Latest CVEs

Real-time Sync

Monitoring global CVE publications.

Live Feed
6.1
CVSS

CVE-2026-2445

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

URL Parameter XSS Vulnerability

The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads. An attacker can leverage this vulnerability to cause the user's browser to redirect to a malicious website, modify the user interface of the webpage, or retrieve sensitive information from the browser. However, the impact is mitigated for session hijacking as all session-related sensitive cookies are protected by the httpOnly flag.

EPSS: 0.00%
Type: XSS
9.4
CVSS

CVE-2026-16242

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

Konnectivity proxy-server Unauthenticated Agent Connection

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.

EPSS: 0.00%
Type: Unauthorized Access, Traffic Interception, Traffic Manipulation
0.0
CVSS

CVE-2026-13577

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

Dancer2 Predictable Session IDs

Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id when both Math::Random::ISAAC::XS and Crypt::URandom are unavailable. The fallback session id is generated from a SHA-1 hash of a call to the built-in rand function, the absolute path of the Dancer2::Core::Role::SessionFactory module, an internal counter, the process id, the module instance memory address, and a shuffled string of characters (using the List::Util::shuffle function, which also uses the built-in rand function). These are all low-entropy and easily guessed sources. The built-in rand() function is seeded with 32-bits and considered unsuitable for security applications. Predictable session ids could allow an attacker to gain access to systems.

EPSS: 0.00%
Type: Session Hijacking, Unauthorized Access
0.0
CVSS

CVE-2026-9833

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

Unauthenticated Stored XSS

The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters before reflecting it in the response body served with an HTML content type, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of a logged-in user with `edit_pages` capability (Editor or higher) who is tricked into following a crafted link.

EPSS: 0.00%
Type: XSS
0.0
CVSS

CVE-2026-8825

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

Authenticated Private Post/Page Data Disclosure

The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators).

EPSS: 0.00%
Type: Information Disclosure
0.0
CVSS

CVE-2026-6656

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

Timing Attack in Crypt::Password

Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allows discrepancies in timing to be used to guess the underlying hash.

EPSS: 0.00%
Type: Timing Attack
0.0
CVSS

CVE-2026-16235

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

Insecure Salt Generation in Crypt::Password

Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.

EPSS: 0.00%
Type: Cryptographic Weakness
0.0
CVSS

CVE-2026-13432

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

Authenticated Plugin Deactivation via Missing Capability Check

The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher to deactivate the ThumbPress WordPress plugin before 6.2.2, disrupting the site's image-handling functionality.

EPSS: 0.00%
Type: Denial of Service
0.0
CVSS

CVE-2026-13156

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

CSRF for Configuration Deletion and Plugin Deactivation

The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's SMTP configuration and deactivates the MailerSend WordPress plugin before 1.0.8, breaking the site's email delivery.

EPSS: 0.00%
Type: CSRF / Denial of Service
0.0
CVSS

CVE-2026-13147

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

Server-Side Request Forgery (SSRF)

The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).

EPSS: 0.00%
Type: SSRF
0.0
CVSS

CVE-2026-13142

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

OTP Brute-Force leading to Full Site Takeover

The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email address to brute-force the code and log in as that user, including an administrator, leading to full site takeover.

EPSS: 0.00%
Type: Account Takeover / RCE
0.0
CVSS

CVE-2026-12973

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

Unauthenticated Order Key Disclosure and Status Modification

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some configurations, to modify order statuses.

EPSS: 0.00%
Type: Information Disclosure / Unauthorized Modification
0.0
CVSS

CVE-2026-12972

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

Unauthenticated Payment Metadata Tampering

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.

EPSS: 0.00%
Type: Unauthorized Modification
0.0
CVSS

CVE-2026-12970

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

Reflected Cross-Site Scripting in LearnPress

The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a crafted link.

EPSS: 0.00%
Type: XSS
0.0
CVSS

CVE-2026-12898

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

Arbitrary Log File Creation in All-in-One WP Migration and Backup

The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations outside its intended storage directory.

EPSS: 0.00%
Type: File Write
0.0
CVSS

CVE-2026-12724

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

HTML Injection in Kirki Password Reset Email

The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivered to a registered user, which can be used for phishing.

EPSS: 0.00%
Type: HTML Injection
0.0
CVSS

CVE-2026-12723

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

Unauthenticated Comment Overwrite/Creation via REST Route in Kirki

The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment moderation.

EPSS: 0.00%
Type: Auth Bypass
0.0
CVSS

CVE-2026-12592

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

Stored Cross-Site Scripting in SlimStat Analytics

The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browser of an administrator who views the reports. Exploitation requires the SlimStat Analytics WordPress plugin before 5.5.0 to be configured to use the Cloudflare geolocation provider.

EPSS: 0.00%
Type: XSS
0.0
CVSS

CVE-2026-11868

PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

Unauthenticated Booking Cancellation in WP Travel

The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.

EPSS: 0.00%
Type: Auth Bypass
0.0
CVSS

CVE-2026-11349

#PoC Available
PUBLISHED Jul 20, 2026
MODIFIED Jul 20, 2026

Unauthenticated SQL Injection in Modern Event Calendar

The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection vulnerability that allows attackers to extract sensitive data from the database.

EPSS: 0.00%
Type: SQLi