CVE-2026-24575
Last Modified: 17 Jun 2026Subscriber Broken Access Control in WishList Member X <= 3.29.0 versions.
CVE-2026-22343
Last Modified: 20 Jun 2026Unauthenticated Broken Access Control in WordPress Dating Theme <= 11.2.0 versions.
CVE-2026-22342
Last Modified: 20 Jun 2026Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme <= 11.2.0 versions.
CVE-2026-22340
Last Modified: 20 Jun 2026Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions.
CVE-2026-22339
Last Modified: 20 Jun 2026Unauthenticated Cross Site Scripting (XSS) in WPJobster <= 6.3.5 versions.
CVE-2026-22338
Last Modified: 26 Jun 2026Unauthenticated Local File Inclusion in EcoBlue <= 1.15 versions.
CVE-2026-22335
Last Modified: 20 Jun 2026Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions.
CVE-2026-22334
Last Modified: 20 Jun 2026Subscriber Arbitrary File Download in Woocommerce Book Price <= 1.3 versions.
CVE-2026-22332
Last Modified: 26 Jun 2026Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions.
CVE-2026-22331
Last Modified: 26 Jun 2026Unauthenticated Local File Inclusion in AutoParts <= 1.5.8 versions.
CVE-2026-22330
Last Modified: 26 Jun 2026Unauthenticated Local File Inclusion in Right Way <= 4.0 versions.
CVE-2026-22329
Last Modified: 20 Jun 2026Unauthenticated Cross Site Scripting (XSS) in Skillate <= 1.2.10 versions.
CVE-2026-22328
Last Modified: 20 Jun 2026Unauthenticated Cross Site Scripting (XSS) in Auto Repair <= 22.6 versions.
CVE-2026-22327
Last Modified: 20 Jun 2026Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions.
CVE-2026-22326
Last Modified: 26 Jun 2026Unauthenticated Local File Inclusion in Reprizo <= 1.0.8 versions.
CVE-2026-22325
Last Modified: 26 Jun 2026Unauthenticated Local File Inclusion in Promo <= 1.3.0 versions.
CVE-2026-9690
Last Modified: 26 Jun 2026Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.
CVE-2025-69179
Last Modified: 20 Jun 2026Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions.
CVE-2025-69173
Last Modified: 26 Jun 2026Unauthenticated Local File Inclusion in Tipsy <= 1.1 versions.
CVE-2025-69172
Last Modified: 26 Jun 2026Unauthenticated Local File Inclusion in Resurs <= 1.3 versions.
CVE-2025-69171
Last Modified: 20 Jun 2026Unauthenticated Local File Inclusion in Orpheus <= 1.3 versions.
CVE-2025-69161
Last Modified: 20 Jun 2026Unauthenticated Local File Inclusion in Snowy <= 1.13 versions.
CVE-2025-69148
Last Modified: 26 Jun 2026Unauthenticated Local File Inclusion in Quirky <= 1.23 versions.
CVE-2025-69145
Last Modified: 26 Jun 2026Unauthenticated Local File Inclusion in Gat <= 1.16 versions.
CVE-2025-69138
Last Modified: 20 Jun 2026Subscriber Privilege Escalation in Genemy <= 1.6.6 versions.
CVE-2025-69135
Last Modified: 20 Jun 2026Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions.
CVE-2025-69129
Last Modified: 20 Jun 2026Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions.
CVE-2025-69117
Last Modified: 26 Jun 2026Unauthenticated Local File Inclusion in Ingenioso <= 1.14.0 versions.
CVE-2025-69110
Last Modified: 20 Jun 2026Unauthenticated Local File Inclusion in AirSupply <= 2.0.0 versions.
CVE-2025-60223
Last Modified: 20 Jun 2026Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <= 13.6.5 versions.
CVE-2025-60218
Last Modified: 20 Jun 2026Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions.
CVE-2025-60205
Last Modified: 20 Jun 2026Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.
CVE-2025-59563
Last Modified: 20 Jun 2026Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions.
CVE-2025-59560
Last Modified: 20 Jun 2026Unauthenticated Cross Site Scripting (XSS) in Sonaar <= 4.27.4 versions.
CVE-2025-58954
Last Modified: 26 Jun 2026Unauthenticated Local File Inclusion in HomeRoofer <= 2.11.0 versions.
CVE-2025-58953
Last Modified: 26 Jun 2026Unauthenticated Local File Inclusion in Joly <= 1.22.0 versions.
CVE-2025-58952
Last Modified: 26 Jun 2026Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions.
CVE-2025-49403
Last Modified: 17 Jun 2026Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions.
CVE-2024-52488
Last Modified: 20 Jun 2026Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.
CVE-2024-49269
Last Modified: 20 Jun 2026Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions.
CVE-2026-12165
Last Modified: 17 Jun 2026The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 30.0.2 via the `RegistryUserRole` parameter. This is due to the plugin's admin menu being registered at the `edit_posts` capability level — granting Contributor-level users access to the plugin's admin pages and a valid `cg_admin` nonce — while the option-saving handler in `change-options-and-sizes.php` performs no `current_user_can()` capability check beyond `check_admin_referer('cg_admin')`, and the `RegistryUserRole` value is processed only through `sanitize_text_field()` and `htmlentities()` without restriction to an allowlist of permitted role names. This makes it possible for authenticated attackers, with author-level access and above, to overwrite the plugin's stored `RegistryUserRole` option with `administrator`, which the `cg_create_wp_user_from_google_user` function then reads back from the `contest_gal1ery_registry_and_login_options` database table without any allowlist validation and passes directly to `wp_update_user()`, effectively promoting a newly registered Google sign-in account to Administrator.
CVE-2026-12115
Last Modified: 20 Jun 2026The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. Deserialization is triggered automatically upon the post-import redirect that renders the list table, and again when any item is opened for editing, requiring no additional navigation beyond the import action itself.
CVE-2026-47340
Last Modified: 17 Jun 2026Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
CVE-2026-32967
Last Modified: 17 Jun 2026Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
CVE-2026-42357
Last Modified: 19 Jun 2026Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.
CVE-2026-41280
Last Modified: 20 Jun 2026Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.
CVE-2026-32966
Last Modified: 20 Jun 2026DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
CVE-2026-40722
Last Modified: 20 Jun 2026Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Yoast SEO Premium: from n/a through 26.6.
CVE-2026-27869
Last Modified: 1 Jul 2026An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could, with a Slow Loris attack, cause Denial of Service (DoS) on the web interface of the device. This issue affects Regesta Smart HD-PLC - TLDPH16D2: 11.02.05.10.02.
CVE-2026-27870
Last Modified: 1 Jul 2026An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action IS required) who has the vulnerable software could, introduce arbitrary JavaScript by injecting a Cross-site Scripting (XSS) payload into the 'Hostname' field of the configuration file resulting in a XSS in the path /upgrade/query.php?cmd=p+3%3Bversion. This issue affects Regesta Smart HD-PLC - TLDPH16D2: 11.02.05.10.02.
