π¨ CVE-2026-82300
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).
π@cveNotify
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).
π@cveNotify
Discuss the Elastic Stack
Elasticsearch 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-176)
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). Affected Versions: 8.x: All versions fromβ¦
π¨ CVE-2026-94396
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Discuss the Elastic Stack
Elasticsearch 9.4.7, 9.5.4 Security Update (ESA-2026-182)
Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Affected Versions: 9.x: All versions from 9.2.0β¦
π¨ CVE-2026-94397
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Discuss the Elastic Stack
Elasticsearch 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-183)
Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Affected Versions: 8.x: All versions from 8.0.0β¦
π¨ CVE-2026-94398
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Discuss the Elastic Stack
Elasticsearch 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-179)
Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Affected Versions: 8.x: All versions from 8.12.0β¦
π¨ CVE-2026-94399
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Discuss the Elastic Stack
Elasticsearch 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-180)
Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Affected Versions: 8.x: All versions from 8.0.0β¦
π¨ CVE-2026-94400
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Discuss the Elastic Stack
Kibana 8.19.22, 9.4.7, 9.5.3 Security Update (ESA-2026-181)
Uncontrolled Resource Consumption in Kibana Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130) Affected Versions: Fixes should be back-ported to all maintainedβ¦
π¨ CVE-2026-94408
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Discuss the Elastic Stack
Elasticsearch 8.19.22, 9.4.7, 9.5.3 Security Update (ESA-2026-184)
Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Affected Versions: 8.x: All versions from 8.0.0β¦
π¨ CVE-2026-81655
The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there, allowing users with a role as low as subscriber to store code which is then executed as PHP or served unescaped to site visitors.
π@cveNotify
The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there, allowing users with a role as low as subscriber to store code which is then executed as PHP or served unescaped to site visitors.
π@cveNotify
WPScan
Ad Inserter 2.8.12 - 2.8.18 - Subscriber+ RCE / Stored XSS via Global Custom Fields
See details on Ad Inserter 2.8.12 - 2.8.18 - Subscriber+ RCE / Stored XSS via Global Custom Fields CVE 2026-81655. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-82841
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration state, allowing any authenticated user, such as a subscriber, to retrieve the credentials of the configured backup destinations, such as passwords and secret keys.
π@cveNotify
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration state, allowing any authenticated user, such as a subscriber, to retrieve the credentials of the configured backup destinations, such as passwords and secret keys.
π@cveNotify
WPScan
UpdraftPlus 1.23.8 - 1.26.7 - Subscriber+ Remote Storage Credential Disclosure via Migration Notice
See details on UpdraftPlus 1.23.8 - 1.26.7 - Subscriber+ Remote Storage Credential Disclosure via Migration Notice CVE 2026-82841. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-84069
The WebFacingβ’ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate a user-supplied path before using it to include a local file, allowing unauthenticated users to perform Local File Inclusion.
π@cveNotify
The WebFacingβ’ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate a user-supplied path before using it to include a local file, allowing unauthenticated users to perform Local File Inclusion.
π@cveNotify
WPScan
WebFacing Email Accounts for cPanel 5.3 - 5.3.6 - Unauthenticated LFI via assets/index.php
See details on WebFacing Email Accounts for cPanel 5.3 - 5.3.6 - Unauthenticated LFI via assets/index.php CVE 2026-84069. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-85002
The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post.
π@cveNotify
The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post.
π@cveNotify
WPScan
EmbedPress < 4.6.7 - Contributor+ Stored XSS via Instagram Carousel Block Attributes
See details on EmbedPress < 4.6.7 - Contributor+ Stored XSS via Instagram Carousel Block Attributes CVE 2026-85002. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-86609
The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature.
π@cveNotify
The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature.
π@cveNotify
WPScan
Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription
See details on Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription CVE 2026-86609. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-86839
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information.
π@cveNotify
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information.
π@cveNotify
WPScan
Bookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and Deletion via IDOR
See details on Bookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and Deletion via IDOR CVE 2026-86839. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-86841
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly assign, to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets.
π@cveNotify
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly assign, to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets.
