🚨 CVE-2026-61948
Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
🎖@cveNotify
Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
🎖@cveNotify
Patchstack
SQL Injection in WordPress WPDM – Premium Packages Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-61972
Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
🎖@cveNotify
Patchstack
undefined in undefined undefined undefined
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65460
Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.
🎖@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.
🎖@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Zarinpal Gateway Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65465
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
🎖@cveNotify
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress JetElements For Elementor Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65466
Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
🎖@cveNotify
Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
🎖@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress JetBooking Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65471
Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
🎖@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
🎖@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Avada Core Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65472
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Kit (formerly ConvertKit) Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65474
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
🎖@cveNotify
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
🎖@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Ninja Tables Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65490
Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.
🎖@cveNotify
Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.
🎖@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Create by Mediavine Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.