🔔 Premium Features
(Level 1+ required)
(Level 2+ required)
(Level 3 required)
🔍 Filter Threats
| Title | Severity | Proof of Concept | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-85350 The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to th... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-85127 The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach t... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-85123 The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of i... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-85122 The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of i... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-85009 The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order ident... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-84904 The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actio... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-84903 The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password check before rendering the co... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-84902 The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content in... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-84738 The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-81810 The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-81340 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders t... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-93485 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-B... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-18912 ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technici... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-18911 ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests with... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-17086 The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions... | HIGH | ????? | ????? | Wordfence | 2 days ago |
| CVE-2026-92991 The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insuffic... | MEDIUM | ????? | ????? | Wordfence | 2 days ago |
| CVE-2026-14855 The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all versions up to, and ... | MEDIUM | ????? | ????? | Wordfence | 2 days ago |
| CVE-2026-15650 The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'point... | MEDIUM | ????? | ????? | Wordfence | 2 days ago |
| CVE-2026-93468 The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-93467 The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the serve... | CRITICAL | ????? | ????? | NVD | 2 days ago |