๐จ CVE-2026-81651
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored settings of any gallery on the site, including its filesystem path, and including galleries belonging to other users.
๐@cveNotify
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored settings of any gallery on the site, including its filesystem path, and including galleries belonging to other users.
๐@cveNotify
WPScan
NextGEN Gallery < 4.5.0 - Authenticated Cross-Gallery Settings Modification via IDOR
See details on NextGEN Gallery < 4.5.0 - Authenticated Cross-Gallery Settings Modification via IDOR CVE 2026-81651. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-81652
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is entitled to a given image record before returning it, allowing users with the Contributor role and above to read the stored metadata of any image on the site, including images in galleries belonging to other users. The disclosed data includes the image's stored EXIF subset, covering camera make and model and capture timestamp, along with internal checksums and identifiers that the Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0's own capability-gated read path reserves to administrators.
๐@cveNotify
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is entitled to a given image record before returning it, allowing users with the Contributor role and above to read the stored metadata of any image on the site, including images in galleries belonging to other users. The disclosed data includes the image's stored EXIF subset, covering camera make and model and capture timestamp, along with internal checksums and identifiers that the Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0's own capability-gated read path reserves to administrators.
๐@cveNotify
WPScan
NextGEN Gallery < 4.5.0 - Contributor+ Image Metadata Disclosure via IDOR
See details on NextGEN Gallery < 4.5.0 - Contributor+ Image Metadata Disclosure via IDOR CVE 2026-81652. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-81653
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to delete, copy and re-tag any image on the site, including images in galleries belonging to other users.
๐@cveNotify
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to delete, copy and re-tag any image on the site, including images in galleries belonging to other users.
๐@cveNotify
WPScan
NextGEN Gallery < 4.5.0 - Authenticated Arbitrary Gallery Image Deletion via IDOR
See details on NextGEN Gallery < 4.5.0 - Authenticated Arbitrary Gallery Image Deletion via IDOR CVE 2026-81653. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-81654
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an administrator to change settings that apply across the whole site.
๐@cveNotify
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an administrator to change settings that apply across the whole site.
๐@cveNotify
WPScan
NextGEN Gallery < 4.5.0 - Authenticated Plugin Image Settings Update
See details on NextGEN Gallery < 4.5.0 - Authenticated Plugin Image Settings Update CVE 2026-81654. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-82842
The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which allows an attacker who can have the site's identity provider assert a login name of their choosing to authenticate as any account, including an administrator, without proving ownership of that account.
๐@cveNotify
The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which allows an attacker who can have the site's identity provider assert a login name of their choosing to authenticate as any account, including an administrator, without proving ownership of that account.
๐@cveNotify
WPScan
SAML Single Sign On < 6.0.0 - Unauthenticated Privilege Escalation via Account Matching
See details on SAML Single Sign On < 6.0.0 - Unauthenticated Privilege Escalation via Account Matching CVE 2026-82842. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-84223
The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site-wide, allowing users with author-level access and above to upload a file containing JavaScript which is then served from the site's own origin and runs in the session of anyone who opens it.
๐@cveNotify
The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site-wide, allowing users with author-level access and above to upload a file containing JavaScript which is then served from the site's own origin and runs in the session of anyone who opens it.
๐@cveNotify
WPScan
Kirki 6.0.0 - 6.3.0 - Author+ Stored XSS via Unsanitized SVG Upload
See details on Kirki 6.0.0 - 6.3.0 - Author+ Stored XSS via Unsanitized SVG Upload CVE 2026-84223. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-85017
The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the 2.0.18 to 2.0.19 releases raised the privilege required to reach the vulnerable action to editor-level, and the issue was fully resolved in 2.0.20.
๐@cveNotify
The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the 2.0.18 to 2.0.19 releases raised the privilege required to reach the vulnerable action to editor-level, and the issue was fully resolved in 2.0.20.
๐@cveNotify
WPScan
Unlimited Elements For Elementor < 2.0.20 - Subscriber+ PHP Object Injection
See details on Unlimited Elements For Elementor < 2.0.20 - Subscriber+ PHP Object Injection CVE 2026-85017. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-87067
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an administrator by default, and to any role the site has granted it through the Forminator Forms WordPress plugin before 1.57.2.1's own settings, so the issue is reachable well below administrator on sites that use that feature.
