Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Free Protection
Severity:
medium
CVE-2026-49767: wpForo Forum <= 3.1.0 Missing Authorization PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49767 affects the wpForo plugin for WordPress versions up to 3.1.0, allowing unauthorized access to user profiles. Update to version…
CVE-2026-49764: RegistrationMagic – User Registration Forms Plugin <= 6.0.8.6 Missing Authorization PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49764 affects the Custom Registration Form Builder With Submission Manager plugin (up to 6.0.8.6) with a CVSS score of 5.3.…
CVE-2026-49775: Welcart e-Commerce <= 2.11.28 Missing Authorization PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49775 affects the Usc E Shop plugin (up to v2.11.28) with a CVSS score of 5.3. This medium severity vulnerability…
CVE-2026-49773: FV Flowplayer Video Player < 7.5.51.7212 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49773 affects the FV Flowplayer Video Player plugin (up to version 7.5.51.7212) with a CVSS score of 6.4. Authenticated attackers…
CVE-2026-49077: Wp EMember <= v10.2.2 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49077 affects the Wp EMember plugin for WordPress (up to v10.2.2) with a medium severity CVSS score of 5.3. Unauthenticated…
CVE-2026-49771: Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.41 Authenticated (Contributor+) SQL Injection PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49771 affects the Photo Gallery plugin for WordPress (up to version 1.8.41) with a medium severity score of 6.5. Authenticated…
CVE-2026-49110: Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups. <= 3.1.4 Missing Authorization PoC, Patch Analysis & Rule
June 14, 2026
CVE-2026-49110 affects the Upsell Order Bump Offer For WooCommerce plugin (up to v3.1.4), allowing remote code execution due to missing…
CVE-2019-25738: Hybrid Composer <= 1.4.6 Missing Authorization PoC, Patch Analysis & Rule
June 13, 2026
CVE-2019-25738 affects the Hybrid Composer plugin for WordPress (up to version 1.4.6) with a medium severity CVSS score of 5.3.…
CVE-2026-49078: WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.7.10 Missing Authorization PoC, Patch Analysis & Rule
June 13, 2026
CVE-2026-49078 affects WP Travel Engine plugin versions up to 6.7.10, allowing unauthorized access due to a missing capability check. Upgrade…
CVE-2026-8608: Event Monster <= 2.1.0 Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via em_capture_payment AJAX Action PoC, Patch Analysis & Rule
June 13, 2026
CVE-2026-8608 affects the Event Monster plugin (up to v2.1.0) with a medium severity (CVSS 5.3) vulnerability. Unauthenticated attackers can forge…
CVE-2026-8385: WP Go Maps < 10.0.10 Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback PoC, Patch Analysis & Rule
June 13, 2026
CVE-2026-8385 affects WP Google Maps versions up to 10.0.09, allowing unauthenticated users to access sensitive marker data. Upgrade to 10.0.10…
CVE-2026-49082: Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons <= 1.4.8 Authenticated (Subscriber+) Information Exposure PoC, Patch Analysis & Rule
June 13, 2026
CVE-2026-49082 affects the Chatway Live Chat plugin (up to version 1.4.8), exposing sensitive data to authenticated attackers. Update to version…
CVE-2026-49112: Shared Files – Frontend File Upload Form & Secure File Sharing <= 1.7.64 Unauthenticated Path Traversal PoC, Patch Analysis & Rule
June 13, 2026
CVE-2026-49112 affects the Shared Files plugin for WordPress (up to version 1.7.64) with a medium severity CVSS score of 5.3.…
CVE-2026-9016: Debug Log Manager <= 2.5.0 Unauthenticated Improper Output Neutralization for Logs via log_js_errors AJAX Action PoC, Patch Analysis & Rule
June 13, 2026
CVE-2026-9016 affects the Debug Log Manager plugin (up to 2.5.0) with a medium severity (CVSS 5.3) vulnerability. Users should upgrade…
CVE-2026-49081: User Registration Stripe <= 1.3.12 Missing Authorization PoC, Patch Analysis & Rule
June 13, 2026
CVE-2026-49081 affects the User Registration Stripe plugin for WordPress (up to version 1.3.12) with a CVSS score of 5.3. It…
CVE-2019-25727: 10WebAdManager <= 1.0.11 Unauthenticated Arbitrary File Download PoC, Patch Analysis & Rule
June 13, 2026
CVE-2019-25727 affects the 10WebAdManager plugin for WordPress (up to version 1.0.11) with a CVSS score of 5.3. Unauthenticated attackers can…
CVE-2026-8976: RSS Aggregator by Feedzy <= 5.1.7 Missing Authorization to Authenticated (Contributor+) Import Job Creation, Execution, Purge, Log Clearing, and Information Disclosure via Multiple AJAX Sub-Actions PoC, Patch Analysis & Rule
June 12, 2026
CVE-2026-8976 affects Feedzy Rss Feeds plugin versions up to 5.1.7, allowing authenticated users to bypass authorization. Update to 5.1.8 to…
CVE-2026-9719: LatePoint <= 5.6.0 Cross-Site Request Forgery via invoices__change_status Action PoC, Patch Analysis & Rule
June 12, 2026
CVE-2026-9719 affects the LatePoint plugin (up to v5.6.0) with a medium severity (CVSS 4.3) CSRF vulnerability. Patch to v5.6.1 to…
CVE-2026-7523: Alba Board <= 2.1.3 Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'card_id' Parameter PoC, Patch Analysis & Rule
June 12, 2026
CVE-2026-7523 affects the Alba Board plugin for WordPress (up to v2.1.3) with a medium severity (CVSS 4.3) authentication bypass vulnerability.…
CVE-2026-8900: Simple SEO Slideshow <= 1.2.8 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
June 12, 2026
CVE-2026-8900 affects the Simple SEO Slideshow plugin for WordPress (up to v1.2.8) with a medium severity CVSS score of 6.4.…
1
2
3
…
98
→