🚨 CVE-2026-15906
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with admin-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
🎖@cveNotify
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with admin-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
🎖@cveNotify
🚨 CVE-2026-16745
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.
🎖@cveNotify
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.
🎖@cveNotify
🚨 CVE-2026-24537
Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.
🎖@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.
🎖@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress WP Accessibility Helper (WAH) Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-27423
Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.
🎖@cveNotify
Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Participants Database Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-57367
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
🎖@cveNotify
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress WP Booking System Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-57425
Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Autopay dla WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-57701
Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Real Estate Manager Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-57703
Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.
🎖@cveNotify
Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Sunshine Photo Cart Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-57767
Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WP Google Maps Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-57769
Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Grand Photography Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59512
Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Product Enquiry for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59513
Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.
🎖@cveNotify
Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Masteriyo - LMS Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59525
Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.
🎖@cveNotify
Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.
🎖@cveNotify
Patchstack
SQL Injection in WordPress Participants Database Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59544
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
🎖@cveNotify
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
🎖@cveNotify
Patchstack
PHP Object Injection in WordPress Thrive Quiz Builder Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59545
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
🎖@cveNotify
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
🎖@cveNotify
Patchstack
Broken Authentication in WordPress miniOrange Discord Integration Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.