CVE-2026-46331 - net/sched: fix pedit partial COW leading to page cache corruption
CVE ID :CVE-2026-46331
Published : June 16, 2026, 8:16 a.m. | 1 hour, 41 minutes ago
Description :In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb_ensure_writable() inside the per-key loop where the actual write offset is known, and add overflow checking on the offset arithmetic. For negative offsets (e.g. Ethernet header edits at ingress), use skb_cow() to COW the headroom instead. Guard offset_valid() against INT_MIN, where negation is undefined.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-46331
Published : June 16, 2026, 8:16 a.m. | 1 hour, 41 minutes ago
Description :In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb_ensure_writable() inside the per-key loop where the actual write offset is known, and add overflow checking on the offset arithmetic. For negative offsets (e.g. Ethernet header edits at ingress), use skb_cow() to COW the headroom instead. Guard offset_valid() against INT_MIN, where negation is undefined.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-8444 - WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) SQL Injection via 'curselrevs' Parameter
CVE ID :CVE-2026-8444
Published : June 16, 2026, 8:16 a.m. | 1 hour, 41 minutes ago
Description :The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up to, and including, 12.6.8. This is due to the handler reading $_POST['curselrevs'] raw with no sanitization or type casting, then concatenating each array element directly into a `WHERE id IN ( ... )` clause without quoting and executing via $wpdb->get_results() without $wpdb->prepare(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-8444
Published : June 16, 2026, 8:16 a.m. | 1 hour, 41 minutes ago
Description :The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up to, and including, 12.6.8. This is due to the handler reading $_POST['curselrevs'] raw with no sanitization or type casting, then concatenating each array element directly into a `WHERE id IN ( ... )` clause without quoting and executing via $wpdb->get_results() without $wpdb->prepare(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-5416 - Command Injection via name parameter
CVE ID :CVE-2026-5416
Published : June 16, 2026, 8:18 a.m. | 1 hour, 40 minutes ago
Description :Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vulnerability in the Managed Ethernet Switch, resulting in full system compromise.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-5416
Published : June 16, 2026, 8:18 a.m. | 1 hour, 40 minutes ago
Description :Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vulnerability in the Managed Ethernet Switch, resulting in full system compromise.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-10825 - Improper JSON Input Validation in WebSocket API Leads to Denial of Service
CVE ID :CVE-2026-10825
Published : June 16, 2026, 8:51 a.m. | 1 hour, 6 minutes ago
Description :A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based requests. A low-privileged authenticated attacker can send a specially crafted request that causes service disruption and may result in an unexpected device reboot.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-10825
Published : June 16, 2026, 8:51 a.m. | 1 hour, 6 minutes ago
Description :A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based requests. A low-privileged authenticated attacker can send a specially crafted request that causes service disruption and may result in an unexpected device reboot.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-68045 - WordPress WP Event SOlution plugin <= 4.1.12 - Broken Access Control vulnerability
CVE ID :CVE-2025-68045
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-68045
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-39437 - WordPress Min Max Step Quantity Limits Manager for WooCommerce plugin <= 5.2.2 - Reflected Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-39437
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-39437
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-39490 - WordPress JupiterX Core plugin <= 4.14.1 - Broken Access Control vulnerability
CVE ID :CVE-2026-39490
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-39490
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-39574 - WordPress InPost Gallery plugin <= 2.1.4.6 - SQL Injection vulnerability
CVE ID :CVE-2026-39574
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-39574
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-39581 - WordPress WP Sessions Time Monitoring Full Automatic plugin <= 1.1.4 - SQL Injection vulnerability
CVE ID :CVE-2026-39581
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-39581
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-52711 - WordPress WooCommerce POS plugin <= 1.8.14 - Broken Access Control vulnerability
CVE ID :CVE-2026-52711
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-52711
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-52712 - WordPress Attendance Manager plugin <= 0.6.2 - SQL Injection vulnerability
CVE ID :CVE-2026-52712
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-52712
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-52714 - WordPress SEO Plugin by Squirrly SEO plugin <= 12.4.16 - Broken Access Control vulnerability
CVE ID :CVE-2026-52714
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-52714
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-52715 - WordPress GEO my WordPress plugin <= 4.5.5 - SQL Injection vulnerability
CVE ID :CVE-2026-52715
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-52715
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-54190 - WordPress Envira Photo Gallery plugin <= 1.12.5 - Broken Access Control vulnerability
CVE ID :CVE-2026-54190
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-54190
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-54191 - WordPress Pods plugin <= 3.3.8 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-54191
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-54191
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-54197 - WordPress GetGenie plugin <= 4.4.1 - Sensitive Data Exposure vulnerability
CVE ID :CVE-2026-54197
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-54197
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-54198 - WordPress Media LIbrary Assistant plugin <= 3.35 - Reflected Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-54198
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-54198
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49774 - WordPress RD Station plugin <= 5.6.0 - Remote Code Execution (RCE) vulnerability
CVE ID :CVE-2026-49774
Published : June 16, 2026, 9:02 a.m. | 55 minutes ago
Description :Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49774
Published : June 16, 2026, 9:02 a.m. | 55 minutes ago
Description :Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49772 - WordPress The Events Calendar plugin 6.15.12-6.16.2 - SQL Injection vulnerability
CVE ID :CVE-2026-49772
Published : June 16, 2026, 9:04 a.m. | 54 minutes ago
Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49772
Published : June 16, 2026, 9:04 a.m. | 54 minutes ago
Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40809 - WordPress Metro Magazine theme <= 1.4.1 - Broken Access Control vulnerability
CVE ID :CVE-2026-40809
Published : June 16, 2026, 9:05 a.m. | 53 minutes ago
Description :Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.4.1.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40809
Published : June 16, 2026, 9:05 a.m. | 53 minutes ago
Description :Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.4.1.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2381 - WooCommerce Stripe Payment Gateway <= 10.7.0 - Missing Authorization to Unauthenticated Order Status Manipulation via 'order' Parameter
CVE ID :CVE-2026-2381
Published : June 16, 2026, 9:31 a.m. | 26 minutes ago
Description :The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment for an order via the `wc_stripe_pay_for_order` WC-AJAX endpoint. The function only validates a nonce (which is publicly available on any WooCommerce page where Express Checkout is enabled), but does not verify that the requesting user owns the target order and is allowed to modify it. This makes it possible for unauthenticated attackers to force any pending order into a failed status by providing a fake payment method, causing a payment exception that updates the order status to "failed" via sequential order ID enumeration.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-2381
Published : June 16, 2026, 9:31 a.m. | 26 minutes ago
Description :The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment for an order via the `wc_stripe_pay_for_order` WC-AJAX endpoint. The function only validates a nonce (which is publicly available on any WooCommerce page where Express Checkout is enabled), but does not verify that the requesting user owns the target order and is allowed to modify it. This makes it possible for unauthenticated attackers to force any pending order into a failed status by providing a fake payment method, causing a payment exception that updates the order status to "failed" via sequential order ID enumeration.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...