๐จ CVE-2026-78617
WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed attempts, but this setting is not enabled by default.
๐@cveNotify
WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed attempts, but this setting is not enabled by default.
๐@cveNotify
๐จ CVE-2026-78618
A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially crafted request.
๐@cveNotify
A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially crafted request.
๐@cveNotify
๐จ CVE-2026-82082
NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
๐@cveNotify
NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
๐@cveNotify
๐จ CVE-2026-12513
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission and their single-pass traversal filter is bypassable, allowing unauthenticated users to store a path that points outside the uploads directory. When the corresponding file entry is later permanently deleted, an arbitrary file on the server (such as wp-config.php) is deleted, leading to denial of service and potential site takeover.
๐@cveNotify
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission and their single-pass traversal filter is bypassable, allowing unauthenticated users to store a path that points outside the uploads directory. When the corresponding file entry is later permanently deleted, an arbitrary file on the server (such as wp-config.php) is deleted, leading to denial of service and potential site takeover.
๐@cveNotify
WPScan
Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Traversal
See details on Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Traversal CVE 2026-12513. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-12514
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capability check in their file-upload handler, which is registered for unauthenticated users and protected only by a nonce that is output on public pages, so an unauthenticated visitor can upload files to a publicly accessible directory and read the server's absolute path from the response. Uploads are limited to WordPress's allowed MIME types, so executable PHP cannot be uploaded.
๐@cveNotify
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capability check in their file-upload handler, which is registered for unauthenticated users and protected only by a nonce that is output on public pages, so an unauthenticated visitor can upload files to a publicly accessible directory and read the server's absolute path from the response. Uploads are limited to WordPress's allowed MIME types, so executable PHP cannot be uploaded.
๐@cveNotify
WPScan
Shared Files < 1.7.70 - Unauthenticated Limited File Upload
See details on Shared Files < 1.7.70 - Unauthenticated Limited File Upload CVE 2026-12514. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14558
The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable POP chain is present on the site.
๐@cveNotify
The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable POP chain is present on the site.
๐@cveNotify
WPScan
WP User Frontend < 4.3.10 - Editor+ PHP Object Injection via AI Form Builder
See details on WP User Frontend < 4.3.10 - Editor+ PHP Object Injection via AI Form Builder CVE 2026-14558. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14567
The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address and phone number of every registered user, including administrators.
๐@cveNotify
The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address and phone number of every registered user, including administrators.
๐@cveNotify
WPScan
WP User Frontend < 4.3.10 - Unauthenticated User Email and Phone Disclosure via User Directory
See details on WP User Frontend < 4.3.10 - Unauthenticated User Email and Phone Disclosure via User Directory CVE 2026-14567. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-19084
The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL.
๐@cveNotify
The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL.
๐@cveNotify
WPScan
Shared Files < 1.7.70 - Unauthenticated Arbitrary File Read
See details on Shared Files < 1.7.70 - Unauthenticated Arbitrary File Read CVE 2026-19084. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-19423
The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form permits, and screens the value against the site's registered role names rather than against the form's own allow-list, allowing unauthenticated users who register through the Ultimate Member WordPress plugin before 2.13.0's own form to grant themselves arbitrary capabilities and reach administrator-equivalent access.
๐@cveNotify
The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form permits, and screens the value against the site's registered role names rather than against the form's own allow-list, allowing unauthenticated users who register through the Ultimate Member WordPress plugin before 2.13.0's own form to grant themselves arbitrary capabilities and reach administrator-equivalent access.
๐@cveNotify
WPScan
Ultimate Member 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation via Role Field on Profile Forms
See details on Ultimate Member 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation via Role Field on Profile Forms CVE 2026-19423. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-77701
The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create refund requests against any guest checkout order on the site.
๐@cveNotify
The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create refund requests against any guest checkout order on the site.
๐@cveNotify
WPScan
WCFM Marketplace < 3.8.2 - Unauthenticated Refund Request Creation on Guest Orders
See details on WCFM Marketplace < 3.8.2 - Unauthenticated Refund Request Creation on Guest Orders CVE 2026-77701. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-79615
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users.
๐@cveNotify
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users.
๐@cveNotify
WPScan
Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Question Bank and Answer Key Disclosure via IDOR
See details on Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Question Bank and Answer Key Disclosure via IDOR CVE 2026-79615. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-79706
The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to build the paths of the files it caches, allowing unauthenticated attackers to create files at arbitrary locations on the server, outside the intended cache directory.
๐@cveNotify
The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to build the paths of the files it caches, allowing unauthenticated attackers to create files at arbitrary locations on the server, outside the intended cache directory.
๐@cveNotify
WPScan
Breeze Cache < 2.5.13 - Unauthenticated File Creation via Cache Path Traversal
See details on Breeze Cache < 2.5.13 - Unauthenticated File Creation via Cache Path Traversal CVE 2026-79706. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-79995
The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email change is being cancelled belongs to the user making the request, allowing authenticated users with Subscriber-level access and above to cancel any other user's in-progress email change, including an administrator's.
