|
CVE-2026-49781
|
|
Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.
Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.
|
Critical
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-49776
|
|
SQL Injection in wordpress (CVE-2026-49776)
SQL injection in wordpress (CVE-2026-49776). Confidential information can be exposed externally.
|
Critical
|
WordPress
SQL Injection
Cwe 89
|
2 months ago
|
|
CVE-2026-49773
|
|
Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.
Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.
|
Medium
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-52695
|
|
Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.
Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.
|
High
|
Cwe 201
|
2 months ago
|
|
CVE-2026-49775
|
|
Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.
Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.
|
Medium
|
Cwe 862
|
2 months ago
|
|
CVE-2026-49766
|
|
Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.
Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.
|
Critical
|
Cwe 22
|
2 months ago
|
|
CVE-2026-49770
|
|
Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.
Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.
|
Critical
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-49765
|
|
Unsafe Deserialization in CVE-2026-49765 (CVE-2026-49765)
vulnerability in CVE-2026-49765 (CVE-2026-49765). Successful exploitation can lead to full system takeover.
|
Critical
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-49764
|
|
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.
|
Critical
|
Cwe 288
|
2 months ago
|
|
CVE-2026-49763
|
|
Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.
Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.
|
Critical
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-49110
|
|
Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.
Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.
|
High
|
Cwe 1284
|
2 months ago
|
|
CVE-2026-49105
|
|
Unsafe Deserialization in CVE-2026-49105 (CVE-2026-49105)
vulnerability in CVE-2026-49105 (CVE-2026-49105). Successful exploitation can lead to full system takeover.
|
Critical
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-49112
|
|
Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.
Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.
|
High
|
Path Traversal
Cwe 35
|
2 months ago
|
|
CVE-2026-49068
|
|
Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.
Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.
|
High
|
Cwe 497
|
2 months ago
|
|
CVE-2026-49055
|
|
Cross-Site Scripting (XSS) in CVE-2026-49055 (CVE-2026-49055)
cross-site scripting in CVE-2026-49055 (CVE-2026-49055). Risk of unauthorized operations or information disclosure.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-49082
|
|
Vulnerability in CVE-2026-49082 (CVE-2026-49082)
vulnerability in CVE-2026-49082 (CVE-2026-49082). Risk of unauthorized operations or information disclosure.
|
High
|
Cwe 201
|
2 months ago
|
|
CVE-2026-49067
|
|
Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.
Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.
|
Critical
|
SQL Injection
Cwe 89
|
2 months ago
|
|
CVE-2026-49106
|
|
Unsafe Deserialization in CVE-2026-49106 (CVE-2026-49106)
vulnerability in CVE-2026-49106 (CVE-2026-49106). Successful exploitation can lead to full system takeover.
|
Critical
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-49104
|
|
Unsafe Deserialization in CVE-2026-49104 (CVE-2026-49104)
vulnerability in CVE-2026-49104 (CVE-2026-49104). Successful exploitation can lead to full system takeover.
|
Critical
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-49083
|
|
Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.
Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.
|
High
|
Privilege Escalation
Cwe 266
|
2 months ago
|
|
CVE-2026-49070
|
|
Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.
Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.
|
High
|
Cwe 862
|
2 months ago
|
|
CVE-2026-49063
|
|
Unauthenticated Privilege Escalation in Listdom <= 5.5.0 versions.
Unauthenticated Privilege Escalation in Listdom <= 5.5.0 versions.
|
High
|
Privilege Escalation
Cwe 266
|
2 months ago
|
|
CVE-2026-49056
|
|
Vulnerability in CVE-2026-49056 (CVE-2026-49056)
vulnerability in CVE-2026-49056 (CVE-2026-49056). Confidential information can be exposed externally.
|
High
|
Cwe 497
|
2 months ago
|
|
CVE-2026-48970
|
|
Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.
Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.
|
High
|
Cwe 288
|
2 months ago
|
|
CVE-2026-49085
|
|
Unsafe Deserialization in CVE-2026-49085 (CVE-2026-49085)
vulnerability in CVE-2026-49085 (CVE-2026-49085). Successful exploitation can lead to full system takeover.
|
Critical
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-48965
|
|
Subscriber Sensitive Data Exposure in XCloner <= 4.8.6 versions.
