CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2026-57789

    Last Modified: 13 Jul 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Aqua aqua allows PHP Local File Inclusion.This issue affects Aqua: from n/a through <= 5.1.2.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57790

    Last Modified: 13 Jul 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allows PHP Local File Inclusion.This issue affects Billey: from n/a through <= 2.1.8.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57788

    Last Modified: 13 Jul 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Aalto aalto allows PHP Local File Inclusion.This issue affects Aalto: from n/a through <= 1.8.

    Published: 13 Jul 2026
    8.8
    High

    CVE-2026-57786

    Last Modified: 13 Jul 2026

    Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass.This issue affects WorkScout-Core: from n/a through <= 1.7.08.

    Published: 13 Jul 2026
    8.5
    High

    CVE-2026-57787

    Last Modified: 27 Jul 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeWS CWS SVGicons cws-svgicons allows Blind SQL Injection.This issue affects CWS SVGicons: from n/a through <= 1.5.5.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57783

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in merkulove Speaker speaker allows Stored XSS.This issue affects Speaker: from n/a through <= 4.1.13.

    Published: 13 Jul 2026
    5.3
    Medium

    CVE-2026-57782

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in PressTigers Universal Clocks universal-clocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Universal Clocks: from n/a through <= 1.2.0.

    Published: 13 Jul 2026
    5.3
    Medium

    CVE-2026-57781

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in Sovlix MeetingHub meetinghub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MeetingHub: from n/a through <= 1.25.10.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57780

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plugin Envision Envision Page Builder envision-page-builder allows DOM-Based XSS.This issue affects Envision Page Builder: from n/a through <= 0.22.

    Published: 13 Jul 2026
    5.3
    Medium

    CVE-2026-57779

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in themebeez Fascinate fascinate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fascinate: from n/a through <= 1.1.5.

    Published: 13 Jul 2026
    5.3
    Medium

    CVE-2026-57778

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.36.

    Published: 13 Jul 2026
    5.3
    Medium

    CVE-2026-57776

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in vowelweb VW Wedding vw-wedding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Wedding: from n/a through <= 1.3.7.

    Published: 13 Jul 2026
    5.3
    Medium

    CVE-2026-57774

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in vowelweb VW Food Corner vw-food-corner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Food Corner: from n/a through <= 1.1.0.

    Published: 13 Jul 2026
    7.6
    High

    CVE-2026-57773

    Last Modified: 13 Jul 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zorem Advanced Shipment Tracking for WooCommerce woo-advanced-shipment-tracking allows Blind SQL Injection.This issue affects Advanced Shipment Tracking for WooCommerce: from n/a through <= 4.0.

    Published: 13 Jul 2026
    8.5
    High

    CVE-2026-57772

    Last Modified: 13 Jul 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Blind SQL Injection.This issue affects WP Inventory Manager: from n/a through <= 2.4.0.

    Published: 13 Jul 2026
    8.5
    High

    CVE-2026-57771

    Last Modified: 13 Jul 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Rating System gd-rating-system allows Blind SQL Injection.This issue affects GD Rating System: from n/a through <= 3.7.

    Published: 13 Jul 2026
    9.8
    Critical

    CVE-2026-57770

    Last Modified: 13 Jul 2026

    Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.

    Published: 13 Jul 2026
    8.2
    High

    CVE-2026-57768

    Last Modified: 13 Jul 2026

    Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through <= 3.3.3.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57745

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Reflected XSS.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

    Published: 13 Jul 2026
    9.8
    Critical

    CVE-2026-57744

    Last Modified: 13 Jul 2026

    Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

    Published: 13 Jul 2026
    8.1
    High

    CVE-2026-57743

    Last Modified: 13 Jul 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows PHP Local File Inclusion.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57741

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Stored XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.

    Published: 13 Jul 2026
    9.3
    Critical

    CVE-2026-57739

    Last Modified: 13 Jul 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.

    Published: 13 Jul 2026
    9.8
    Critical

    CVE-2026-57738

    Last Modified: 13 Jul 2026

    Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57740

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.1.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57734

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.3.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57733

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Cloud Library td-cloud-library allows DOM-Based XSS.This issue affects tagDiv Cloud Library: from n/a through <= 3.9.4.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57732

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows DOM-Based XSS.This issue affects tagDiv Opt-In Builder: from n/a through <= 1.7.4.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57729

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flatsome: from n/a through <= 3.20.5.

    Published: 13 Jul 2026
    9.8
    Critical

    CVE-2026-57724

    Last Modified: 13 Jul 2026

    Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57725

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirki kirki allows Stored XSS.This issue affects Kirki: from n/a through <= 6.0.11.

    Published: 13 Jul 2026
    9.3
    Critical

    CVE-2026-57726

    Last Modified: 13 Jul 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from n/a through <= 6.0.12.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57728

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Reflected XSS.This issue affects Flatsome: from n/a through <= 3.20.5.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57727

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kirki: from n/a through <= 6.0.13.

    Published: 13 Jul 2026
    10
    Critical

    CVE-2026-57719

    Last Modified: 13 Jul 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= 2.8.3.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57718

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 2.0.12.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57715

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPManageNinja Fluent CRM fluent-crm allows Reflected XSS.This issue affects Fluent CRM: from n/a through <= 3.1.7.

    Published: 13 Jul 2026
    9.3
    Critical

    CVE-2026-57714

    Last Modified: 13 Jul 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LatePoint LatePoint latepoint allows Blind SQL Injection.This issue affects LatePoint: from n/a through <= 5.6.3.

    Published: 13 Jul 2026
    8.8
    High

    CVE-2026-57713

    Last Modified: 13 Jul 2026

    Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57712

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Portfolio wpzoom-portfolio allows Reflected XSS.This issue affects WPZOOM Portfolio: from n/a through <= 1.4.29.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57711

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PSM Plugins SupportCandy supportcandy allows Stored XSS.This issue affects SupportCandy: from n/a through <= 3.4.8.

    Published: 13 Jul 2026
    9.9
    Critical

    CVE-2026-57710

    Last Modified: 13 Jul 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through <= 14.1.7.

    Published: 13 Jul 2026
    8.6
    High

    CVE-2026-57709

    Last Modified: 13 Jul 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Path Traversal.This issue affects Membership For WooCommerce: from n/a through <= 3.1.0.

    Published: 13 Jul 2026
    9.3
    Critical

    CVE-2026-57707

    Last Modified: 13 Jul 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from n/a through <= 15.9.4.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57708

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Contact Form Entries contact-form-entries allows Reflected XSS.This issue affects Contact Form Entries: from n/a through <= 1.5.2.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57706

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan, Inc. Dokan dokan-lite allows Reflected XSS.This issue affects Dokan: from n/a through <= 5.0.6.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57705

    Last Modified: 27 Jul 2026

    Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through <= 5.28.5.

    Published: 13 Jul 2026
    9.3
    Critical

    CVE-2026-57702

    Last Modified: 13 Jul 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.4.2.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57698

    Last Modified: 13 Jul 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.12.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57697

    Last Modified: 13 Jul 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.9.9.6.

    Published: 13 Jul 2026