Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Severity:
critical
CVE-2026-10580: Hippoo Mobile App for WooCommerce <= 1.9.4 Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API PoC, Patch Analysis & Rule
June 13, 2026
CVE-2026-10580 reveals a critical authentication bypass in the Hippoo Mobile App for WooCommerce plugin (versions
CVE-2026-8206: Kirki 6.0.0 6.0.6 Unauthenticated Privilege Escalation via ‘handle_forgot_password’ PoC, Patch Analysis & Rule
June 12, 2026
CVE-2026-8206 is a critical vulnerability in the Kirki plugin (versions 6.0.0 to 6.0.6) allowing unauthenticated account takeover via password reset.…
CVE-2025-6254: Doctreat Core <= 1.6.8 Unauthenticated Privilege Escalation PoC, Patch Analysis & Rule
June 9, 2026
CVE-2025-6254 affects the Doctreat Core plugin (versions
CVE-2026-5076: ARMember Premium <= 7.3.1 Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation PoC, Patch Analysis & Rule
June 2, 2026
CVE-2026-5076 affects the ARMember plugin for WordPress (up to 7.3.1) with a critical CVSS score of 9.8. This SQL injection…
CVE-2026-42680: Contest Gallery Pro <= 29.0.1 – Unauthenticated Privilege Escalation (contest-gallery-pro)
May 22, 2026
CVE-2026-42680 is a critical privilege escalation vulnerability in the Contest Gallery Pro plugin for WordPress, affecting versions up to 29.0.1.…
CVE-2026-6960: BookingPress Pro <= 5.6 – Unauthenticated Arbitrary File Upload via Signature Custom Field (bookingpress-appointment-booking-pro)
May 21, 2026
CVE-2026-6960 affects BookingPress Appointment Booking Pro versions up to 5.6, allowing unauthenticated file uploads with a CVSS score of 9.8.…
CVE-2026-6555: ProSolution WP Client <= 2.0.0 – Unauthenticated Arbitrary File Upload via 'files' (prosolution-wp-client)
May 21, 2026
CVE-2026-6555 affects the ProSolution WP Client plugin (up to 2.0.0) with a critical CVSS score of 9.8. Unauthenticated attackers can…
CVE-2026-6279: Avada (Fusion) Builder <= 3.15.2 – Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics' Shortcode Attribute via Widget AJAX Handler (fusion-builder)
May 20, 2026
CVE-2026-6279 affects the Fusion Builder plugin for WordPress (up to version 3.15.2) with a critical CVSS score of 9.8. Unauthenticated…
CVE-2026-5118: Divi Form Builder <= 5.1.2 – Unauthenticated Privilege Escalation via 'role' (divi-form-builder)
May 20, 2026
CVE-2026-5118 affects the Divi Form Builder plugin (up to version 5.1.2) with a critical CVSS score of 9.8, allowing unauthenticated…
CVE-2026-7637: Boost <= 2.0.3 – Unauthenticated PHP Object Injection via STYXKEY-BOOST_USER_LOCATION Cookie (boost)
May 19, 2026
CVE-2026-7637 is a critical PHP Object Injection vulnerability in the Boost plugin for WordPress (up to 2.0.3) with a CVSS…
CVE-2026-7284: Easy Elements for Elementor <= 1.4.4 – Unauthenticated Privilege Escalation via easyel_handle_register (easy-elements)
May 19, 2026
CVE-2026-7284 affects the Easy Elements plugin for WordPress (up to version 1.4.4) with a critical CVSS score of 9.8. Unauthenticated…
CVE-2026-4883: Piotnet Forms <= 2.1.40 – Unauthenticated Arbitrary File Upload via Form File Upload (piotnetforms-pro)
May 18, 2026
CVE-2026-4883 reveals a critical file upload vulnerability in the Piotnet Forms plugin for WordPress (up to version 2.1.40) with a…
CVE-2026-4885: Piotnet Addons for Elementor Pro <= 7.1.70 – Unauthenticated Arbitrary File Upload via Form File Upload (piotnet-addons-for-elementor-pro)
May 18, 2026
CVE-2026-4885 affects the Piotnet Addons for Elementor Pro plugin (up to version 7.1.70) with a critical CVSS score of 9.8.…
CVE-2025-15484: Order Notification for WooCommerce – Get Audio Alert on new Orders < 3.6.3 – Unauthenticated Remote Code Execution (woc-order-alert)
May 17, 2026
CVE-2025-15484 affects the Woc Order Alert plugin (up to 3.6.2) with a critical CVSS score of 9.8, allowing remote code…
CVE-2026-5229: Receive Notifications After Form Submitting – Form Notify for Any Forms <= 1.1.10 – Unauthenticated Authentication Bypass via LINE OAuth Callback (form-notify)
May 14, 2026
CVE-2026-5229 affects the Form Notify plugin for WordPress (up to v1.1.10) with a critical CVSS score of 9.8. Unauthenticated attackers…
CVE-2026-8181: Burst Statistics 3.4.0 – 3.4.1.1 – Authentication Bypass to Admin Account Takeover (burst-statistics)
May 14, 2026
CVE-2026-8181 affects the Burst Statistics plugin (versions 3.4.0 to 3.4.1.1) with a CVSS score of 9.8. Unauthenticated attackers can impersonate…
CVE-2026-6510: InfusedWoo Pro <= 5.1.2 – Unauthenticated Missing Authorization to Privilege Escalation via 'iwar_save_recipe' (infusedwooPRO)
May 13, 2026
CVE-2026-6510 is a critical vulnerability (CVSS 9.8) in the InfusedWoo Pro plugin (versions
CVE-2026-6512: InfusedWoo Pro <= 5.1.2 – Unauthenticated Missing Authorization to Arbitrary Post Deletion via Multiple Parameters (infusedwooPRO)
May 13, 2026
CVE-2026-6512 affects the InfusedWoo Pro plugin for WordPress (up to v5.1.2) with a critical CVSS score of 9.1. Unauthenticated attackers…
CVE-2026-6271: Career Section <= 1.7 – Unauthenticated Arbitrary File Upload (career-section)
May 13, 2026
CVE-2026-6271 affects the Career Section plugin for WordPress (up to version 1.7) with a critical CVSS score of 9.8. Unauthenticated…
CVE-2026-5722: MoreConvert Pro <= 1.9.14 – Authentication Bypass via Waitlist Guest Verification Token Reuse (smart-wishlist-for-more-convert-premium)
May 5, 2026
CVE-2026-5722 affects the Smart Wishlist For More Convert Premium plugin (up to v1.9.14) with a critical CVSS score of 9.8.…
1
2
3
…
7
→