🚨 CVE-2026-81288
Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Upsell Order Bump Offer for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-81289
Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions.
🎖@cveNotify
🚨 CVE-2026-81769
Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation.
This issue affects Booking Hub: from n/a through 1.3.1.
🎖@cveNotify
Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation.
This issue affects Booking Hub: from n/a through 1.3.1.
🎖@cveNotify
Patchstack
Privilege Escalation in WordPress Booking Hub Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-81770
Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Interactive Geo Maps Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-81771
Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress TrustedSite Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-81772
Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.
🎖@cveNotify
Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.
🎖@cveNotify
Patchstack
PHP Object Injection in WordPress Ninja Forms - Layout & Styles Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
⚡1
🚨 CVE-2026-82223
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress WP Event SOlution Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-83562
Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.
🎖@cveNotify
Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.
🎖@cveNotify
🚨 CVE-2026-84217
Missing Authorization vulnerability in Mamunur Rashid Classified Listing allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Classified Listing: from n/a through 6.1.1.
🎖@cveNotify
Missing Authorization vulnerability in Mamunur Rashid Classified Listing allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Classified Listing: from n/a through 6.1.1.
🎖@cveNotify
🚨 CVE-2026-84759
Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.
🎖@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.
🎖@cveNotify
🚨 CVE-2026-84760
Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
🎖@cveNotify
🚨 CVE-2026-84764
Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
🎖@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
🎖@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Simply Schedule Appointments Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-84770
Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.
🎖@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.
🎖@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Mang Board WP Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-84771
Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions.
🎖@cveNotify
Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions.
🎖@cveNotify
🚨 CVE-2026-84772
Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions.
🎖@cveNotify
Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions.
🎖@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress Broken Link Checker Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-84775
Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions.
🎖@cveNotify
Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions.
🎖@cveNotify
Patchstack
Denial of Service Attack in WordPress Really Simple SSL Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-84780
Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions.
🎖@cveNotify
Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions.
🎖@cveNotify
Patchstack
Denial of Service Attack in WordPress WP Go Maps Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-84781
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.
🎖@cveNotify
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Gallery PhotoBlocks Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-84792
Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers with limited section permissions can relocate or publish entries to unauthorized sections by overwriting the sectionId attribute after initial authorization checks, bypassing the destination section permission validation.
🎖@cveNotify
Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers with limited section permissions can relocate or publish entries to unauthorized sections by overwriting the sectionId attribute after initial authorization checks, bypassing the destination section permission validation.
🎖@cveNotify
GitHub
Broken access control: a non-admin can move/publish entries into sections they cannot edit
The control panel inline-edit endpoint `element-indexes/save-elements` authorizes the current user against each element with `canSave()` before it applies client-supplied attributes, then mass-assi...