CVE-2026-39490 - WordPress JupiterX Core plugin <= 4.14.1 - Broken Access Control vulnerability
CVE ID :CVE-2026-39490
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-39490
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-39574 - WordPress InPost Gallery plugin <= 2.1.4.6 - SQL Injection vulnerability
CVE ID :CVE-2026-39574
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-39574
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-39581 - WordPress WP Sessions Time Monitoring Full Automatic plugin <= 1.1.4 - SQL Injection vulnerability
CVE ID :CVE-2026-39581
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-39581
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-52711 - WordPress WooCommerce POS plugin <= 1.8.14 - Broken Access Control vulnerability
CVE ID :CVE-2026-52711
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-52711
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-52712 - WordPress Attendance Manager plugin <= 0.6.2 - SQL Injection vulnerability
CVE ID :CVE-2026-52712
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-52712
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-52714 - WordPress SEO Plugin by Squirrly SEO plugin <= 12.4.16 - Broken Access Control vulnerability
CVE ID :CVE-2026-52714
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-52714
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-52715 - WordPress GEO my WordPress plugin <= 4.5.5 - SQL Injection vulnerability
CVE ID :CVE-2026-52715
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-52715
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-54190 - WordPress Envira Photo Gallery plugin <= 1.12.5 - Broken Access Control vulnerability
CVE ID :CVE-2026-54190
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-54190
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-54191 - WordPress Pods plugin <= 3.3.8 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-54191
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-54191
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-54197 - WordPress GetGenie plugin <= 4.4.1 - Sensitive Data Exposure vulnerability
CVE ID :CVE-2026-54197
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-54197
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-54198 - WordPress Media LIbrary Assistant plugin <= 3.35 - Reflected Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-54198
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-54198
Published : June 16, 2026, 9 a.m. | 57 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49774 - WordPress RD Station plugin <= 5.6.0 - Remote Code Execution (RCE) vulnerability
CVE ID :CVE-2026-49774
Published : June 16, 2026, 9:02 a.m. | 55 minutes ago
Description :Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49774
Published : June 16, 2026, 9:02 a.m. | 55 minutes ago
Description :Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49772 - WordPress The Events Calendar plugin 6.15.12-6.16.2 - SQL Injection vulnerability
CVE ID :CVE-2026-49772
Published : June 16, 2026, 9:04 a.m. | 54 minutes ago
Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49772
Published : June 16, 2026, 9:04 a.m. | 54 minutes ago
Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40809 - WordPress Metro Magazine theme <= 1.4.1 - Broken Access Control vulnerability
CVE ID :CVE-2026-40809
Published : June 16, 2026, 9:05 a.m. | 53 minutes ago
Description :Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.4.1.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40809
Published : June 16, 2026, 9:05 a.m. | 53 minutes ago
Description :Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.4.1.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2381 - WooCommerce Stripe Payment Gateway <= 10.7.0 - Missing Authorization to Unauthenticated Order Status Manipulation via 'order' Parameter
CVE ID :CVE-2026-2381
Published : June 16, 2026, 9:31 a.m. | 26 minutes ago
Description :The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment for an order via the `wc_stripe_pay_for_order` WC-AJAX endpoint. The function only validates a nonce (which is publicly available on any WooCommerce page where Express Checkout is enabled), but does not verify that the requesting user owns the target order and is allowed to modify it. This makes it possible for unauthenticated attackers to force any pending order into a failed status by providing a fake payment method, causing a payment exception that updates the order status to "failed" via sequential order ID enumeration.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-2381
Published : June 16, 2026, 9:31 a.m. | 26 minutes ago
Description :The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment for an order via the `wc_stripe_pay_for_order` WC-AJAX endpoint. The function only validates a nonce (which is publicly available on any WooCommerce page where Express Checkout is enabled), but does not verify that the requesting user owns the target order and is allowed to modify it. This makes it possible for unauthenticated attackers to force any pending order into a failed status by providing a fake payment method, causing a payment exception that updates the order status to "failed" via sequential order ID enumeration.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-8176 - LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset
CVE ID :CVE-2026-8176
Published : June 16, 2026, 9:31 a.m. | 26 minutes ago
Description :The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.5.1. The plugin chains three independent flaws that together allow an authenticated Agent (Agent+) to overwrite a WordPress Administrator's password without ever invoking an Administrator-only API. This makes it possible for authenticated attackers, with Agent access and above, to elevate their privileges to Administrator.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-8176
Published : June 16, 2026, 9:31 a.m. | 26 minutes ago
Description :The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.5.1. The plugin chains three independent flaws that together allow an authenticated Agent (Agent+) to overwrite a WordPress Administrator's password without ever invoking an Administrator-only API. This makes it possible for authenticated attackers, with Agent access and above, to elevate their privileges to Administrator.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-8442 - WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) Arbitrary File Deletion via 'myaction' Parameter
CVE ID :CVE-2026-8442
Published : June 16, 2026, 9:31 a.m. | 26 minutes ago
Description :The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing authorization checks on the wpfb_hide_review and wprp_save_review_admin AJAX handlers combined with insufficient path validation in the wpfb_hidereview_ajax() function, which uses strpos() to check that a stored media URL starts with the expected prefix but fails to sanitize path traversal sequences in the remaining relative path before passing it to unlink(). This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the affected site's server which may make remote code execution possible.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-8442
Published : June 16, 2026, 9:31 a.m. | 26 minutes ago
Description :The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing authorization checks on the wpfb_hide_review and wprp_save_review_admin AJAX handlers combined with insufficient path validation in the wpfb_hidereview_ajax() function, which uses strpos() to check that a stored media URL starts with the expected prefix but fails to sanitize path traversal sequences in the remaining relative path before passing it to unlink(). This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the affected site's server which may make remote code execution possible.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12309 - Memory safety bug fixed in Firefox 152
CVE ID :CVE-2026-12309
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-12309
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12310 - Memory safety bug fixed in Firefox 152
CVE ID :CVE-2026-12310
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-12310
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12311 - Information disclosure, sandbox escape in the Security: Process Sandboxing component
CVE ID :CVE-2026-12311
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-12311
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12312 - Memory safety bug fixed in Firefox 152
CVE ID :CVE-2026-12312
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-12312
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...