π@cveNotify
WPScan
Bookly 23.2 - 28.2 - Bookly Administrator+ PHP Object Injection via Diagnostics Advanced Options
See details on Bookly 23.2 - 28.2 - Bookly Administrator+ PHP Object Injection via Diagnostics Advanced Options CVE 2026-86841. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-89000
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to internal-only resources and read the responses back.
π@cveNotify
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to internal-only resources and read the responses back.
π@cveNotify
WPScan
WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run
See details on WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run CVE 2026-89000. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-89001
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing users with contributor-level access and above to publish posts live and set any registered user, including an administrator, as the post author.
π@cveNotify
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing users with contributor-level access and above to publish posts live and set any registered user, including an administrator, as the post author.
π@cveNotify
WPScan
WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Post Publication and Author Spoofing via Campaign Settings
See details on WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Post Publication and Author Spoofing via Campaign Settings CVE 2026-89001. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-89003
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses back.
π@cveNotify
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses back.
π@cveNotify
WPScan
WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Preview
See details on WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Preview CVE 2026-89003. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-89006
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
π@cveNotify
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
π@cveNotify
WPScan
WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import
See details on WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import CVE 2026-89006. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-92436
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents.
π@cveNotify
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents.
π@cveNotify
WPScan
Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via IDOR
See details on Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via IDOR CVE 2026-92436. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-101041
The account recovery (password reset) functionality in the vulnerability-lookup web application contains a time-of-check-to-time-of-use (TOCTOU) race condition in the consumption of single-use recovery tokens. The original implementation verified the token nonce against the stored digest and then consumed (cleared) it in separate database operations. Two concurrent HTTP requests presenting the same valid recovery token could both pass the verification check before either transaction committed, allowing both to set their own password on the target account. The last transaction to commit overwrites the first, enabling an attacker who possesses a valid recovery token to replace the legitimate user's password with one of their choosing.
A secondary defect in the same endpoint (confirm_account) allowed a valid recovery link to be used to set an empty or trivially short password (e.g., three characters). The view handler performed only a manual equality comparison between the two password fields and never invoked the form's validation logic, bypassing the intended minimum-length and complexity constraints.
The affected component is the user account recovery endpoint (/user/confirm_account/<token>) and the associated token verification and consumption logic in the User model (website/models/user.py) and the view layer (website/web/views/user.py).
π@cveNotify
The account recovery (password reset) functionality in the vulnerability-lookup web application contains a time-of-check-to-time-of-use (TOCTOU) race condition in the consumption of single-use recovery tokens. The original implementation verified the token nonce against the stored digest and then consumed (cleared) it in separate database operations. Two concurrent HTTP requests presenting the same valid recovery token could both pass the verification check before either transaction committed, allowing both to set their own password on the target account. The last transaction to commit overwrites the first, enabling an attacker who possesses a valid recovery token to replace the legitimate user's password with one of their choosing.
A secondary defect in the same endpoint (confirm_account) allowed a valid recovery link to be used to set an empty or trivially short password (e.g., three characters). The view handler performed only a manual equality comparison between the two password fields and never invoked the form's validation logic, bypassing the intended minimum-length and complexity constraints.
The affected component is the user account recovery endpoint (/user/confirm_account/<token>) and the associated token verification and consumption logic in the User model (website/models/user.py) and the view layer (website/web/views/user.py).
π@cveNotify
GitHub
Fix recovery token consumption race Β· vulnerability-lookup/vulnerability-lookup@5462bab
Vulnerability-Lookup facilitates quick correlation of vulnerabilities from various sources, independent of vulnerability IDs, and streamlines the management of Coordinated Vulnerability Disclosure (CVD). - Fix recovery token consumption race Β· vulnerabilityβ¦
π¨ CVE-2026-84744
The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts.
π@cveNotify
The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts.
π@cveNotify
WPScan
WPForms Lite 1.5.0.1 - 2.0.2 - Unauthenticated Arbitrary Shortcode Execution via Form Field Repopulation
See details on WPForms Lite 1.5.0.1 - 2.0.2 - Unauthenticated Arbitrary Shortcode Execution via Form Field Repopulation CVE 2026-84744. View the latest Plugin Vulnerabilities on WPScan.