CVE-2026-51565 - Milk Admin Cross-Site Scripting
CVE ID :CVE-2026-51565
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter in a crafted request
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-51565
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter in a crafted request
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-61953 - WordPress Simple Link Directory Pro plugin <= 15.0.6 - Server Side Request Forgery (SSRF) vulnerability
CVE ID :CVE-2026-61953
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-61953
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-61957 - WordPress miniorange otp verification plugin <= 5.5.1 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-61957
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-61957
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65437 - WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin <= 6.82 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-65437
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-65437
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65438 - WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.9 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-65438
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-65438
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65439 - WordPress Ultimate Addons for Contact Form 7 plugin <=3.5.45 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-65439
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-65439
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65440 - WordPress GetGenie plugin <= 4.4.3 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-65440
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-65440
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65441 - WordPress GiveWP plugin <= 4.16.3 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-65441
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-65441
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65442 - WordPress FormCraft plugin <= 3.9.15 - Server Side Request Forgery (SSRF) vulnerability
CVE ID :CVE-2026-65442
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-65442
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65443 - WordPress BackWPup plugin <= 5.7.4 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-65443
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-65443
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65445 - WordPress Ad Invalid Click Protector (AICP) plugin <= 1.3.0 - Broken Access Control vulnerability
CVE ID :CVE-2026-65445
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-65445
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65446 - WordPress Kali Forms plugin <= 2.4.18 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-65446
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-65446
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65447 - WordPress Contest Gallery plugin <= 30.0.6 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-65447
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-65447
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65448 - WordPress Anti Spam and list cleaner – AcyChecker plugin <= 1.8.1 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-65448
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner – AcyChecker <= 1.8.1 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-65448
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner – AcyChecker <= 1.8.1 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66473 - WordPress Xendit Payment plugin <= 7.1.0 - Broken Access Control vulnerability
CVE ID :CVE-2026-66473
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66473
Published : July 27, 2026, 11:16 p.m. | 1 hour, 31 minutes ago
Description :Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-17528 - nice-select2 Cross-site Scripting Vulnerability
CVE ID :CVE-2026-17528
Published : July 28, 2026, 6:16 a.m. | 2 hours, 31 minutes ago
Description :Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the element. An attacker can supply a malicious payload that is rendered directly into the DOM without proper sanitization, causing arbitrary script execution in a victim’s browser when they view or interact with the affected page.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-17528
Published : July 28, 2026, 6:16 a.m. | 2 hours, 31 minutes ago
Description :Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the element. An attacker can supply a malicious payload that is rendered directly into the DOM without proper sanitization, causing arbitrary script execution in a victim’s browser when they view or interact with the affected page.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12124 - PDFDraft <= 1.1.0 - Missing Authorization to Unauthenticated Sensitive PDF Disclosure via 'slug' Parameter
CVE ID :CVE-2026-12124
Published : July 28, 2026, 7:16 a.m. | 1 hour, 31 minutes ago
Description :The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the serveTemplatePdfAjax() function and the serveTemplatePdf() REST route (which is registered with `permission_callback => '__return_true'`) in versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to download stored template PDFs — which may contain customer PII, invoice, order, and certificate data — by requesting the publicly registered admin-ajax action `pdfdraft_embed_pdf` or the REST endpoint `/wp-json/pdfdraft/v1/embed-pdf/templates/{slug}/pdf` with a known or guessable design slug, bypassing the plugin's own .
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-12124
Published : July 28, 2026, 7:16 a.m. | 1 hour, 31 minutes ago
Description :The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the serveTemplatePdfAjax() function and the serveTemplatePdf() REST route (which is registered with `permission_callback => '__return_true'`) in versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to download stored template PDFs — which may contain customer PII, invoice, order, and certificate data — by requesting the publicly registered admin-ajax action `pdfdraft_embed_pdf` or the REST endpoint `/wp-json/pdfdraft/v1/embed-pdf/templates/{slug}/pdf` with a known or guessable design slug, bypassing the plugin's own .
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14490 - Demi <= 0.0.6 - Unauthenticated Arbitrary Directory Deletion via demi_restore_step AJAX action
CVE ID :CVE-2026-14490
Published : July 28, 2026, 7:16 a.m. | 1 hour, 31 minutes ago
Description :The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 0.0.7. The vulnerability exists because the plugin stores its HMAC signing key and per-step restore token as dotfiles inside a publicly accessible subdirectory of the WordPress uploads folder — without any `.htaccess` or index file protection — and the `demi_restore_step` AJAX handler, registered for unauthenticated callers, explicitly accepts possession of the on-disk signing key as a standalone alternative to WordPress capability and nonce checks; an unauthenticated attacker who retrieves the exposed key can forge a valid signed state envelope to invoke `CleanDir::execute()` with a caller-supplied absolute path that is subject to no allow-list or path-canonicalization check. This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14490
Published : July 28, 2026, 7:16 a.m. | 1 hour, 31 minutes ago
Description :The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 0.0.7. The vulnerability exists because the plugin stores its HMAC signing key and per-step restore token as dotfiles inside a publicly accessible subdirectory of the WordPress uploads folder — without any `.htaccess` or index file protection — and the `demi_restore_step` AJAX handler, registered for unauthenticated callers, explicitly accepts possession of the on-disk signing key as a standalone alternative to WordPress capability and nonce checks; an unauthenticated attacker who retrieves the exposed key can forge a valid signed state envelope to invoke `CleanDir::execute()` with a caller-supplied absolute path that is subject to no allow-list or path-canonicalization check. This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14545 - TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via Password Reset
CVE ID :CVE-2026-14545
Published : July 28, 2026, 7:16 a.m. | 1 hour, 31 minutes ago
Description :The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14545
Published : July 28, 2026, 7:16 a.m. | 1 hour, 31 minutes ago
Description :The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14819 - Event Tickets < 5.28.4 - Editor+ Stored XSS via Ticket Move
CVE ID :CVE-2026-14819
Published : July 28, 2026, 7:16 a.m. | 1 hour, 31 minutes ago
Description :The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14819
Published : July 28, 2026, 7:16 a.m. | 1 hour, 31 minutes ago
Description :The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14821 - Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion
CVE ID :CVE-2026-14821
Published : July 28, 2026, 7:16 a.m. | 1 hour, 31 minutes ago
Description :The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14821
Published : July 28, 2026, 7:16 a.m. | 1 hour, 31 minutes ago
Description :The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...