CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2026-39624

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in kutethemes Biolife biolife allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Biolife: from n/a through <= 3.2.3.

    Published: 8 Apr 2026
    7.5
    High

    CVE-2026-39623

    Last Modified: 29 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes Biolife biolife allows PHP Local File Inclusion.This issue affects Biolife: from n/a through <= 3.2.3.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39622

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in acmethemes Education Base education-base allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Education Base: from n/a through <= 3.0.8.

    Published: 8 Apr 2026
    8.8
    High

    CVE-2026-39621

    Last Modified: 29 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in spicethemes SpicePress spicepress allows Upload a Web Shell to a Web Server.This issue affects SpicePress: from n/a through <= 2.3.2.5.

    Published: 8 Apr 2026
    9.6
    Critical

    CVE-2026-39620

    Last Modified: 24 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affects Appointment: from n/a through <= 3.5.5.

    Published: 8 Apr 2026
    9.6
    Critical

    CVE-2026-39619

    Last Modified: 24 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web Server.This issue affects Busiprof: from n/a through <= 2.5.2.

    Published: 8 Apr 2026
    4.3
    Medium

    CVE-2026-39618

    Last Modified: 24 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in themearile NewsExo newsexo allows Cross Site Request Forgery.This issue affects NewsExo: from n/a through <= 7.1.

    Published: 8 Apr 2026
    9.6
    Critical

    CVE-2026-39617

    Last Modified: 24 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestreet: from n/a through <= 1.7.3.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39616

    Last Modified: 29 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments download-attachments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Attachments: from n/a through <= 1.4.0.

    Published: 8 Apr 2026
    5.9
    Medium

    CVE-2026-39615

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada Download Manager download-manager allows Stored XSS.This issue affects Download Manager: from n/a through <= 3.3.53.

    Published: 8 Apr 2026
    5.4
    Medium

    CVE-2026-39614

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in ilGhera JW Player for WordPress jw-player-7-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JW Player for WordPress: from n/a through <= 2.3.6.

    Published: 8 Apr 2026
    7.5
    High

    CVE-2026-39613

    Last Modified: 24 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes Boutique kute-boutique allows PHP Local File Inclusion.This issue affects Boutique: from n/a through <= 2.3.3.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39612

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in kutethemes KuteShop kuteshop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KuteShop: from n/a through <= 4.2.9.

    Published: 8 Apr 2026
    7.5
    High

    CVE-2026-39611

    Last Modified: 24 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes KuteShop kuteshop allows PHP Local File Inclusion.This issue affects KuteShop: from n/a through <= 4.2.9.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39610

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Pankaj Kumar WpXmas-Snow wpxmas-snow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpXmas-Snow: from n/a through <= 1.1.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39609

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Wava.co Wava Payment wava-payment allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wava Payment: from n/a through <= 0.3.7.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39608

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in iPOSPays iPOSpays Gateways WC ipospays-gateways-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iPOSpays Gateways WC: from n/a through <= 1.3.7.

    Published: 8 Apr 2026
    5.4
    Medium

    CVE-2026-39607

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Wpbens Filter Plus filter-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filter Plus: from n/a through <= 1.1.17.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39606

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Foysal Imran BizReview bizreview allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BizReview: from n/a through <= 1.5.13.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39605

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Obadiah Super Custom Login super-custom-login allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Custom Login: from n/a through <= 1.1.

    Published: 8 Apr 2026
    5.9
    Medium

    CVE-2026-39604

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable allows Stored XSS.This issue affects MyBookTable Bookstore: from n/a through <= 3.6.0.

    Published: 8 Apr 2026
    5.4
    Medium

    CVE-2026-39603

    Last Modified: 24 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Photography grandphotography allows Cross Site Request Forgery.This issue affects Grand Photography: from n/a through <= 5.7.8.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39602

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Rustaurius Order Tracking order-tracking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Tracking: from n/a through <= 3.4.3.

