🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-15946 The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authori... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-13191 The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 2.... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-9832 The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions u... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-1242 The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-13770 The AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) plugin for WordPress is vulnerable to Stored Cr... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-4792 The Bread plugin for WordPress is vulnerable to information exposure in versions up to and including 2.9.12. This is due to the lack of authentication... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-2278 The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blo... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-15947 The Metasync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_instant_indexing_se... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-15664 The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multipl... | HIGH | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-11899 The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorization bypass in all versions up ... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-11608 The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-9615 The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. This is due to the license_acti... | MEDIUM | ????? | ????? | NVD | 10 hours ago |
| CVE-2026-92435 The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission c... | UNKNOWN | ????? | ????? | NVD | 12 hours ago |
| CVE-2026-92430 The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX paymen... | UNKNOWN | ????? | ????? | NVD | 12 hours ago |
| CVE-2026-92425 The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks o... | UNKNOWN | ????? | ????? | NVD | 12 hours ago |
| CVE-2026-92421 The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified ... | UNKNOWN | ????? | ????? | NVD | 12 hours ago |
| CVE-2026-92420 The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the reques... | UNKNOWN | ????? | ????? | NVD | 12 hours ago |
| CVE-2026-92404 The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to re... | UNKNOWN | ????? | ????? | NVD | 12 hours ago |
| CVE-2026-92403 The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rend... | UNKNOWN | ????? | ????? | NVD | 12 hours ago |
| CVE-2026-92099 The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a... | UNKNOWN | ????? | ????? | NVD | 12 hours ago |