Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Severity:
high
CVE-2026-49769: wpForo Forum <= 3.1.0 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49769 affects the wpForo plugin for WordPress (up to version 3.1.0) with a CVSS score of 8.1. This high-severity file…
CVE-2026-49768: Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms <= 1.26.13 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49768 affects the Happyforms plugin (up to version 1.26.13) with a CVSS score of 8.1. This high-severity PHP Object Injection…
CVE-2026-10586: Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 Authenticated (Author+) Server-Side Request Forgery PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-10586 affects the Essential Blocks plugin for WordPress (up to version 6.1.3) with a CVSS score of 7.2. Authenticated attackers…
CVE-2026-49778: WPFunnels Pro <= 2.9.4 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49778 affects WPFunnels Pro plugin versions up to 2.9.4 with a CVSS score of 7.2. This high-severity stored XSS vulnerability…
CVE-2026-49763: Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.3.7 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49763 affects the Cf7 Hubspot plugin (up to v1.3.7) with a CVSS score of 8.1. This high-severity file upload vulnerability…
CVE-2026-49774: RD Station <= 5.6.0 Authenticated (Contributor+) Remote Code Execution PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49774 exposes the RD Station plugin for WordPress (up to 5.6.0) to high-severity remote code execution, with a CVSS score…
CVE-2026-49770: WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.7.12 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49770 affects the WP Travel Engine plugin (up to version 6.7.12) with a high severity (CVSS 8.1) file upload vulnerability.…
CVE-2026-49106: Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.6 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49106 affects the Cf7 Constant Contact plugin (up to v1.1.6) with a high severity CVSS score of 8.1. Unauthenticated PHP…
CVE-2026-49781: OttoKit: All-in-One Automation Platform <= 1.1.27 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49781 affects the Suretriggers plugin for WordPress (up to version 1.1.27) with a high severity (CVSS 8.1) file upload vulnerability.…
CVE-2026-49113: Cornerstone < 7.8.8 Authenticated (Subscriber+) Arbitrary Code Execution PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49113 affects the Cornerstone plugin for WordPress (up to version 7.8.8) with a CVSS score of 8.8. Authenticated attackers can…
CVE-2026-49765: Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49765 affects the Cf7 Mailchimp plugin (up to v1.1.8) with a high severity CVSS score of 8.1. Unauthenticated attackers can…
CVE-2026-49109: Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49109 affects the Cf7 Salesforce plugin (up to version 1.4.3) with a high severity CVSS score of 8.1. Unauthenticated PHP…
CVE-2026-49776: GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49776 affects the GPTranslate plugin for WordPress (versions up to 2.32.6) with a high severity score of 7.5. Unauthenticated SQL…
CVE-2026-7654: Admin Columns <= 7.0.18 Authenticated (Contributor+) PHP Object Injection to Remote Code Execution via Custom Field Meta Value PoC, Patch Analysis & Rule
June 13, 2026
CVE-2026-7654 affects the Codepress Admin Columns plugin (up to version 7.0.18) with a CVSS score of 8.8. This high-severity vulnerability…
CVE-2026-5411: WP Captcha PRO <= 5.38 Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload PoC, Patch Analysis & Rule
June 13, 2026
CVE-2026-5411 affects the Advanced Google Recaptcha plugin (up to version 5.38) with a CVSS score of 8.8. Authenticated users can…
CVE-2026-49766: WP User Manager – User Profile Builder & Membership <= 2.9.16 Authenticated (Subscriber+) Arbitrary File Deletion PoC, Patch Analysis & Rule
June 13, 2026
CVE-2026-49766 affects WP User Manager plugin versions up to 2.9.16, allowing authenticated users to delete arbitrary files, potentially leading to…
CVE-2026-49079: JetSearch <= 3.5.17 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
June 13, 2026
CVE-2026-49079 reveals a high severity SQL injection vulnerability (CVSS 7.5) in the Jet Search plugin for WordPress, affecting versions up…
CVE-2026-49083: LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.5.1 Authenticated (Contributor+) Privilege Escalation PoC, Patch Analysis & Rule
June 13, 2026
CVE-2026-49083 affects the LatePoint plugin for WordPress (up to 5.5.1) with a CVSS score of 8.8. Authenticated attackers can escalate…
CVE-2026-9290: WP User Manager <= 2.9.17 Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter PoC, Patch Analysis & Rule
June 13, 2026
CVE-2026-9290 affects the WP User Manager plugin (up to 2.9.17) with a CVSS score of 7.5. This high-severity vulnerability allows…
CVE-2026-9691: Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
June 13, 2026
CVE-2026-9691 affects the Cf7 Active Campaign plugin for WordPress (versions up to 1.1.1) with a high severity CVSS score of…
1
2
3
…
26
→