanently delete or forcibly resolve arbitrary GDPR data request records stored in the wpl_data_req table via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 28 Jul 2026
    4.3
    Medium

    CVE-2026-16797

    Last Modified: 28 Jul 2026

    The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.5 via the 'optionSection' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to read arbitrary wp_options rows — including internal plugin news feed data, WooCommerce block pattern transients, and third-party configuration records — whose values are stored as arrays-of-arrays containing 'title' keys, enabling cross-plugin data leakage.

    Published: 28 Jul 2026
    7.5
    High

    CVE-2026-14490

    Last Modified: 28 Jul 2026

    The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 0.0.7. The vulnerability exists because the plugin stores its HMAC signing key and per-step restore token as dotfiles inside a publicly accessible subdirectory of the WordPress uploads folder — without any `.htaccess` or index file protection — and the `demi_restore_step` AJAX handler, registered for unauthenticated callers, explicitly accepts possession of the on-disk signing key as a standalone alternative to WordPress capability and nonce checks; an unauthenticated attacker who retrieves the exposed key can forge a valid signed state envelope to invoke `CleanDir::execute()` with a caller-supplied absolute path that is subject to no allow-list or path-canonicalization check. This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server.

    Published: 28 Jul 2026
    5.3
    Medium

    CVE-2026-15012

    Last Modified: 28 Jul 2026

    The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Copy in all versions up to, and including, 0.0.8 via the handle_restore_step function. This is due to missing HTTP access controls on the wp-content/uploads/demi-backup-state/ directory, which exposes the cryptographic restore key used to both authenticate the unauthenticated AJAX handler and forge signed restore-state envelopes. This makes it possible for unauthenticated attackers to copy arbitrary files to attacker-controlled destinations on the server. An active restore operation must have been initiated, which writes the .restore_key and .restore_step_token files to the public upload directory, before the exposed secrets can be harvested and chained to achieve unauthenticated arbitrary file copy.

    Published: 28 Jul 2026
    6.5
    Medium

    CVE-2026-6251

    Last Modified: 28 Jul 2026

    The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and including 3.5.5. This is due to the fetch_custom_field() function in admin/class-admin-base.php retrieving the widget_id POST parameter via filter_input(INPUT_POST, ...) and directly concatenating the value into a raw SQL query in a numeric context without using $wpdb->prepare() or any integer casting. Additionally, the nonce verification check is performed after the SQL query has already executed, providing no protection against the injection. This makes it possible for authenticated attackers with subscriber-level access and above to inject arbitrary SQL commands, potentially leading to unauthorized extraction of sensitive database contents including user credentials and configuration data.

    Published: 28 Jul 2026
    5.3
    Medium

    CVE-2026-12124

    Last Modified: 28 Jul 2026

    The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the serveTemplatePdfAjax() function and the serveTemplatePdf() REST route (which is registered with `permission_callback => '__return_true'`) in versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to download stored template PDFs — which may contain customer PII, invoice, order, and certificate data — by requesting the publicly registered admin-ajax action `pdfdraft_embed_pdf` or the REST endpoint `/wp-json/pdfdraft/v1/embed-pdf/templates/{slug}/pdf` with a known or guessable design slug, bypassing the plugin's own .

    Published: 28 Jul 2026
    5.3
    Medium

    CVE-2026-17528

    Last Modified: 4 Aug 2026

    Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element. An attacker can supply a malicious payload that is rendered directly into the DOM without proper sanitization, causing arbitrary script execution in a victim’s browser when they view or interact with the affected page.

    Published: 28 Jul 2026
    8.7
    High

    CVE-2026-17524

    Last Modified: 1 Aug 2026

    Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extraction process. An attacker can bypass security checks designed to prevent directory traversal. The intended security function, isOutsideTargetFolder, only checks and caches the path status when the initial directory symlink is created during the first extraction.

    Published: 28 Jul 2026
    Unknown

    CVE-2026-51274

    Last Modified: 1 Aug 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 28 Jul 2026
    Unknown

    CVE-2026-51271

    Last Modified: 1 Aug 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 28 Jul 2026
    Unknown

    CVE-2026-51266

    Last Modified: 1 Aug 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 28 Jul 2026
    Unknown

    CVE-2026-51261

    Last Modified: 1 Aug 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 28 Jul 2026
    8.8
    High

    CVE-2026-51275

    Last Modified: 31 Jul 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 28 Jul 2026
    9.8
    Critical

    CVE-2026-51263

    Last Modified: 31 Jul 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 28 Jul 2026
    9.4
    Critical

    CVE-2026-51260

    Last Modified: 31 Jul 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 28 Jul 2026
    9.8
    Critical

    CVE-2026-51259

    Last Modified: 31 Jul 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 28 Jul 2026
    Unknown

    CVE-2026-51254

    Last Modified: 31 Jul 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 28 Jul 2026
    Unknown