Subscriber Sensitive Data Exposure in XCloner <= 4.8.6 versions.
|
Medium
|
Cwe 201
|
2 months ago
|
|
CVE-2026-49066
|
|
Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.
Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.
|
High
|
Cwe 497
|
2 months ago
|
|
CVE-2026-49043
|
|
Unauthenticated Cross Site Request Forgery (CSRF) in WP Migrate Lite <= 2.7.8 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in WP Migrate Lite <= 2.7.8 versions.
|
Medium
|
Cross-Site Request Forgery
Cwe 352
|
2 months ago
|
|
CVE-2026-49078
|
|
Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.
Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.
|
High
|
Cwe 1284
|
2 months ago
|
|
CVE-2026-48964
|
|
Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions.
Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions.
|
High
|
WordPress
SQL Injection
Cwe 89
|
2 months ago
|
|
CVE-2026-48889
|
|
Subscriber Privilege Escalation in Amelia <= 2.3 versions.
Subscriber Privilege Escalation in Amelia <= 2.3 versions.
|
High
|
Privilege Escalation
Cwe 266
|
2 months ago
|
|
CVE-2026-48966
|
|
Unauthenticated Cross Site Scripting (XSS) in Funnel Builder by FunnelKit <= 3.15.0.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Funnel Builder by FunnelKit <= 3.15.0.2 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-49109
|
|
Unsafe Deserialization in CVE-2026-49109 (CVE-2026-49109)
vulnerability in CVE-2026-49109 (CVE-2026-49109). Successful exploitation can lead to full system takeover.
|
Critical
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-49065
|
|
Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.
Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.
|
High
|
Cwe 862
|
2 months ago
|
|
CVE-2026-49061
|
|
Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions.
Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions.
|
High
|
Cwe 22
|
2 months ago
|
|
CVE-2026-48880
|
|
Subscriber Cross Site Scripting (XSS) in WP Job Portal <= 2.5.2 versions.
Subscriber Cross Site Scripting (XSS) in WP Job Portal <= 2.5.2 versions.
|
Medium
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-48881
|
|
Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.
Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.
|
Critical
|
Cwe 862
|
2 months ago
|
|
CVE-2026-48885
|
|
Unauthenticated Cross Site Scripting (XSS) in HollerBox <= 2.3.10.1 versions.
Unauthenticated Cross Site Scripting (XSS) in HollerBox <= 2.3.10.1 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-48871
|
|
Unauthenticated Cross Site Scripting (XSS) in MW WP Form <= 5.1.3 versions.
Unauthenticated Cross Site Scripting (XSS) in MW WP Form <= 5.1.3 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-48873
|
|
Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions.
Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions.
|
High
|
Cwe 862
|
2 months ago
|
|
CVE-2026-48887
|
|
Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.
Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.
|
Medium
|
JavaScript
Cwe 862
|
2 months ago
|
|
CVE-2026-48835
|
|
Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.
Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.
|
High
|
Cwe 862
|
2 months ago
|
|
CVE-2026-45439
|
|
Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.
Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.
|
Critical
|
SQL Injection
Cwe 89
|
2 months ago
|
|
CVE-2026-48886
|
|
Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions.
Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions.
|
Critical
|
JavaScript
SQL Injection
Cwe 89
|
2 months ago
|
|
CVE-2026-48872
|
|
Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions.
Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions.
|
High
|
Cwe 639
|
2 months ago
|
|
CVE-2026-48883
|
|
Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.
Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.
|
High
|
Cwe 862
|
2 months ago
|
|
CVE-2026-48836
|
|
Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.
Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.
|
Critical
|
Remote Code Execution
Cwe 94
|
2 months ago
|
|
CVE-2026-48874
|
|
Subscriber SQL Injection in GamiPress <= 7.8.7 versions.
Subscriber SQL Injection in GamiPress <= 7.8.7 versions.
|
High
|
SQL Injection
Cwe 89
|
2 months ago
|
|
CVE-2026-48838
|
|
Unauthenticated Cross Site Scripting (XSS) in Post SMTP <= 3.6.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Post SMTP <= 3.6.2 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-48876
|
|
Unauthenticated Cross Site Scripting (XSS) in Stop Spammers <= 2026.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Stop Spammers <= 2026.3 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|