CVE tracker
333 subscribers
4.61K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-49772 - WordPress The Events Calendar plugin 6.15.12-6.16.2 - SQL Injection vulnerability

CVE ID :CVE-2026-49772
Published : June 16, 2026, 9:04 a.m. | 54 minutes ago
Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40809 - WordPress Metro Magazine theme <= 1.4.1 - Broken Access Control vulnerability

CVE ID :CVE-2026-40809
Published : June 16, 2026, 9:05 a.m. | 53 minutes ago
Description :Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.4.1.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-2381 - WooCommerce Stripe Payment Gateway <= 10.7.0 - Missing Authorization to Unauthenticated Order Status Manipulation via 'order' Parameter

CVE ID :CVE-2026-2381
Published : June 16, 2026, 9:31 a.m. | 26 minutes ago
Description :The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment for an order via the `wc_stripe_pay_for_order` WC-AJAX endpoint. The function only validates a nonce (which is publicly available on any WooCommerce page where Express Checkout is enabled), but does not verify that the requesting user owns the target order and is allowed to modify it. This makes it possible for unauthenticated attackers to force any pending order into a failed status by providing a fake payment method, causing a payment exception that updates the order status to "failed" via sequential order ID enumeration.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-8176 - LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset

CVE ID :CVE-2026-8176
Published : June 16, 2026, 9:31 a.m. | 26 minutes ago
Description :The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.5.1. The plugin chains three independent flaws that together allow an authenticated Agent (Agent+) to overwrite a WordPress Administrator's password without ever invoking an Administrator-only API. This makes it possible for authenticated attackers, with Agent access and above, to elevate their privileges to Administrator.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-8442 - WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) Arbitrary File Deletion via 'myaction' Parameter

CVE ID :CVE-2026-8442
Published : June 16, 2026, 9:31 a.m. | 26 minutes ago
Description :The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing authorization checks on the wpfb_hide_review and wprp_save_review_admin AJAX handlers combined with insufficient path validation in the wpfb_hidereview_ajax() function, which uses strpos() to check that a stored media URL starts with the expected prefix but fails to sanitize path traversal sequences in the remaining relative path before passing it to unlink(). This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the affected site's server which may make remote code execution possible.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12309 - Memory safety bug fixed in Firefox 152

CVE ID :CVE-2026-12309
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12310 - Memory safety bug fixed in Firefox 152

CVE ID :CVE-2026-12310
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12311 - Information disclosure, sandbox escape in the Security: Process Sandboxing component

CVE ID :CVE-2026-12311
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12312 - Memory safety bug fixed in Firefox 152

CVE ID :CVE-2026-12312
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12313 - Information disclosure, sandbox escape in the Security: Process Sandboxing component

CVE ID :CVE-2026-12313
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12314 - Memory safety bug fixed in Firefox 152

CVE ID :CVE-2026-12314
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12315 - Mitigation bypass in the DOM: Security component

CVE ID :CVE-2026-12315
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12316 - Mitigation bypass in the DOM: Security component

CVE ID :CVE-2026-12316
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12317 - Memory safety bug fixed in Firefox 152

CVE ID :CVE-2026-12317
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12318 - Incorrect boundary conditions in the Libraries component in NSS

CVE ID :CVE-2026-12318
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12319 - Denial-of-service in the Audio/Video: Playback component

CVE ID :CVE-2026-12319
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12320 - Information disclosure in the Password Manager component

CVE ID :CVE-2026-12320
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12321 - JIT miscompilation in the JavaScript: WebAssembly component

CVE ID :CVE-2026-12321
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12322 - Clickjacking issue in the Widget: Gtk component

CVE ID :CVE-2026-12322
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12323 - Spoofing issue in the DOM: Core & HTML component

CVE ID :CVE-2026-12323
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12324 - Incorrect boundary conditions in the Graphics: CanvasWebGL component

CVE ID :CVE-2026-12324
Published : June 16, 2026, 1:16 p.m. | 43 minutes ago
Description :Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...