Threat Intelligence Feed

Aggregating 7583 articles from trusted cybersecurity sources

LATEST CVEs
MED · CVE-2026-91707 The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5. MED · CVE-2026-90977 The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is e MED · CVE-2026-90976 The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an acco HIGH · CVE-2026-89413 The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1. MED · CVE-2026-89330 The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for MED · CVE-2026-89278 The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is v MED · CVE-2026-89138 The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1. MED · CVE-2026-88994 The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a MED · CVE-2026-86800 The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before MED · CVE-2026-86796 The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request befo MED · CVE-2026-84909 The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scri MED · CVE-2026-79713 The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page- MED · CVE-2026-75017 The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plu MED · CVE-2026-75016 The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's client MED · CVE-2026-18317 The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to a MED · CVE-2026-17576 The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, MED · CVE-2026-12106 The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, MED · CVE-2024-38639 An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the CVE-2024-27123 A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit t HIGH · CVE-2026-93485 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPre MED · CVE-2026-90984 The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch HIGH · CVE-2026-90978 The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonc CVE-2026-89008 The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on o CVE-2026-89007 The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one o MED · CVE-2026-88993 The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it CVE-2026-88844 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the c HIGH · CVE-2026-88825 The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowin MED · CVE-2026-88798 The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using MED · CVE-2026-87966 The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauth MED · CVE-2026-87965 The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appoi HIGH · CVE-2026-87775 The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to HIGH · CVE-2026-87774 The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to HIGH · CVE-2026-87771 The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them HIGH · CVE-2026-87770 The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using HIGH · CVE-2026-87767 The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter bef MED · CVE-2026-85350 The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought HIGH · CVE-2026-85127 The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthentic MED · CVE-2026-85123 The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stor HIGH · CVE-2026-85122 The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stor MED · CVE-2026-85009 The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on
5087 general 974 advisories 720 research 534 vendor 268 enterprise

Trending Vendors

Latest News

Data Breaches

No articles found.