CVE tracker
378 subscribers
5.23K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-9266 - Accelerate <= 1.5.3 - Missing Authorization to Authenticated (Subscriber+) ThemeGrill Demo Importer Plugin Installation

CVE ID :CVE-2025-9266
Published : Aug. 6, 2026, 11:29 a.m. | 39 minutes ago
Description :The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enqueue_scripts() function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate the ThemeGrill Demo Importer plugin.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-8166 - Stored XSS in Logo Software's e-Logo Purchasing Portal

CVE ID :CVE-2026-8166
Published : Aug. 6, 2026, 11:30 a.m. | 38 minutes ago
Description :Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Purchasing Portal allows Stored XSS. This issue affects e-Logo Purchasing Portal: before 1.52.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19035 - Shibby Tomato qoslimit new_qoslimit_start os command injection

CVE ID :CVE-2026-19035
Published : Aug. 6, 2026, 11:30 a.m. | 38 minutes ago
Description :A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66685 - WordPress Featured Video Plus plugin <= 2.3.3 - Sensitive Data Exposure vulnerability

CVE ID :CVE-2026-66685
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66686 - WordPress Plugins Garbage Collector (Database Cleanup) plugin <= 0.14 - Cross Site Request Forgery (CSRF) vulnerability

CVE ID :CVE-2026-66686
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66688 - WordPress Ultimate Addons for Elementor plugin <= 1.45.2 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-66688
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66690 - WordPress GiveWP plugin <= 4.16.5 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-66690
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66692 - WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.10.0 - Insecure Direct Object References (IDOR) vulnerability

CVE ID :CVE-2026-66692
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66694 - WordPress Thrive Architect plugin <= 10.9.3.1 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-66694
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66695 - WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability

CVE ID :CVE-2026-66695
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66696 - WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.8 - Sensitive Data Exposure vulnerability

CVE ID :CVE-2026-66696
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66699 - WordPress Dokan plugin <= 5.0.10 - Broken Access Control vulnerability

CVE ID :CVE-2026-66699
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Custom role Broken Access Control in Dokan <= 5.0.10 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66701 - WordPress Profile Builder plugin <= 3.16.5 - Broken Access Control vulnerability

CVE ID :CVE-2026-66701
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66702 - WordPress Rank Math SEO plugin <= 1.0.274.1 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-66702
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66703 - WordPress MailOptin plugin <= 1.2.78.0 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-66703
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66705 - WordPress Facebook for WordPress plugin <= 5.2.1 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-66705
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66706 - WordPress Subscribe to Comments plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-66706
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66707 - WordPress Facebook for WooCommerce plugin <= 3.7.5 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-66707
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66708 - WordPress Total Upkeep plugin <= 1.17.2 - Broken Access Control vulnerability

CVE ID :CVE-2026-66708
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66709 - WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerability

CVE ID :CVE-2026-66709
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66710 - WordPress e2pdf plugin <= 1.32.40 - Local File Inclusion vulnerability

CVE ID :CVE-2026-66710
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...