CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2026-57717

    Last Modified: 2 Aug 2026

    Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.

    Published: 23 Jul 2026
    5.3
    Medium

    CVE-2026-57716

    Last Modified: 23 Jul 2026

    Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.

    Published: 23 Jul 2026
    7.1
    High

    CVE-2026-57704

    Last Modified: 23 Jul 2026

    Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.

    Published: 23 Jul 2026
    6.3
    Medium

    CVE-2026-57703

    Last Modified: 23 Jul 2026

    Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.

    Published: 23 Jul 2026
    7.1
    High

    CVE-2026-57701

    Last Modified: 2 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.

    Published: 23 Jul 2026
    7.1
    High

    CVE-2026-57699

    Last Modified: 23 Jul 2026

    Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.

    Published: 23 Jul 2026
    7.1
    High

    CVE-2026-57696

    Last Modified: 23 Jul 2026

    Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.

    Published: 23 Jul 2026
    7.1
    High

    CVE-2026-57428

    Last Modified: 23 Jul 2026

    Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.

    Published: 23 Jul 2026
    7.1
    High

    CVE-2026-57427

    Last Modified: 23 Jul 2026

    Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.

    Published: 23 Jul 2026
    6.5
    Medium

    CVE-2026-57425

    Last Modified: 23 Jul 2026

    Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.

    Published: 23 Jul 2026
    7.1
    High

    CVE-2026-57397

    Last Modified: 23 Jul 2026

    Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions.

    Published: 23 Jul 2026
    6.5
    Medium

    CVE-2026-57384

    Last Modified: 23 Jul 2026

    Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.

    Published: 23 Jul 2026
    7.1
    High

    CVE-2026-57374

    Last Modified: 2 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.

    Published: 23 Jul 2026
    6.5
    Medium

    CVE-2026-57373

    Last Modified: 2 Aug 2026

    Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.

    Published: 23 Jul 2026
    7.1
    High

    CVE-2026-57370

    Last Modified: 23 Jul 2026

    Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.

    Published: 23 Jul 2026
    7.1
    High

    CVE-2026-57367

    Last Modified: 2 Aug 2026

    Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.

    Published: 23 Jul 2026
    4.3
    Medium

    CVE-2026-27423

    Last Modified: 2 Aug 2026

    Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.

    Published: 23 Jul 2026
    5.3
    Medium

    CVE-2026-27422

    Last Modified: 23 Jul 2026

    Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.

    Published: 23 Jul 2026
    5.3
    Medium

    CVE-2026-27418

    Last Modified: 23 Jul 2026

    Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.

    Published: 23 Jul 2026
    6.5
    Medium

    CVE-2026-27403

    Last Modified: 23 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3.

    Published: 23 Jul 2026
    5.3
    Medium

    CVE-2026-27399

    Last Modified: 23 Jul 2026

    Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.

    Published: 23 Jul 2026
    4.3
    Medium

    CVE-2026-27392

    Last Modified: 2 Aug 2026

    Contributor Broken Access Control in uListing <= 2.2.0 versions.

    Published: 23 Jul 2026
    5.4
    Medium

    CVE-2026-27391

    Last Modified: 2 Aug 2026

    Subscriber Broken Access Control in uListing <= 2.2.0 versions.

    Published: 23 Jul 2026
    6.7
    Medium

    CVE-2026-27377

    Last Modified: 23 Jul 2026

    Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.

    Published: 23 Jul 2026
    6.5
    Medium

    CVE-2026-27372

    Last Modified: 2 Aug 2026

    Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.

    Published: 23 Jul 2026
    5.3
    Medium

    CVE-2026-27355

    Last Modified: 23 Jul 2026

    Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.

    Published: 23 Jul 2026
    9.1
    Critical

    CVE-2026-27064

    Last Modified: 23 Jul 2026

    Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.

    Published: 23 Jul 2026
    5.3
    Medium

    CVE-2026-25466

    Last Modified: 23 Jul 2026

    Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.

    Published: 23 Jul 2026
    5.4
    Medium

    CVE-2026-25427

    Last Modified: 23 Jul 2026

    Subscriber Broken Access Control in eRoom <= 1.7.1 versions.

    Published: 23 Jul 2026
    4.3
    Medium

    CVE-2026-25424

    Last Modified: 23 Jul 2026

    Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.

    Published: 23 Jul 2026
    8.5
    High

    CVE-2026-25405

    Last Modified: 23 Jul 2026

    Contributor SQL Injection in eRoom <= 1.7.1 versions.

    Published: 23 Jul 2026
    4.4
    Medium

    CVE-2026-24639

    Last Modified: 23 Jul 2026

    Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.

    Published: 23 Jul 2026
    5.9
    Medium

    CVE-2026-24628

    Last Modified: 23 Jul 2026

    Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.

    Published: 23 Jul 2026
    8.5
    High

    CVE-2026-24552

    Last Modified: 6 Aug 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'Allier Create allows Blind SQL Injection. This issue affects Create: from n/a through 2.5.3.