    CVE-2026-51273

    Last Modified: 1 Aug 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 28 Jul 2026
    Unknown

    CVE-2026-51270

    Last Modified: 1 Aug 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 28 Jul 2026
    Unknown

    CVE-2026-51268

    Last Modified: 1 Aug 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 28 Jul 2026
    9.8
    Critical

    CVE-2026-51267

    Last Modified: 31 Jul 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 28 Jul 2026
    Unknown

    CVE-2026-51251

    Last Modified: 1 Aug 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 28 Jul 2026
    8.8
    High

    CVE-2026-51269

    Last Modified: 31 Jul 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 28 Jul 2026
    Unknown

    CVE-2026-51252

    Last Modified: 1 Aug 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 28 Jul 2026
    6.5
    Medium

    CVE-2026-65448

    Last Modified: 28 Jul 2026

    Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner &#8211; AcyChecker <= 1.8.1 versions.

    Published: 27 Jul 2026
    7.1
    High

    CVE-2026-65447

    Last Modified: 28 Jul 2026

    Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.

    Published: 27 Jul 2026
    7.1
    High

    CVE-2026-65446

    Last Modified: 28 Jul 2026

    Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.

    Published: 27 Jul 2026
    6.5
    Medium

    CVE-2026-65445

    Last Modified: 28 Jul 2026

    Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.

    Published: 27 Jul 2026
    7.1
    High

    CVE-2026-65443

    Last Modified: 28 Jul 2026

    Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.

    Published: 27 Jul 2026
    7.2
    High

    CVE-2026-65442

    Last Modified: 28 Jul 2026

    Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.

    Published: 27 Jul 2026
    7.1
    High

    CVE-2026-65441

    Last Modified: 28 Jul 2026

    Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.

    Published: 27 Jul 2026
    7.1
    High

    CVE-2026-65440

    Last Modified: 28 Jul 2026

    Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.

    Published: 27 Jul 2026
    7.1
    High

    CVE-2026-65439

    Last Modified: 28 Jul 2026

    Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.

    Published: 27 Jul 2026
    7.1
    High

    CVE-2026-65438

    Last Modified: 28 Jul 2026

    Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.

    Published: 27 Jul 2026
    7.1
    High

    CVE-2026-65437

    Last Modified: 28 Jul 2026

    Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.

    Published: 27 Jul 2026
    7.1
    High

    CVE-2026-61957

    Last Modified: 28 Jul 2026

    Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.

    Published: 27 Jul 2026
    7.2
    High

    CVE-2026-61953

    Last Modified: 28 Jul 2026

    Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.

    Published: 27 Jul 2026
    7.5
    High

    CVE-2026-66473

    Last Modified: 28 Jul 2026

    Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.

    Published: 27 Jul 2026
    5.1
    Medium

    CVE-2026-53669

    Last Modified: 28 Jul 2026

    React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in <Link> and useNavigate. This issue is a follow up to CVE-2025-68470 and has been fixed in version 7.18.0.

    Published: 27 Jul 2026
    8.7
    High

    CVE-2026-55685

    Last Modified: 28 Jul 2026

    React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue is a follow up to CVE-2026-42342, and does not does not impact React Router applications using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>). This issue has been fixed in version 7.18.0.

    Published: 27 Jul 2026
    6.9
    Medium

    CVE-2026-53668

    Last Modified: 28 Jul 2026

    React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site or that exploits an XSS vector.This issue has been fixed in version 7.13.0.

    Published: 27 Jul 2026
    6.9
    Medium

    CVE-2026-59240

    Last Modified: 28 Jul 2026

    The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` method at endpoint `GET /notification/delete/{id}`. The flaw allows any authenticated user, regardless of company or permissions, to delete notifications belonging to any other user in the system. The controller retrieves the target record with `Notification::findOrFail($id)` and deletes it without validating `user_id` or `company_id` ownership, unlike the sibling `SetNotificationReadAjaxController`, which correctly scopes lookups by `Auth::id()`. Because notification identifiers are sequential, an attacker can iterate over IDs to systematically delete notifications belonging to any user, denying them visibility of ticket alerts, task assignments, and other system events.

    Published: 27 Jul 2026
    6.9
    Medium

    CVE-2026-53667

    Last Modified: 28 Jul 2026

    React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This issue has been fixed in version 7.18.0.

    Published: 27 Jul 2026
    6.1
    Medium

    CVE-2026-53666

    Last Modified: 28 Jul 2026

    React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker to trigger unexpected constructor execution on the client, which would in turn trigger an outbound network request. This is only possible with very specific (and unlikely) application-layer code. Note that this does not impact an application if it is using Declarative Mode. It only impacts Framework Mode and Data Mode applications that perform manual SSR/hydration. This issue has been fixed in version 7.18.0.

    Published: 27 Jul 2026