🚨 CVE-2026-65463
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
🎖@cveNotify
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
🎖@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Masteriyo - LMS Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65464
Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.
🎖@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.
🎖@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress GiveWP Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65465
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
🎖@cveNotify
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress JetElements For Elementor Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65466
Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
🎖@cveNotify
Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
🎖@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress JetBooking Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65467
Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
🎖@cveNotify
Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
🎖@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress JetEngine Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65469
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress AWP Classifieds Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65471
Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
🎖@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
🎖@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Avada Core Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65472
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Kit (formerly ConvertKit) Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65473
Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.
🎖@cveNotify
Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Virtue/Ascend/Pinnacle Toolkit Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65474
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
🎖@cveNotify
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
🎖@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Ninja Tables Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65475
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS.
This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.
🎖@cveNotify
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS.
This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Modula Image Gallery Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65482
Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
🎖@cveNotify
Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress LA-Studio Element Kit for Elementor Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65483
Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.
🎖@cveNotify
Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress HashThemes Demo Importer Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.