🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-74005 The Issues and Series for Newspapers, Magazines, Publishers, Writers plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions ... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-74002 The Booking Calendar plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 11.7. This is due to a missing ca... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-74000 The Simple Membership plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 4.8.2. This is due to a missing ... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-73999 The Cooked – Recipe Management plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.16.0. ... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-66676 The Easy Invoice – Invoice Generator, PDF Quotes & Payments plugin for WordPress is vulnerable to unauthorized access in all versions up to, and... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-66631 The MoreConvert Wishlist for WooCommerce plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.9.21. This is due... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-66630 The Issues and Series for Newspapers, Magazines, Publishers, Writers plugin for WordPress is vulnerable to SQL Injection in all versions up to, and in... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-66628 The WP-Lister Lite for eBay plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.8.11. This is due to insuffici... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-66626 The SKT Addons for Elementor plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.0. This is due to insufficien... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-66625 The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to SQL Injection in all versio... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-66624 The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.22.0. Th... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-66619 The Newsletters plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.18. This is due to insufficient escaping o... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-66618 The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to SQL Injection in ... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-66617 The Issues and Series for Newspapers, Magazines, Publishers, Writers plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-66608 The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.19. T... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-66580 The Product Feed Manager for WooCommerce – RexFeed – Sell on 200+ Shopping Channels plugin for WordPress is vulnerable to SQL Injection in all ver... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-66579 The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.2.1. This is due to insuff... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-66578 The Property Hive plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.2.6. This is due to insuff... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-66577 The JetSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.6.3. This is due to insufficie... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-66576 The JetBlocks for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.5.2. This is due... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |