- CVE-2026-11756 CRITICAL CVSS 10.0 -
NVD: A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.
An attacker may be able to run code or commands on affected systems; CVSS 10.0 (CRITICAL); EPSS percentile 37; sources: NVD.
- CVE-2026-14545 CRITICAL CVSS 9.8 -
NVD: The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an...
This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 9.8 (CRITICAL); EPSS percentile 20; sources: NVD.
- CVE-2026-17524 HIGH CVSS 8.7 -
NVD: Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extraction process. NVD: An attacker can bypass security checks designed to prevent directory traversal. NVD: The intended security function, isOutsideTargetFolder, only checks and caches the path status when the initial directory symlink is created during the first extraction.
An attacker may be able to reach files outside the intended application path; CVSS 8.7 (HIGH); EPSS percentile 53; sources: NVD, OSV.
- CVE-2024-14041 HIGH CVSS 8.2 -
NVD: In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines... NVD: An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. NVD: These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.2 (HIGH); EPSS percentile 20; sources: NVD, OSV.
- CVE-2026-14490 HIGH CVSS 7.5 -
NVD: The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 0.0.7. NVD: The vulnerability exists because the plugin stores its HMAC signing key and per-step restore token as dotfiles inside a publicly accessible subdirectory of the WordPress uploads folder — without any .htaccess or index file protection — and the... NVD: This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 7.5 (HIGH); EPSS percentile 41; sources: NVD.
- CVE-2026-12741 HIGH CVSS 7.5 -
NVD: The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter in all versions up to, and including, 1.80.280 due to insufficient escaping on the user supplied parameter and... NVD: This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
A remote attacker may be able to read or change database-backed application data; CVSS 7.5 (HIGH); EPSS percentile 23; sources: NVD.
- CVE-2026-14924 HIGH CVSS 7.5 -
NVD: The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 7.5 (HIGH); EPSS percentile 17; sources: NVD.
- CVE-2026-16585 HIGH CVSS 7.2 -
NVD: The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_sticker function in all versions up to, and including, 2.15.19. NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.2 (HIGH); EPSS percentile 51; sources: NVD.
- CVE-2026-14870 HIGH CVSS 7.1 -
NVD: The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high...
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 7.1 (HIGH); EPSS percentile 4; sources: NVD.
- CVE-2026-6251 MEDIUM CVSS 6.5 -
NVD: The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and including 3.5.5. NVD: This is due to the fetch_custom_field() function in admin/class-admin-base.php retrieving the widget_id POST parameter via filter_input(INPUT_POST, ...) and directly concatenating the value into a raw SQL query in a numeric context without using... NVD: Additionally, the nonce verification check is performed after the SQL query has already executed, providing no protection against the injection.
An attacker may be able to read or change database-backed application data; CVSS 6.5 (MEDIUM); EPSS percentile 16; sources: NVD.
- CVE-2026-15012 MEDIUM CVSS 5.3 -
NVD: The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Copy in all versions up to, and including, 0.0.8 via the handle_restore_step function. NVD: This is due to missing HTTP access controls on the wp-content/uploads/demi-backup-state/ directory, which exposes the cryptographic restore key used to both authenticate the unauthenticated AJAX handler and forge signed restore-state envelopes. NVD: This makes it possible for unauthenticated attackers to copy arbitrary files to attacker-controlled destinations on the server.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 5.3 (MEDIUM); EPSS percentile 24; sources: NVD.
- CVE-2026-17528 MEDIUM CVSS 5.3 -
NVD: Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element. OSV: Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.3 (MEDIUM); EPSS percentile 12; sources: NVD, OSV.
- CVE-2026-12124 MEDIUM CVSS 5.3 -
NVD: The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the serveTemplatePdfAjax() function and the... NVD: This makes it possible for unauthenticated attackers to download stored template PDFs — which may contain customer PII, invoice, order, and certificate data — by requesting the publicly registered admin-ajax action pdfdraft_embed_pdf or the REST endpoint...
A remote attacker may access resources that should require stronger authorization; CVSS 5.3 (MEDIUM); EPSS percentile 11; sources: NVD.
- CVE-2026-16811 MEDIUM CVSS 4.9 -
NVD: The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.4.5 due to insufficient escaping on the user supplied... NVD: This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
An attacker may be able to read or change database-backed application data; CVSS 4.9 (MEDIUM); EPSS percentile 19; sources: NVD.
- CVE-2026-16587 MEDIUM CVSS 4.3 -
NVD: The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. NVD: This is due to the plugin not properly verifying that a user is authorized to perform an action. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the site's stored MailUp OAuth tokens in the adfoin_mailup_keys option with attacker-controlled tokens, hijacking future form-submission data to a MailUp...
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 4.3 (MEDIUM); EPSS percentile 13; sources: NVD.
- CVE-2026-16797 MEDIUM CVSS 4.3 -
NVD: The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.5 via the 'optionSection' parameter due to missing validation on a user... NVD: This makes it possible for authenticated attackers, with contributor-level access and above, to read arbitrary wp_options rows — including internal plugin news feed data, WooCommerce block pattern transients, and third-party configuration records — whose...
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 4.3 (MEDIUM); EPSS percentile 12; sources: NVD.
- CVE-2026-15136 MEDIUM CVSS 4.3 -
NVD: The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3.7. NVD: This is due to missing or incorrect nonce validation on the process_bulk_action function. NVD: This makes it possible for unauthenticated attackers to permanently delete or forcibly resolve arbitrary GDPR data request records stored in the wpl_data_req table via a forged request granted they can trick a site administrator into performing an action such...
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 4.3 (MEDIUM); EPSS percentile 3; sources: NVD.
- CVE-2026-14926 MEDIUM CVSS 4.2 -
NVD: The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a subscription belongs to the requesting customer in several of its payment-method endpoints, allowing any authenticated customer to act on another customer's...
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 4.2 (MEDIUM); EPSS percentile 4; sources: NVD.
- CVE-2026-14819 LOW CVSS 3.5 -
NVD: The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute...
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 3.5 (LOW); EPSS percentile 4; sources: NVD.
- CVE-2026-14821 LOW CVSS 2.7 -
NVD: The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.7 (LOW); EPSS percentile 6; sources: NVD.