CVE IDSeverityCVSSDescriptionDate
CVE-2026-19754NAN/ABaserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authent…2026-09-02
CVE-2026-3851MEDIUM6.4The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's le…2026-09-02
CVE-2024-35585HIGH8.6Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.…2026-09-02
CVE-2025-46418HIGH7.6Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.…2026-09-02
CVE-2026-9055CRITICAL9.8The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Priv…2026-09-02
CVE-2025-15663MEDIUM6.8The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the …2026-09-02
CVE-2025-15664MEDIUM6.8The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the …2026-09-02
CVE-2026-12526HIGH8.1The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is aut…2026-09-02
CVE-2026-12865HIGH7.1The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before refle…2026-09-02
CVE-2026-14215MEDIUM6.5The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authenticatio…2026-09-02
CVE-2026-14357HIGH8.8The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2…2026-09-02
CVE-2026-15232MEDIUM5.3The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership…2026-09-02
CVE-2026-16966MEDIUM5.3The Solace Extra WordPress plugin before 1.7.0 does not perform any authorization or post-status checks in one…2026-09-02
CVE-2026-16983MEDIUM4.3The Gutentor WordPress plugin before 4.0.6 does not apply the correct context restriction to one of its REST …2026-09-02
CVE-2026-19116HIGH8.8The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deser…2026-09-02
CVE-2026-19251MEDIUM5.3The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whe…2026-09-02
CVE-2026-19453HIGH7.1The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it pre…2026-09-02
CVE-2026-19704MEDIUM5.3The Comments WordPress plugin before 7.6.66 does not validate a value used to build a database query, allowin…2026-09-02
CVE-2026-19719MEDIUM6.8The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post t…2026-09-02
CVE-2026-19723HIGH7.1The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a…2026-09-02
CVE-2026-74927MEDIUM5.3The MultiVendorX WordPress plugin before 5.0.15 does not have proper authorisation controls on one of its RES…2026-09-02
CVE-2026-77764MEDIUM4.3The GamiPress WordPress plugin before 7.9.9.6 does not properly restrict its video watch-tracking functionali…2026-09-02
CVE-2026-77782MEDIUM5.3The Rank Math SEO WordPress plugin before 1.0.277.1 does not check whether a post is password protected befor…2026-09-02
CVE-2026-77783LOW3.7The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on th…2026-09-02
CVE-2026-77784LOW2.7The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object b…2026-09-02
CVE-2026-77785LOW2.7The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to re…2026-09-02
CVE-2026-77787LOW2.7The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata upda…2026-09-02
CVE-2026-77788MEDIUM4.9The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs…2026-09-02
CVE-2026-77792HIGH7.5The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before …2026-09-02
CVE-2026-78151MEDIUM5.3The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's…2026-09-02
CVE-2026-78657CRITICAL9.8The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to i…2026-09-02
CVE-2026-79621MEDIUM4.3The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user c…2026-09-02
CVE-2026-80467HIGH8.1The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted thro…2026-09-02
CVE-2026-81194MEDIUM4.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization wh…2026-09-02
CVE-2026-81195MEDIUM5.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check b…2026-09-02
CVE-2026-81196LOW2.7The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of qui…2026-09-02
CVE-2026-81197MEDIUM5.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route …2026-09-02
CVE-2026-81198LOW3.8The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a c…2026-09-02
CVE-2026-81199MEDIUM5.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check b…2026-09-02
CVE-2026-81426MEDIUM4.3The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order s…2026-09-02
CVE-2026-81427MEDIUM4.3The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order s…2026-09-02
CVE-2026-81428MEDIUM6.5The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownership or the object type of user-supplied …2026-09-02
CVE-2026-81432MEDIUM4.3The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on some of its A…2026-09-02
CVE-2026-81583MEDIUM5.4The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processin…2026-09-02
CVE-2026-81737HIGH8.8The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthentic…2026-09-02
CVE-2026-81807HIGH8.8The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering i…2026-09-02
CVE-2026-82182MEDIUM4.1The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied li…2026-09-02
CVE-2026-82183HIGH8.1The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its…2026-09-02
CVE-2026-3850MEDIUM6.4The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of …2026-09-02
CVE-2026-82883HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus L…2026-09-02
2 / 7715