๐@cveNotify
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an administrator by default, and to any role the site has granted it through the Forminator Forms WordPress plugin before 1.57.2.1's own settings, so the issue is reachable well below administrator on sites that use that feature.
๐@cveNotify
WPScan
Forminator Forms < 1.57.2.1 - Authenticated RCE via XML-RPC PHP Object Injection
See details on Forminator Forms < 1.57.2.1 - Authenticated RCE via XML-RPC PHP Object Injection CVE 2026-87067. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-87068
The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may import quizzes to publish a live, publicly reachable form that grants any role, including administrator, to anyone who submits it. The same user is refused an identical form through both the ordinary form editor and the ordinary form import.
๐@cveNotify
The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may import quizzes to publish a live, publicly reachable form that grants any role, including administrator, to anyone who submits it. The same user is refused an identical form through both the ordinary form editor and the ordinary form import.
๐@cveNotify
WPScan
Forminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form Import
See details on Forminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form Import CVE 2026-87068. View the latest Plugin Vulnerabilities on WPScan.
โค1
๐จ CVE-2026-87839
The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.
๐@cveNotify
The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.
๐@cveNotify
WPScan
Tripzzy < 1.5.1 - Unauthenticated Arbitrary Comment Deletion
See details on Tripzzy < 1.5.1 - Unauthenticated Arbitrary Comment Deletion CVE 2026-87839. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-87840
The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative booking-management actions, which are additionally exposed to unauthenticated users and gated only by a token the Tripzzy WordPress plugin before 1.5.1 issues to any anonymous visitor on request, allowing unauthenticated attackers to alter the contents, stored totals and notes of arbitrary bookings.
๐@cveNotify
The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative booking-management actions, which are additionally exposed to unauthenticated users and gated only by a token the Tripzzy WordPress plugin before 1.5.1 issues to any anonymous visitor on request, allowing unauthenticated attackers to alter the contents, stored totals and notes of arbitrary bookings.
๐@cveNotify
WPScan
Tripzzy < 1.5.1 - Unauthenticated Booking Data Tampering
See details on Tripzzy < 1.5.1 - Unauthenticated Booking Data Tampering CVE 2026-87840. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-92410
The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability.
๐@cveNotify
The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability.
๐@cveNotify
WPScan
Sign-up Sheets < 2.4.0 - Arbitrary Sign-up Deletion via CSRF
See details on Sign-up Sheets < 2.4.0 - Arbitrary Sign-up Deletion via CSRF CVE 2026-92410. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-92422
The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a publicly reachable endpoint, allowing unauthenticated users to execute arbitrary registered shortcodes and disclose non-public gallery content.
๐@cveNotify
The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a publicly reachable endpoint, allowing unauthenticated users to execute arbitrary registered shortcodes and disclose non-public gallery content.
๐@cveNotify
WPScan
Meow Gallery < 5.5.5 - Unauthenticated Arbitrary Shortcode Execution via load_gallery_collection REST Route
See details on Meow Gallery < 5.5.5 - Unauthenticated Arbitrary Shortcode Execution via load_gallery_collection REST Route CVE 2026-92422. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-92423
The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above to disclose the titles, authors, dates and statuses of other users' draft and private posts.
๐@cveNotify
The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above to disclose the titles, authors, dates and statuses of other users' draft and private posts.
๐@cveNotify
WPScan
Meow Gallery < 5.5.5 - Author+ Draft and Private Post Disclosure via fetch_posts
See details on Meow Gallery < 5.5.5 - Author+ Draft and Private Post Disclosure via fetch_posts CVE 2026-92423. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-92540
The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator.
๐@cveNotify
The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator.
๐@cveNotify
WPScan
Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via caller_can_promote_users
See details on Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via caller_can_promote_users CVE 2026-92540. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-92541
The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.
๐@cveNotify
The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.
