Latest CVEs

Real-time Sync

Monitoring global CVE publications.

Live Feed
7.5
CVSS

CVE-2026-87908

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-87908

multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single multipart part. An unauthenticated attacker can send a single request whose part carries a very large volume of header bytes, forcing the parser to buffer all of them and exhausting the process memory, which crashes the server. This is a denial of service with no confidentiality or integrity impact. The issue is fixed in multiparty 4.3.1, which caps the size of the accumulated part headers. Users should upgrade to multiparty 4.3.1 or later.

EPSS: 0.00%
Type: DoS
0.0
CVSS

CVE-2026-86815

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-86815

The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, backup-destination, and backup-execution management, allowing users holding a BackWPup WordPress plugin before 5.7.5-defined, administrator-assigned limited role to create and run backup jobs and exfiltrate a full database backup to an attacker-controlled destination.

EPSS: 0.00%
Type: Other
0.0
CVSS

CVE-2026-86812

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-86812

The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allowing unauthenticated users to disclose guest order information and to change the status of, or trash, any order.

EPSS: 0.00%
Type: Other
0.0
CVSS

CVE-2026-86782

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-86782

The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing users with the Contributor role and above to publish, rename, and overwrite the content of posts and pages they do not own, including other users' private drafts.

EPSS: 0.00%
Type: Other
0.0
CVSS

CVE-2026-86781

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-86781

The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowing any authenticated user, including Subscribers, to download the site's TLS private key, certificates, and diagnostic logs.

EPSS: 0.00%
Type: Other
0.0
CVSS

CVE-2026-86780

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-86780

The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected post, including higher-privileged users such as Editors and Administrators.

EPSS: 0.00%
Type: XSS
0.0
CVSS

CVE-2026-86779

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-86779

The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above to permanently delete any chart on the site, including charts created by other users such as administrators.

EPSS: 0.00%
Type: Other
0.0
CVSS

CVE-2026-85678

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-85678

The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it inside a script tag on the front end, allowing users with contributor level access and above to store arbitrary JavaScript that will execute in the browser of anyone who views the post, including the editor or administrator who reviews it.

EPSS: 0.00%
Type: Other
0.0
CVSS

CVE-2026-85677

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-85677

The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted comments, allowing unauthenticated users to store JavaScript that will execute in the browser of any administrator who reviews the comment queue, and of any visitor to the post once the comment is approved.

EPSS: 0.00%
Type: Other
0.0
CVSS

CVE-2026-83546

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-83546

The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed.

EPSS: 0.00%
Type: Other
0.0
CVSS

CVE-2026-83545

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-83545

The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes when the content is viewed.

EPSS: 0.00%
Type: Other
0.0
CVSS

CVE-2026-82305

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-82305

The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site.

EPSS: 0.00%
Type: Other
0.0
CVSS

CVE-2026-74925

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-74925

The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.

EPSS: 0.00%
Type: Other
7.5
CVSS

CVE-2026-73785

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-73785

A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS).

EPSS: 0.00%
Type: DoS
8.8
CVSS

CVE-2026-73784

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-73784

A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.

EPSS: 0.00%
Type: Other
0.0
CVSS

CVE-2026-14566

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-14566

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order, allowing any authenticated user such as a subscriber to tamper with the custom metadata of orders belonging to other customers.

EPSS: 0.00%
Type: Other
0.0
CVSS

CVE-2026-14565

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-14565

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated user such as a subscriber to store JavaScript that executes in the browser of visitors viewing the affected product.

EPSS: 0.00%
Type: Other
0.0
CVSS

CVE-2026-14563

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-14563

The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including administrators, or to create arbitrary new accounts.

EPSS: 0.00%
Type: Other
0.0
CVSS

CVE-2026-14562

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-14562

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, allowing unauthenticated attackers to disclose other customers' order and attachment data.

EPSS: 0.00%
Type: Other
0.0
CVSS

CVE-2026-14560

PUBLISHED Sep 11, 2026
MODIFIED Sep 11, 2026

CVE-2026-14560

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the server.

EPSS: 0.00%
Type: Other