🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-91847 The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant co... | UNKNOWN | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-88926 The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them... | UNKNOWN | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-88824 The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its s... | UNKNOWN | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-86814 The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it t... | UNKNOWN | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-86591 The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to up... | UNKNOWN | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-85680 The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page ... | UNKNOWN | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-85574 The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy ... | UNKNOWN | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-84750 The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uploaded through one of its form f... | UNKNOWN | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-76790 The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before refle... | UNKNOWN | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-76554 The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to create or modify user account... | UNKNOWN | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-19860 The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a... | UNKNOWN | ????? | ????? | NVD | 13 hours ago |
| CVE-2025-15698 The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could allow high privilege users suc... | UNKNOWN | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-16557 The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenti... | UNKNOWN | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-93741 A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafr... | CRITICAL | ????? | ????? | NVD | 13 hours ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | CRITICAL | ????? | ????? | SA | 13 hours ago |
| CVE-2026-92807 The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via... | HIGH | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-92967 The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' parameter in versions up to, and includin... | MEDIUM | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-12042 The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, ... | MEDIUM | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-89274 The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerabilit... | CRITICAL | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-89093 The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoo... | MEDIUM | ????? | ????? | NVD | 16 hours ago |