🚨 CVE-2026-9066
The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's loader injects script elements pointing to an attacker-controlled origin, which lets the attacker execute arbitrary JavaScript in the visitor's session on the target site.
🎖@cveNotify
The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's loader injects script elements pointing to an attacker-controlled origin, which lets the attacker execute arbitrary JavaScript in the visitor's session on the target site.
🎖@cveNotify
WPScan
WP Compress < 7.10.04 - Reflected XSS via test_zone
See details on WP Compress < 7.10.04 - Reflected XSS via test_zone CVE 2026-9066. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-9577
The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in the administrator's session when they are tricked into following a crafted URL.
🎖@cveNotify
The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in the administrator's session when they are tricked into following a crafted URL.
🎖@cveNotify
WPScan
Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter
See details on Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter CVE 2026-9577. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-59677
A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in
unconfined context
This issue affects policycoreutils through 3.10.
🎖@cveNotify
A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in
unconfined context
This issue affects policycoreutils through 3.10.
🎖@cveNotify
🚨 CVE-2026-59678
An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager.
This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.
🎖@cveNotify
An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager.
This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.
🎖@cveNotify
🚨 CVE-2026-16745
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.
🎖@cveNotify
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.
🎖@cveNotify
🚨 CVE-2026-24639
Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
🎖@cveNotify
Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
🎖@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress Photo Block Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-27403
Contributor Cross Site Scripting (XSS) in Hubbub Lite <= 1.36.3 versions.
🎖@cveNotify
Contributor Cross Site Scripting (XSS) in Hubbub Lite <= 1.36.3 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Hubbub Lite Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-57373
Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.
🎖@cveNotify
Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Funnel Kit Funnel Builder PRO Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-57428
Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Sprout Clients Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
❤1
🚨 CVE-2026-57626
Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery.
This issue affects MailPoet: from 5.30.0 through 5.33.0.
🎖@cveNotify
Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery.
This issue affects MailPoet: from 5.30.0 through 5.33.0.
🎖@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress MailPoet Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-57716
Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.
🎖@cveNotify
Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.
🎖@cveNotify
Patchstack
Arbitrary File Deletion in WordPress Broadcast Live Video Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-57785
Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.
🎖@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.
🎖@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress ApusListing Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-57809
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress AffiliateWP Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59517
Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Easy Form Builder Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59524
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
🎖@cveNotify
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
🎖@cveNotify
Patchstack
Broken Authentication in WordPress Easy Digital Downloads Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59543
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
🎖@cveNotify
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
🎖@cveNotify
Patchstack
Remote Code Execution (RCE) in WordPress Advanced Views Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-61943
Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress WPDM – Premium Packages Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-61948
Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
🎖@cveNotify
Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
🎖@cveNotify
Patchstack
SQL Injection in WordPress WPDM – Premium Packages Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.