CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2026-24575

    Last Modified: 17 Jun 2026

    Subscriber Broken Access Control in WishList Member X <= 3.29.0 versions.

    Published: 17 Jun 2026
    8.6
    High

    CVE-2026-22343

    Last Modified: 20 Jun 2026

    Unauthenticated Broken Access Control in WordPress Dating Theme <= 11.2.0 versions.

    Published: 17 Jun 2026
    8.8
    High

    CVE-2026-22342

    Last Modified: 20 Jun 2026

    Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme <= 11.2.0 versions.

    Published: 17 Jun 2026
    9.3
    Critical

    CVE-2026-22340

    Last Modified: 20 Jun 2026

    Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions.

    Published: 17 Jun 2026
    7.1
    High

    CVE-2026-22339

    Last Modified: 20 Jun 2026

    Unauthenticated Cross Site Scripting (XSS) in WPJobster <= 6.3.5 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-22338

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in EcoBlue <= 1.15 versions.

    Published: 17 Jun 2026
    8.5
    High

    CVE-2026-22335

    Last Modified: 20 Jun 2026

    Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions.

    Published: 17 Jun 2026
    7.5
    High

    CVE-2026-22334

    Last Modified: 20 Jun 2026

    Subscriber Arbitrary File Download in Woocommerce Book Price <= 1.3 versions.

    Published: 17 Jun 2026
    9.3
    Critical

    CVE-2026-22332

    Last Modified: 26 Jun 2026

    Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-22331

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in AutoParts <= 1.5.8 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-22330

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Right Way <= 4.0 versions.

    Published: 17 Jun 2026
    7.1
    High

    CVE-2026-22329

    Last Modified: 20 Jun 2026

    Unauthenticated Cross Site Scripting (XSS) in Skillate <= 1.2.10 versions.

    Published: 17 Jun 2026
    7.1
    High

    CVE-2026-22328

    Last Modified: 20 Jun 2026

    Unauthenticated Cross Site Scripting (XSS) in Auto Repair <= 22.6 versions.

    Published: 17 Jun 2026
    9.9
    Critical

    CVE-2026-22327

    Last Modified: 20 Jun 2026

    Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-22326

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Reprizo <= 1.0.8 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-22325

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Promo <= 1.3.0 versions.

    Published: 17 Jun 2026
    7.5
    High

    CVE-2026-9690

    Last Modified: 26 Jun 2026

    Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.

    Published: 17 Jun 2026
    9.8
    Critical

    CVE-2025-69179

    Last Modified: 20 Jun 2026

    Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69173

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Tipsy <= 1.1 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69172

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Resurs <= 1.3 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69171

    Last Modified: 20 Jun 2026

    Unauthenticated Local File Inclusion in Orpheus <= 1.3 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69161

    Last Modified: 20 Jun 2026

    Unauthenticated Local File Inclusion in Snowy <= 1.13 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69148

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Quirky <= 1.23 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69145

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Gat <= 1.16 versions.

    Published: 17 Jun 2026
    8.8
    High

    CVE-2025-69138

    Last Modified: 20 Jun 2026

    Subscriber Privilege Escalation in Genemy <= 1.6.6 versions.

    Published: 17 Jun 2026
    8.5
    High

    CVE-2025-69135

    Last Modified: 20 Jun 2026

    Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions.

    Published: 17 Jun 2026
    10
    Critical

    CVE-2025-69129

    Last Modified: 20 Jun 2026

    Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69117

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Ingenioso <= 1.14.0 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69110

    Last Modified: 20 Jun 2026

    Unauthenticated Local File Inclusion in AirSupply <= 2.0.0 versions.

    Published: 17 Jun 2026
    7.7
    High

    CVE-2025-60223

    Last Modified: 20 Jun 2026

    Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <= 13.6.5 versions.

    Published: 17 Jun 2026
    9.9
    Critical

    CVE-2025-60218

    Last Modified: 20 Jun 2026

    Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions.

    Published: 17 Jun 2026
    9.8
    Critical

    CVE-2025-60205

    Last Modified: 20 Jun 2026

    Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.

