🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-87831 The Checkout Field Manager plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 7.9.6. This is due to a mis... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-87829 The Checkout Field Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.9.6. This is... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-50605 A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insufficient access controls withi... | UNKNOWN | ????? | ????? | NVD | 5 days ago |
| CVE-2026-86320 A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-87963 The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and re... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-91017 The Robokassa payment gateway for Woocommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 1.8.8. This i... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-86801 The To Do List Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions 1.4 to 1.6. This is due to insufficient input ... | HIGH | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-90982 @fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4, on a case-insensitive filesy... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-44940 The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than manag... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-91019 The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.5.0. This ... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-91016 The Motors plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.4.120. This is due to missin... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-91015 The Master Addons for Elementor plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.1.8. This is due to ... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-91014 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-91011 The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.7.6. This is due to... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-91010 The Invisible Anti-Spam & CAPTCHA plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.1.0. This is d... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-91009 The Active Products Tables for WooCommerce plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.1.2. This... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-91008 The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including,... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-90923 The Autopay plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.0.0. This is due to a missing capability... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-90922 The Paid Member Subscriptions plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 3.0.8. This is due to a lack ... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-88904 The PuppyFW plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.4.4. This is due to insufficient restri... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |