🚨 CVE-2026-59530
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Stripe For WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59531
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
🎖@cveNotify
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
🎖@cveNotify
Patchstack
Unknown in WordPress Falcon – WordPress Optimizations & Tweaks Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59534
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Post My CF7 Form Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59535
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Thrive Product Manager Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59536
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress CoCart – Headless ecommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59537
Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions.
🎖@cveNotify
Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions.
🎖@cveNotify
Patchstack
SQL Injection in WordPress Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59539
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
🎖@cveNotify
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
🎖@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Paid Member Subscriptions Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59548
Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.
🎖@cveNotify
Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.
🎖@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Byteflows Travel & Hotel Booking Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59549
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
🎖@cveNotify
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
🎖@cveNotify
Patchstack
SQL Injection in WordPress rtMedia for WordPress, BuddyPress and bbPress Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59551
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
🎖@cveNotify
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
🎖@cveNotify
Patchstack
SQL Injection in WordPress rtMedia for WordPress, BuddyPress and bbPress Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59552
Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions.
🎖@cveNotify
Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions.
🎖@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress 3D Flipbook PDF Viewer & Embedder Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59553
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Product Feed Manager Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59556
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Dynamic Pricing With Discount Rules for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59557
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Events Made Easy Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59558
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Booking Calendar Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-59559
Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
🎖@cveNotify
Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.