Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Severity:
high
CVE-2026-57672: wpDataTables (Premium) <= 6.5.1.1 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
July 20, 2026
CVE-2026-57672 affects the wpDataTables plugin (up to version 6.5.1.1) with a CVSS score of 7.2. Unauthenticated attackers can exploit this…
CVE-2026-42740: Tainacan <= 1.0.3 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
July 20, 2026
CVE-2026-42740 affects the Tainacan plugin for WordPress (up to 1.0.3) with a high severity SQL injection vulnerability (CVSS 7.5). Update…
CVE-2026-57359: ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema <= 2.3.10 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
July 20, 2026
CVE-2026-57359 reveals a high-severity XSS vulnerability in the ReviewX plugin for WordPress, affecting versions up to 2.3.10. Upgrade to 2.3.11…
CVE-2026-57361: Survey Maker by AYS <= 5.2.2.5 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
July 20, 2026
CVE-2026-57361 affects Survey Maker by AYS versions up to 5.2.2.5, with a CVSS score of 7.2. This high-severity XSS vulnerability…
CVE-2026-57360: eCommerce Product Catalog Plugin for WordPress <= 3.5.4 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
July 20, 2026
CVE-2026-57360 affects the Ecommerce Product Catalog Plugin for WordPress (up to version 3.5.4) with a CVSS score of 7.2. Patch…
CVE-2026-57366: WPAdverts – Classifieds Plugin <= 2.3.1 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
July 20, 2026
CVE-2026-57366 affects the WPAdverts plugin for WordPress, versions 2.3.1 and earlier, with a CVSS score of 7.2. Users should upgrade…
CVE-2026-57351: HandL UTM Grabber / Tracker <= 2.9.2 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
July 20, 2026
CVE-2026-57351 affects the HandL UTM Grabber plugin (up to v2.9.2) with a CVSS score of 7.2. This high-severity XSS vulnerability…
CVE-2026-57356: MoreConvert Wishlist for WooCommerce <= 1.9.19 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
July 20, 2026
CVE-2026-57356 affects the Smart Wishlist For More Convert plugin (v1.9.19) with a CVSS score of 7.2. Unauthenticated attackers can exploit…
CVE-2026-57349: WPeMatico RSS Feed Fetcher <= 2.8.17 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
July 20, 2026
CVE-2026-57349 affects the WPeMatico plugin (up to version 2.8.17) with a CVSS score of 7.2. This high-severity XSS vulnerability allows…
CVE-2026-57350: WP Debugging <= 2.12.2 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
July 20, 2026
CVE-2026-57350 affects the WP Debugging plugin (up to 2.12.2) with a high severity CVSS score of 7.2 due to stored…
CVE-2026-6820: VikBooking Hotel Booking Engine & PMS <= 1.8.8 Unauthenticated Stored Cross-Site Scripting via Booking Form Email Field PoC, Patch Analysis & Rule
July 7, 2026
High CVE-2026-6820 in Vikbooking (CVSS 7.2): VikBooking Hotel Booking Engine & PMS. Atomic Edge summarizes impact, exploitability, and patch details.…
CVE-2026-5356: LatePoint Calendar Booking Plugin for Appointments and Events <= 5.4.0 Unauthenticated Stripe PaymentIntent Amount-Binding Bypass PoC, Patch Analysis & Rule
July 7, 2026
High CVE-2026-5356 in Latepoint (CVSS 7.5): LatePoint - Calendar Booking Plugin for Appointments and Events. Atomic Edge summarizes impact, exploitability,…
CVE-2026-3688: WCFM WooCommerce Multivendor Membership <= 2.11.10 Insecure Direct Object Reference to Limited Privilege Escalation via User Role Overwrite PoC, Patch Analysis & Rule
July 7, 2026
High CVE-2026-3688 in Wc Multivendor Membership (CVSS 8.1): WCFM - WooCommerce Multivendor Membership. Atomic Edge summarizes impact, exploitability, and patch…
CVE-2026-6818: VikBooking Hotel Booking Engine & PMS <= 1.8.8 Unauthenticated Stored Cross-Site Scripting via 'special_requests' Parameter PoC, Patch Analysis & Rule
July 7, 2026
High CVE-2026-6818 in Vikbooking (CVSS 7.2): VikBooking Hotel Booking Engine & PMS. Atomic Edge summarizes impact, exploitability, and patch details.…
CVE-2026-6230: Tainacan <= 1.0.3 Unauthenticated SQL Injection via 'geoquery' REST API Parameter PoC, Patch Analysis & Rule
July 7, 2026
High CVE-2026-6230 in Tainacan (CVSS 7.5): Tainacan. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.1.0.
CVE-2026-6854: My Calendar <= 3.7.8 Unauthenticated SQL Injection via 'mc_auth' and 'mc_host' Parameters PoC, Patch Analysis & Rule
July 7, 2026
High CVE-2026-6854 in My Calendar (CVSS 7.5): My Calendar. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule…
CVE-2026-14489: WHMCS Bridge <= 6.9 Unauthenticated Arbitrary File Upload via 'ccce' Parameter PoC, Patch Analysis & Rule
July 7, 2026
High CVE-2026-14489 in Whmcs Bridge (CVSS 8.8): WHMCS Bridge. Atomic Edge summarizes impact, exploitability, and patch details.
CVE-2026-14495: DoLogin Security <= 4.3 Unauthenticated Authentication Bypass via Insufficient Randomness via 'dologin' Parameter Weak PRNG Token PoC, Patch Analysis & Rule
July 7, 2026
High CVE-2026-14495 in Dologin (CVSS 8.8): DoLogin Security. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
CVE-2025-14169: FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.13.1.5 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
July 7, 2026
High CVE-2025-14169 in Funnel Builder (CVSS 7.5): FunnelKit – Funnel Builder for WooCommerce Checkout. Atomic Edge summarizes impact, exploitability, and…
CVE-2026-6101: AMP for WP <= 1.1.12 Authenticated (Author+) Arbitrary File Write via Role-Based Access Configuration with Local Font Upload PoC, Patch Analysis & Rule
July 6, 2026
High CVE-2026-6101 in Accelerated Mobile Pages (CVSS 7.5): AMP for WP. Atomic Edge summarizes impact, exploitability, and patch details. Update…
←
1
2
3
4
…
32
→