- CVE-2026-14293 HIGH CVSS 8.8 -
NVD: The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to...
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 8.8 (HIGH); EPSS percentile 20; sources: NVD.
- CVE-2026-13133 HIGH CVSS 8.4 -
NVD: A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead...
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.4 (HIGH); EPSS percentile 2; sources: NVD.
- CVE-2026-16257 HIGH CVSS 8.2 -
NVD: The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before...
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 8.2 (HIGH); EPSS percentile 17; sources: NVD.
- CVE-2026-13600 HIGH CVSS 8.1 -
NVD: The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-synchronization task. NVD: On server configurations where the scheduled task executes before the HTTP response is committed, an unauthenticated attacker who triggers the due task can receive the administrator's session cookie and gain administrator access without credentials.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 8.1 (HIGH); EPSS percentile 27; sources: NVD.
- CVE-2026-14206 HIGH CVSS 7.5 -
NVD: The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 7.5 (HIGH); EPSS percentile 24; sources: NVD.
- CVE-2026-13170 HIGH CVSS 7.2 -
NVD: The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.2 (HIGH); EPSS percentile 33; sources: NVD.
- CVE-2026-14237 HIGH CVSS 7.2 -
NVD: The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by...
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.2 (HIGH); EPSS percentile 18; sources: NVD.
- CVE-2026-15047 MEDIUM CVSS 6.8 -
NVD: The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the...
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 6.8 (MEDIUM); EPSS percentile 15; sources: NVD.
- CVE-2026-72522 MEDIUM CVSS 6.2 -
NVD: libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions. OSV: libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 6.2 (MEDIUM); EPSS percentile 7; sources: NVD, OSV.
- CVE-2026-12570 MEDIUM CVSS 5.5 -
NVD: A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. NVD: The H5IOStore.__getitem__ method in keras/src/saving/saving_lib.py does not validate the shape or size of datasets, leading to unbounded memory allocation. NVD: A specially crafted .keras file can exploit this flaw to trigger an out-of-memory (OOM) condition, causing the process to be terminated (exit code 137).
The affected service may become unavailable or unreliable; CVSS 5.5 (MEDIUM); EPSS percentile 3; sources: NVD, OSV.
- CVE-2026-14941 MEDIUM CVSS 5.4 -
NVD: The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers...
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.4 (MEDIUM); EPSS percentile 6; sources: NVD.
- CVE-2026-15238 MEDIUM CVSS 5.4 -
NVD: The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any...
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 5.4 (MEDIUM); EPSS percentile 6; sources: NVD.
- CVE-2026-14860 MEDIUM CVSS 5.3 -
NVD: The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing unauthenticated attackers to make the server issue requests to arbitrary hosts and read back responses that...
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 5.3 (MEDIUM); EPSS percentile 15; sources: NVD.
- CVE-2026-15237 MEDIUM CVSS 5.3 -
NVD: The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and...
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 5.3 (MEDIUM); EPSS percentile 13; sources: NVD.
- CVE-2026-15229 MEDIUM CVSS 5.3 -
NVD: The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain...
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 5.3 (MEDIUM); EPSS percentile 8; sources: NVD.
- CVE-2026-13701 MEDIUM CVSS 4.8 -
NVD: The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it on the front end of the site, which could allow administrators (including those without the unfiltered_html capability, such as on...
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 4.8 (MEDIUM); EPSS percentile 7; sources: NVD.
- CVE-2026-14238 MEDIUM CVSS 4.1 -
NVD: The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body before using it in a database query in one of its report endpoints, allowing users with administrator-level access to perform SQL...
An attacker may be able to read or change database-backed application data; CVSS 4.1 (MEDIUM); EPSS percentile 8; sources: NVD.
- CVE-2026-14211 LOW CVSS 3.8 -
NVD: The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and...
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 3.8 (LOW); EPSS percentile 5; sources: NVD.
- CVE-2026-12971 LOW CVSS 2.2 -
NVD: The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side...
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.2 (LOW); EPSS percentile 9; sources: NVD.