CVE-2026-11983 - Ad Inserter <= 2.8.16 - Missing Authorization to Block Visibility Bypass via ai_ajax
CVE ID :CVE-2026-11983
Published : Aug. 6, 2026, 11:29 a.m. | 39 minutes ago
Description :The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check in the `ai_ajax` function. This makes it possible for unauthenticated attackers to view the contents of ad blocks that an administrator has restricted to administrator-only visibility.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-11983
Published : Aug. 6, 2026, 11:29 a.m. | 39 minutes ago
Description :The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check in the `ai_ajax` function. This makes it possible for unauthenticated attackers to view the contents of ad blocks that an administrator has restricted to administrator-only visibility.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15028 - FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.9.2 - Unauthenticated Stored Cross-Site Scripting
CVE ID :CVE-2025-15028
Published : Aug. 6, 2026, 11:29 a.m. | 39 minutes ago
Description :The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission fields in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-15028
Published : Aug. 6, 2026, 11:29 a.m. | 39 minutes ago
Description :The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission fields in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9266 - Accelerate <= 1.5.3 - Missing Authorization to Authenticated (Subscriber+) ThemeGrill Demo Importer Plugin Installation
CVE ID :CVE-2025-9266
Published : Aug. 6, 2026, 11:29 a.m. | 39 minutes ago
Description :The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enqueue_scripts() function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate the ThemeGrill Demo Importer plugin.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-9266
Published : Aug. 6, 2026, 11:29 a.m. | 39 minutes ago
Description :The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enqueue_scripts() function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate the ThemeGrill Demo Importer plugin.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-8166 - Stored XSS in Logo Software's e-Logo Purchasing Portal
CVE ID :CVE-2026-8166
Published : Aug. 6, 2026, 11:30 a.m. | 38 minutes ago
Description :Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Purchasing Portal allows Stored XSS. This issue affects e-Logo Purchasing Portal: before 1.52.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-8166
Published : Aug. 6, 2026, 11:30 a.m. | 38 minutes ago
Description :Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Purchasing Portal allows Stored XSS. This issue affects e-Logo Purchasing Portal: before 1.52.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19035 - Shibby Tomato qoslimit new_qoslimit_start os command injection
CVE ID :CVE-2026-19035
Published : Aug. 6, 2026, 11:30 a.m. | 38 minutes ago
Description :A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19035
Published : Aug. 6, 2026, 11:30 a.m. | 38 minutes ago
Description :A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66685 - WordPress Featured Video Plus plugin <= 2.3.3 - Sensitive Data Exposure vulnerability
CVE ID :CVE-2026-66685
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66685
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66686 - WordPress Plugins Garbage Collector (Database Cleanup) plugin <= 0.14 - Cross Site Request Forgery (CSRF) vulnerability
CVE ID :CVE-2026-66686
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66686
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66688 - WordPress Ultimate Addons for Elementor plugin <= 1.45.2 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-66688
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66688
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66690 - WordPress GiveWP plugin <= 4.16.5 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-66690
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66690
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66692 - WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.10.0 - Insecure Direct Object References (IDOR) vulnerability
CVE ID :CVE-2026-66692
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66692
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66694 - WordPress Thrive Architect plugin <= 10.9.3.1 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-66694
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66694
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66695 - WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability
CVE ID :CVE-2026-66695
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66695
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66696 - WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.8 - Sensitive Data Exposure vulnerability
CVE ID :CVE-2026-66696
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66696
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66699 - WordPress Dokan plugin <= 5.0.10 - Broken Access Control vulnerability
CVE ID :CVE-2026-66699
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Custom role Broken Access Control in Dokan <= 5.0.10 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66699
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Custom role Broken Access Control in Dokan <= 5.0.10 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66701 - WordPress Profile Builder plugin <= 3.16.5 - Broken Access Control vulnerability
CVE ID :CVE-2026-66701
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66701
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66702 - WordPress Rank Math SEO plugin <= 1.0.274.1 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-66702
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66702
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66703 - WordPress MailOptin plugin <= 1.2.78.0 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-66703
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66703
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66705 - WordPress Facebook for WordPress plugin <= 5.2.1 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-66705
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66705
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66706 - WordPress Subscribe to Comments plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-66706
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66706
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66707 - WordPress Facebook for WooCommerce plugin <= 3.7.5 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-66707
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66707
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66708 - WordPress Total Upkeep plugin <= 1.17.2 - Broken Access Control vulnerability
CVE ID :CVE-2026-66708
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66708
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...