🚨 CVE-2026-73190
Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WPDM – Premium Packages Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-73341
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
🎖@cveNotify
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
🎖@cveNotify
Patchstack
PHP Object Injection in WordPress RegistrationMagic Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-73343
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
🎖@cveNotify
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
🎖@cveNotify
🚨 CVE-2026-73360
Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Chaty Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-73367
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
🎖@cveNotify
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
🎖@cveNotify
Patchstack
Remote File Inclusion in WordPress Easy Google Maps Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-73377
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Ultimate Maps by Supsystic Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-73379
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
🎖@cveNotify
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
🎖@cveNotify
Patchstack
undefined in undefined undefined undefined
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-73382
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Site Reviews Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-73396
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
🎖@cveNotify
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
🎖@cveNotify
Patchstack
Broken Authentication in WordPress MWB HubSpot for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-73398
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
🎖@cveNotify
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
🎖@cveNotify
Patchstack
Broken Authentication in WordPress Piraeus Bank WooCommerce Payment Gateway Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-74003
Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
🎖@cveNotify
Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress RomethemeForm For Elementor Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-74009
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.
🎖@cveNotify
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.
🎖@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Razorpay for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-12564
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role authentication is tested. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access to the control plane namespaces with full pod CRUD and secret read permissions, including database credentials and the Django SECRET_KEY.
🎖@cveNotify
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role authentication is tested. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access to the control plane namespaces with full pod CRUD and secret read permissions, including database credentials and the Django SECRET_KEY.
🎖@cveNotify
Redhat
CVE-2026-12564 - Red Hat Customer Portal
CVE Details App