๐จ CVE-2026-65453
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Ebook Store Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65454
Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
๐@cveNotify
Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress Quiz And Survey Master Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65456
Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.
๐@cveNotify
Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.
๐@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Product Slider for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65457
Subscriber Broken Access Control in ะฎKassa ะดะปั WooCommerce <= 2.16.1 versions.
๐@cveNotify
Subscriber Broken Access Control in ะฎKassa ะดะปั WooCommerce <= 2.16.1 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress ะฎKassa ะดะปั WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65460
Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.
๐@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.
๐@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Zarinpal Gateway Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65461
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
๐@cveNotify
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
๐@cveNotify
Patchstack
Arbitrary File Upload in WordPress Really Simple CSV Importer Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65462
Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.
๐@cveNotify
Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress Uncanny Automator Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65463
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
๐@cveNotify
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
๐@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Masteriyo - LMS Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65464
Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.
๐@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.
๐@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress GiveWP Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65465
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress JetElements For Elementor Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65466
Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
๐@cveNotify
Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
๐@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress JetBooking Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65467
Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
๐@cveNotify
Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
๐@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress JetEngine Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65468
Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
๐@cveNotify
Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress JetBooking Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65469
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
๐@cveNotify
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress AWP Classifieds Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65471
Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
๐@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
๐@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Avada Core Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65472
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Kit (formerly ConvertKit) Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65473
Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Virtue/Ascend/Pinnacle Toolkit Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65474
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
๐@cveNotify
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
๐@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Ninja Tables Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65475
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS.
This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.
๐@cveNotify
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS.
This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Modula Image Gallery Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.