🚨 CVE-2026-81769
Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation.
This issue affects Booking Hub: from n/a through 1.3.1.
🎖@cveNotify
Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation.
This issue affects Booking Hub: from n/a through 1.3.1.
🎖@cveNotify
Patchstack
Privilege Escalation in WordPress Booking Hub Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-81770
Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Interactive Geo Maps Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-81771
Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress TrustedSite Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-81772
Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.
🎖@cveNotify
Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.
🎖@cveNotify
Patchstack
PHP Object Injection in WordPress Ninja Forms - Layout & Styles Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
⚡1
🚨 CVE-2026-82223
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress WP Event SOlution Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-83562
Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.
🎖@cveNotify
Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.
🎖@cveNotify
🚨 CVE-2026-84217
Missing Authorization vulnerability in Mamunur Rashid Classified Listing allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Classified Listing: from n/a through 6.1.1.
🎖@cveNotify
Missing Authorization vulnerability in Mamunur Rashid Classified Listing allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Classified Listing: from n/a through 6.1.1.
🎖@cveNotify
🚨 CVE-2026-84759
Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.
🎖@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.
🎖@cveNotify
🚨 CVE-2026-84760
Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
🎖@cveNotify
🚨 CVE-2026-84764
Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
🎖@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
🎖@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Simply Schedule Appointments Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-84770
Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.
🎖@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.
🎖@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Mang Board WP Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-84771
Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions.
🎖@cveNotify
Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions.
🎖@cveNotify
🚨 CVE-2026-84772
Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions.
🎖@cveNotify
Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions.
🎖@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress Broken Link Checker Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-84775
Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions.
🎖@cveNotify
Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions.
🎖@cveNotify
Patchstack
Denial of Service Attack in WordPress Really Simple SSL Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-84780
Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions.
🎖@cveNotify
Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions.
🎖@cveNotify
Patchstack
Denial of Service Attack in WordPress WP Go Maps Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-84781
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.
🎖@cveNotify
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Gallery PhotoBlocks Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-84792
Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers with limited section permissions can relocate or publish entries to unauthorized sections by overwriting the sectionId attribute after initial authorization checks, bypassing the destination section permission validation.
🎖@cveNotify
Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers with limited section permissions can relocate or publish entries to unauthorized sections by overwriting the sectionId attribute after initial authorization checks, bypassing the destination section permission validation.
🎖@cveNotify
GitHub
Broken access control: a non-admin can move/publish entries into sections they cannot edit
The control panel inline-edit endpoint `element-indexes/save-elements` authorizes the current user against each element with `canSave()` before it applies client-supplied attributes, then mass-assi...
🚨 CVE-2026-84793
Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to sanitize input. Administrators can inject arbitrary JavaScript payloads in the site name that execute when other users view the control panel settings pages.
🎖@cveNotify
Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to sanitize input. Administrators can inject arbitrary JavaScript payloads in the site name that execute when other users view the control panel settings pages.
🎖@cveNotify
GitHub
Stored XSS in site name rendered without escaping
A stored Cross-Site Scripting (XSS) vulnerability exists in the site name field. The application fails to sanitize input, allowing an attacker to execute arbitrary JavaScript when another user view...
🚨 CVE-2026-84794
Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing unauthorized asset deletion and replacement.
🎖@cveNotify
Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing unauthorized asset deletion and replacement.
🎖@cveNotify
GitHub
Authorization Bypass in assets/move-asset
Craft CMS lacks an authorization check in `assets/move-asset` when the request includes `force=1`.
An authenticated Control Panel user who can manage their own assets in a volume, but does not h...
An authenticated Control Panel user who can manage their own assets in a volume, but does not h...