    Published: 8 Apr 2026
    4.3
    Medium

    CVE-2026-39592

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Andy Ha DEPART depart-deposit-and-part-payment-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DEPART: from n/a through <= 1.0.7.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39588

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in nmerii NM Gift Registry and Wishlist Lite nm-gift-registry-and-wishlist-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NM Gift Registry and Wishlist Lite: from n/a through <= 5.13.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39586

    Last Modified: 24 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy: from n/a through <= 4.1132.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39585

    Last Modified: 12 May 2026

    Missing Authorization vulnerability in Arraytics Booktics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Booktics: from n/a through 1.0.16.

    Published: 8 Apr 2026
    6.5
    Medium

    CVE-2026-39575

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronald Huereca Custom Query Blocks post-type-archive-mapping allows DOM-Based XSS.This issue affects Custom Query Blocks: from n/a through <= 5.5.0.

    Published: 8 Apr 2026
    4.3
    Medium

    CVE-2026-39572

    Last Modified: 29 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Retrieve Embedded Sensitive Data.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through < 5.6.5.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39571

    Last Modified: 24 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Themefic Instantio instantio allows Retrieve Embedded Sensitive Data.This issue affects Instantio: from n/a through <= 3.3.30.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39570

    Last Modified: 24 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Retrieve Embedded Sensitive Data.This issue affects 12 Step Meeting List: from n/a through <= 3.19.9.

    Published: 8 Apr 2026
    6.5
    Medium

    CVE-2026-39569

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 12 Step Meeting List: from n/a through <= 3.19.9.

    Published: 8 Apr 2026
    4.3
    Medium

    CVE-2026-39566

    Last Modified: 29 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Designinvento DirectoryPress directorypress allows Retrieve Embedded Sensitive Data.This issue affects DirectoryPress: from n/a through <= 3.6.26.

    Published: 8 Apr 2026
    4.3
    Medium

    CVE-2026-39565

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpTravelly: from n/a through <= 2.1.7.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39564

    Last Modified: 24 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Retrieve Embedded Sensitive Data.This issue affects Sunshine Photo Cart: from n/a through < 3.6.2.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39563

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in ILLID Share This Image share-this-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share This Image: from n/a through <= 2.12.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39562

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.10.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39561

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in WP Chill Revive.so revive-so allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Revive.so: from n/a through <= 2.0.7.

    Published: 8 Apr 2026
    7.5
    High

    CVE-2026-39544

    Last Modified: 24 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themeStek LabtechCO labtechco allows PHP Local File Inclusion.This issue affects LabtechCO: from n/a through <= 8.3.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39543

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.21.4.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39542

    Last Modified: 24 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Doofinder Doofinder for WooCommerce doofinder-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Doofinder for WooCommerce: from n/a through <= 2.10.13.

    Published: 8 Apr 2026
    5.9
    Medium

    CVE-2026-39541

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Stored XSS.This issue affects Hydra Booking: from n/a through <= 1.1.38.

    Published: 8 Apr 2026
    7.5
    High

    CVE-2026-39538

    Last Modified: 24 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Mikado Core mikado-core allows PHP Local File Inclusion.This issue affects Mikado Core: from n/a through <= 1.6.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39536

    Last Modified: 24 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Chill RSVP and Event Management rsvp allows Retrieve Embedded Sensitive Data.This issue affects RSVP and Event Management: from n/a through <= 2.7.16.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39535

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in fullworks Display Eventbrite Events widget-for-eventbrite-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display Eventbrite Events: from n/a through <= 6.5.6.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39528

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in WP Delicious WP Delicious delicious-recipes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Delicious: from n/a through <= 1.9.5.

    Published: 8 Apr 2026
    5.4
    Medium

    CVE-2026-39526

    Last Modified: 24 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpStream: from n/a through < 4.11.2.

    Published: 8 Apr 2026
    4.9
    Medium

    CVE-2026-39521

    Last Modified: 24 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Nelio Software Nelio Content nelio-content allows Server Side Request Forgery.This issue affects Nelio Content: from n/a through <= 4.3.1.

    Published: 8 Apr 2026
    5.3
    Medium

    CVE-2026-39520

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in weDevs weDocs wedocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects weDocs: from n/a through <= 2.1.18.

    Published: 8 Apr 2026
    6.5
    Medium

    CVE-2026-39517

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Filter blog-filter allows DOM-Based XSS.This issue affects Blog Filter: from n/a through <= 1.7.6.

    Published: 8 Apr 2026