🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-90976 The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an account in its registration handle... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-88994 The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is includ... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-86800 The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disabling its login and URL hi... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-86796 The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, thr... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-79713 The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-cache key while still caching ... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-90984 The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its PDF renderer performs on ... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-90978 The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonce field is omitted, and applie... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-89008 The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-re... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-89007 The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deleti... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-88993 The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, al... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-88844 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the course before returning its enr... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-88825 The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowing unauthenticated users to sto... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-88798 The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-87966 The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservat... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-87965 The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointment cancellation and confir... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-87775 The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX a... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-87774 The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX a... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-87771 The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them in SQL queries on AJAX action... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-87770 The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using them in a SQL query on an AJAX... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-87767 The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter before using it in a SQL query on... | UNKNOWN | ????? | ????? | NVD | 2 days ago |