๐@cveNotify
The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email change is being cancelled belongs to the user making the request, allowing authenticated users with Subscriber-level access and above to cancel any other user's in-progress email change, including an administrator's.
๐@cveNotify
WPScan
User Registration & Membership < 5.2.5 - Subscriber+ Pending Email Change Cancellation via IDOR
See details on User Registration & Membership < 5.2.5 - Subscriber+ Pending Email Change Cancellation via IDOR CVE 2026-79995. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-79996
The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change arbitrary site options and escalate their privileges to administrator.
๐@cveNotify
The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change arbitrary site options and escalate their privileges to administrator.
๐@cveNotify
WPScan
User Registration & Membership < 5.2.6 - Authenticated Privilege Escalation via Login Settings
See details on User Registration & Membership < 5.2.6 - Authenticated Privilege Escalation via Login Settings CVE 2026-79996. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-82233
SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolute file paths without workspace boundary validation. Attackers can induce the AI Agent to upload sensitive files such as SSH keys or credentials from outside the workspace into the asset directory through prompt injection.
๐@cveNotify
SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolute file paths without workspace boundary validation. Attackers can induce the AI Agent to upload sensitive files such as SSH keys or credentials from outside the workspace into the asset directory through prompt injection.
๐@cveNotify
GitHub
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
# Security Advisory โ SiYuan MCP `asset.upload` Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
| Field | Value |
|---|---|
| **Disclosed by** | joysinleung (`joysinleung@gmail...
| Field | Value |
|---|---|
| **Disclosed by** | joysinleung (`joysinleung@gmail...
๐จ CVE-2026-3423
The Envira Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the gallery 'description' configuration field in all versions up to, and including, 1.12.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses a page displaying the gallery with a description enabled.
๐@cveNotify
The Envira Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the gallery 'description' configuration field in all versions up to, and including, 1.12.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses a page displaying the gallery with a description enabled.
๐@cveNotify
๐จ CVE-2026-5096
The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the `load_previous_field_value()` method in `class-evf-form-task.php` accepting arbitrary URL values from `$_POST` data for upload fields without domain restriction, which are then passed to `wp_remote_head()` in the `get_local_file_size()` method of `class-evf-form-fields-upload.php`. This makes it possible for unauthenticated attackers to force the WordPress server to make outbound HTTP HEAD requests to arbitrary URLs by submitting a form with an upload field containing a malicious URL while leaving a required field empty to trigger form re-rendering.
๐@cveNotify
The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the `load_previous_field_value()` method in `class-evf-form-task.php` accepting arbitrary URL values from `$_POST` data for upload fields without domain restriction, which are then passed to `wp_remote_head()` in the `get_local_file_size()` method of `class-evf-form-fields-upload.php`. This makes it possible for unauthenticated attackers to force the WordPress server to make outbound HTTP HEAD requests to arbitrary URLs by submitting a form with an upload field containing a malicious URL while leaving a required field empty to trigger form re-rendering.
๐@cveNotify
๐จ CVE-2026-5934
The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.21.0.1. This is due to insufficient input sanitization and output escaping of user-supplied data via the rocket_beacon AJAX endpoint. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
๐@cveNotify
The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.21.0.1. This is due to insufficient input sanitization and output escaping of user-supplied data via the rocket_beacon AJAX endpoint. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
๐@cveNotify
GitHub
Release 3.21.1 ยท wp-media/wp-rocket
Changelog
Enhancement: New recommendations added to Rocket Insights related to RocketCDN and Imagify (#8216)
Enhancement: Improve Rocket Insights copywriting (#8219, #8221, #8228)
Enhancement: Cle...
Enhancement: New recommendations added to Rocket Insights related to RocketCDN and Imagify (#8216)
Enhancement: Improve Rocket Insights copywriting (#8219, #8221, #8228)
Enhancement: Cle...
๐จ CVE-2026-6176
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and including 5.106.0. This is due to insufficient input sanitization and output escaping on user-supplied review comment text. The plugin accepts review submissions from unauthenticated users through the 'cr_local_forms_submit' AJAX action without sanitizing HTML content before storing it via wp_insert_comment(), and later renders this stored content on product pages through comment_text() without proper escaping. This makes it possible for unauthenticated attackers with a valid review form URL (obtainable through review reminder emails sent to customers who placed orders) to inject arbitrary web scripts in pages that will execute whenever a user accesses the affected product page.
๐@cveNotify
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and including 5.106.0. This is due to insufficient input sanitization and output escaping on user-supplied review comment text. The plugin accepts review submissions from unauthenticated users through the 'cr_local_forms_submit' AJAX action without sanitizing HTML content before storing it via wp_insert_comment(), and later renders this stored content on product pages through comment_text() without proper escaping. This makes it possible for unauthenticated attackers with a valid review form URL (obtainable through review reminder emails sent to customers who placed orders) to inject arbitrary web scripts in pages that will execute whenever a user accesses the affected product page.
๐@cveNotify
๐จ CVE-2026-81284
Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
๐@cveNotify
Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress ACF Extended Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81285
Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.
๐@cveNotify
Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.
๐@cveNotify
Patchstack
Denial of Service Attack in WordPress Smush Image Compression and Optimization Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.