🚨 CVE-2026-24537
Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.
🎖@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.
🎖@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress WP Accessibility Helper (WAH) Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-24628
Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.
🎖@cveNotify
Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Photo Gallery by Supsystic Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-24639
Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
🎖@cveNotify
Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
🎖@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress Photo Block Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-25424
Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.
🎖@cveNotify
Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Mediavine Control Panel Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-27372
Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.
🎖@cveNotify
Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.
🎖@cveNotify
Patchstack
Sensitive Data Exposure in WordPress PeproDev Ultimate Invoice Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-27377
Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.
🎖@cveNotify
Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress QuickCal - Appointment Booking Calendar for WordPress Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-27403
Contributor Cross Site Scripting (XSS) in Hubbub Lite <= 1.36.3 versions.
🎖@cveNotify
Contributor Cross Site Scripting (XSS) in Hubbub Lite <= 1.36.3 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Hubbub Lite Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-27418
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress WP Fast Total Search Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-27423
Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.
🎖@cveNotify
Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Participants Database Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-57367
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
🎖@cveNotify
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress WP Booking System Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-57370
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Visitor Traffic Real Time Statistics Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.