    Published: 17 Jun 2026
    8.8
    High

    CVE-2025-59563

    Last Modified: 20 Jun 2026

    Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions.

    Published: 17 Jun 2026
    7.1
    High

    CVE-2025-59560

    Last Modified: 20 Jun 2026

    Unauthenticated Cross Site Scripting (XSS) in Sonaar <= 4.27.4 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-58954

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in HomeRoofer <= 2.11.0 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-58953

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Joly <= 1.22.0 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-58952

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions.

    Published: 17 Jun 2026
    7.5
    High

    CVE-2025-49403

    Last Modified: 17 Jun 2026

    Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions.

    Published: 17 Jun 2026
    9.9
    Critical

    CVE-2024-52488

    Last Modified: 20 Jun 2026

    Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.

    Published: 17 Jun 2026
    7.1
    High

    CVE-2024-49269

    Last Modified: 20 Jun 2026

    Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions.

    Published: 17 Jun 2026
    8.8
    High

    CVE-2026-12165

    Last Modified: 17 Jun 2026

    The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 30.0.2 via the `RegistryUserRole` parameter. This is due to the plugin's admin menu being registered at the `edit_posts` capability level — granting Contributor-level users access to the plugin's admin pages and a valid `cg_admin` nonce — while the option-saving handler in `change-options-and-sizes.php` performs no `current_user_can()` capability check beyond `check_admin_referer('cg_admin')`, and the `RegistryUserRole` value is processed only through `sanitize_text_field()` and `htmlentities()` without restriction to an allowlist of permitted role names. This makes it possible for authenticated attackers, with author-level access and above, to overwrite the plugin's stored `RegistryUserRole` option with `administrator`, which the `cg_create_wp_user_from_google_user` function then reads back from the `contest_gal1ery_registry_and_login_options` database table without any allowlist validation and passes directly to `wp_update_user()`, effectively promoting a newly registered Google sign-in account to Administrator.

    Published: 17 Jun 2026
    6.6
    Medium

    CVE-2026-12115

    Last Modified: 20 Jun 2026

    The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. Deserialization is triggered automatically upon the post-import redirect that renders the list table, and again when any item is opened for editing, requiring no additional navigation beyond the import action itself.

    Published: 17 Jun 2026
    6.5
    Medium

    CVE-2026-47340

    Last Modified: 17 Jun 2026

    Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

    Published: 17 Jun 2026
    9.1
    Critical

    CVE-2026-32967

    Last Modified: 17 Jun 2026

    Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

    Published: 17 Jun 2026
    6.5
    Medium

    CVE-2026-42357

    Last Modified: 19 Jun 2026

    Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

    Published: 17 Jun 2026
    4.9
    Medium

    CVE-2026-41280

    Last Modified: 20 Jun 2026

    Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

    Published: 17 Jun 2026
    9.8
    Critical

    CVE-2026-32966

    Last Modified: 20 Jun 2026

    DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

    Published: 17 Jun 2026
    5.5
    Medium

    CVE-2026-40722

    Last Modified: 20 Jun 2026

    Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Yoast SEO Premium: from n/a through 26.6.

    Published: 17 Jun 2026
    6.9
    Medium

    CVE-2026-27869

    Last Modified: 1 Jul 2026

    An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could, with a Slow Loris attack, cause Denial of Service (DoS) on the web interface of the device. This issue affects Regesta Smart HD-PLC - TLDPH16D2: 11.02.05.10.02.

    Published: 17 Jun 2026
    4.8
    Medium

    CVE-2026-27870

    Last Modified: 1 Jul 2026

    An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action IS required) who has the vulnerable software could, introduce arbitrary JavaScript by injecting a Cross-site Scripting (XSS)  payload into the 'Hostname' field of the configuration file resulting in a XSS in the path /upgrade/query.php?cmd=p+3%3Bversion. This issue affects Regesta Smart HD-PLC - TLDPH16D2: 11.02.05.10.02.

    Published: 17 Jun 2026