🚨 CVE-2026-66424
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
🎖@cveNotify
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
🎖@cveNotify
Patchstack
Privilege Escalation in WordPress SMS Alert Order Notifications Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66429
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Visitor Traffic Real Time Statistics Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66430
Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
🎖@cveNotify
Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
🎖@cveNotify
Patchstack
SQL Injection in WordPress Visitor Traffic Real Time Statistics Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66431
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66436
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
🎖@cveNotify
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
🎖@cveNotify
Patchstack
SQL Injection in WordPress Active Products Tables for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66441
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress MultiVendorX Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66443
Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.
🎖@cveNotify
Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.
🎖@cveNotify
Patchstack
Sensitive Data Exposure in WordPress REST API Log Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66444
Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.
🎖@cveNotify
Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.
🎖@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Payment Forms for Paystack Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66446
Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
🎖@cveNotify
Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
🎖@cveNotify
Patchstack
SQL Injection in WordPress If-So Dynamic Content Personalization Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66449
Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Geo Mashup Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66453
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
🎖@cveNotify
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
🎖@cveNotify
Patchstack
Broken Authentication in WordPress Salon booking system Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66454
Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress WP Social Avatar Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66456
Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
🎖@cveNotify
Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Profile Extra Fields by BestWebSoft Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66460
Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions.
🎖@cveNotify
Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress AfterShip Tracking Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.