๐@cveNotify
WPScan
Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via Frontend Importer
See details on Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via Frontend Importer CVE 2026-92541. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-94030
A security vulnerability has been detected in SerenityOS up to 3d83e4509fd20d7438e1ae8470ffe668c136229c. Affected by this vulnerability is the function decode_bmp_pixel_data of the file Userland/Libraries/LibGfx/ImageFormats/BMPLoader.cpp of the component LibGfx. The manipulation of the argument height leads to integer overflow. The attack is possible to be carried out remotely. The attack's complexity is rated as high. The exploitation appears to be difficult. The exploit has been disclosed publicly and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The identifier of the patch is 007041bb2dd6d140c9e707caddfb0a49ecf96469. Applying a patch is the recommended action to fix this issue. This was reproducible with a minimal 55-byte PoC via the standard image-decode fuzz target but evidence for an actual exploitable defect is thin.
๐@cveNotify
A security vulnerability has been detected in SerenityOS up to 3d83e4509fd20d7438e1ae8470ffe668c136229c. Affected by this vulnerability is the function decode_bmp_pixel_data of the file Userland/Libraries/LibGfx/ImageFormats/BMPLoader.cpp of the component LibGfx. The manipulation of the argument height leads to integer overflow. The attack is possible to be carried out remotely. The attack's complexity is rated as high. The exploitation appears to be difficult. The exploit has been disclosed publicly and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The identifier of the patch is 007041bb2dd6d140c9e707caddfb0a49ecf96469. Applying a patch is the recommended action to fix this issue. This was reproducible with a minimal 55-byte PoC via the standard image-decode fuzz target but evidence for an actual exploitable defect is thin.
๐@cveNotify
GitHub
LibGfx: Reject BMPs with an unrepresentable height ยท SerenityOS/serenity@007041b
A signed DIB height may be negative for top-down images, but the
minimum signed value cannot be negated. Reject it while parsing so
size and frame decoding cannot overflow.
minimum signed value cannot be negated. Reject it while parsing so
size and frame decoding cannot overflow.
๐จ CVE-2026-94031
A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914. Affected by this issue is the function child_process.exec of the file src/auth/browser.ts of the component nexus_reauth MCP tool. The manipulation of the argument url results in command injection. The attack may be performed from remote. The exploit is now public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.
๐@cveNotify
A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914. Affected by this issue is the function child_process.exec of the file src/auth/browser.ts of the component nexus_reauth MCP tool. The manipulation of the argument url results in command injection. The attack may be performed from remote. The exploit is now public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.
๐@cveNotify
GitHub
GitHub - 0-Gaurav-0/nexus-mcp: Universal multi-AI gateway MCP server
Universal multi-AI gateway MCP server. Contribute to 0-Gaurav-0/nexus-mcp development by creating an account on GitHub.
๐จ CVE-2026-94032
A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown part of the file /module/department/index.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
๐@cveNotify
A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown part of the file /module/department/index.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
๐@cveNotify
GitHub
itsourcecode Leave Management System V1.0 SQL Injection Vulnerability ยท Issue #15 ยท ltranquility/submit_repository
itsourcecode Leave Management System V1.0 SQL Injection Vulnerability NAME OF AFFECTED PRODUCT(S) Leave Management System Vendor Homepage https://itsourcecode.com/free-projects/php-project/leave-ma...
๐จ CVE-2026-94033
A vulnerability has been found in SourceCodester Drug Recommendation System 1.0. This vulnerability affects unknown code of the file /drug_recommender/Admin/add_user of the component User Management. Such manipulation of the argument txtname/txtemail/txtpassword leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
๐@cveNotify
A vulnerability has been found in SourceCodester Drug Recommendation System 1.0. This vulnerability affects unknown code of the file /drug_recommender/Admin/add_user of the component User Management. Such manipulation of the argument txtname/txtemail/txtpassword leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
๐@cveNotify
GitHub
Drug_recommendation_system/xss/add_user/Readme.md at main ยท KaranParelkar/Drug_recommendation_system
Vulnerabilities found in drug recommendation system - KaranParelkar/Drug_recommendation_system
๐จ CVE-2026-94034
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /drug_recommender/Admin/change_password of the component Password Change. Performing a manipulation of the argument txtoldpassword/txtnewpassword results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and could be used.
๐@cveNotify
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /drug_recommender/Admin/change_password of the component Password Change. Performing a manipulation of the argument txtoldpassword/txtnewpassword results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and could be used.
๐@cveNotify
GitHub
Drug_recommendation_system/xss/change_password/Readme.md at main ยท KaranParelkar/Drug_recommendation_system
Vulnerabilities found in drug recommendation system - KaranParelkar/Drug_recommendation_system