    Published: 23 Jul 2026
    4.3
    Medium

    CVE-2026-24537

    Last Modified: 2 Aug 2026

    Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.

    Published: 23 Jul 2026
    5.9
    Medium

    CVE-2025-68081

    Last Modified: 23 Jul 2026

    Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.

    Published: 23 Jul 2026
    7.5
    High

    CVE-2026-64611

    Last Modified: 19 Aug 2026

    A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.

    Published: 23 Jul 2026
    8.8
    High

    CVE-2026-16745

    Last Modified: 8 Sept 2026

    A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.

    Published: 23 Jul 2026
    9.8
    Critical

    CVE-2026-15015

    Last Modified: 23 Jul 2026

    The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain an administrator-bound OAuth Bearer token via a self-registered client, granting full administrator-equivalent access to the plugin's MCP tool surface and all exposed WordPress content, users, and options. This is exploitable by combining the publicly accessible Dynamic Client Registration endpoint, which allows unauthenticated callers to register arbitrary OAuth clients with an attacker-controlled redirect_uri, with the unprotected authorization endpoint to complete the full OAuth flow without any administrator interaction.

    Published: 23 Jul 2026
    6.4
    Medium

    CVE-2026-15394

    Last Modified: 23 Jul 2026

    The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code' Snippet Meta in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 23 Jul 2026
    6.5
    Medium

    CVE-2026-15448

    Last Modified: 23 Jul 2026

    The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with staff-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 23 Jul 2026
    6.5
    Medium

    CVE-2026-13119

    Last Modified: 23 Jul 2026

    The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard'] and uses the JSON array keys directly as column identifiers in the SET clause of an UPDATE statement built inside RTEC_Db_Admin::update_entry(). Only esc_sql() (mysqli_real_escape_string) is applied to the identifier; that function escapes quotes, backslashes, and a few control characters but does not escape spaces, equals signs, parentheses, or hyphens, so an attacker can break out of the identifier context and inject subqueries (terminated with a SQL comment). This makes it possible for authenticated attackers, with Contributor-level access and above who can edit the targeted event, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 23 Jul 2026
    4.4
    Medium

    CVE-2026-15786

    Last Modified: 24 Jul 2026

    The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. Although file write content is passed through esc_html(), which encodes angle brackets and prevents direct PHP execution, plaintext configuration files such as .htaccess are fully writable and exploitable for denial-of-service or redirect attacks. This is only exploitable when the premium version of the software is enabled and active.

    Published: 23 Jul 2026
    6.5
    Medium

    CVE-2026-13009

    Last Modified: 23 Jul 2026

    The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The required waic-nonce is emitted on the front-end whenever the [waic_form] or [aiwu-form] shortcode is rendered, enabling contributor-level users who can publish shortcodes to obtain a valid nonce and reach the vulnerable AJAX handler, which performs no capability check beyond nonce verification when the shortcodes are not already embedded in a page.

    Published: 23 Jul 2026
    8.8
    High

    CVE-2026-15017

    Last Modified: 23 Jul 2026

    The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined with the absence of server-side allow-list validation on the `employee_roles[]` and `new_role` POST parameters before they are passed to `mdjm_set_employee_role()` and `WP_User::set_role()`. This makes it possible for unauthenticated attackers to grant arbitrary MDJM capabilities — including `mdjm_employee` and `mdjm_employee_edit` — to any registered WordPress role, and subsequently leverage a subscriber-level account to escalate privileges to Administrator. `MDJM_Permissions::init()` is registered on the public WordPress `init` hook without any authentication gate, meaning the role-manipulation endpoint is reachable without any prior login.

    Published: 23 Jul 2026
    6.3
    Medium

    CVE-2026-15348

    Last Modified: 2 Aug 2026

    The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via the `wpdmppdl` parameter. This is due to the `download()` function — hooked to the unauthenticated WordPress `wp` action — decoding the attacker-controlled `wpdmppdl` parameter using only `base64_decode()` and `json_decode()` with no HMAC, cryptographic signature, or nonce verification, and then issuing WordPress authentication cookies after a domain check that is trivially bypassed because both sides of the comparison are attacker-supplied values. This makes it possible for unauthenticated attackers to authenticate as any non-administrator WordPress user, including subscribers, customers, contributors, authors, editors, and shop managers, who owns an order, gaining full session-level access to that account.

    Published: 23 Jul 2026
    8.2
    High

    CVE-2026-65758

    Last Modified: 30 Jul 2026

    Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.

    Published: 23 Jul 2026
    6.5
    Medium

    CVE-2026-65713

    Last Modified: 24 Jul 2026

    Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories.

    Published: 23 Jul 2026
    9.8
    Critical

    CVE-2026-64873

    Last Modified: 24 Jul 2026

    Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.

    Published: 23 Jul 2026
    5.4
    Medium

    CVE-2026-64871

    Last Modified: 24 Jul 2026

    Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid token and cache-management permission.

    Published: 23 Jul 2026