Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.4 CVE-2026-9594

WP Maps <= 4.9.4 - Authenticated (Admin+) Stored Cross-Site Scripting via 'location_messages' Parameter_CVE-2026-9594

The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Sc...

flippercode WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters CVE
MEDIUM 5.3 CVE-2026-9016

Debug Log Manager <= 2.5.0 - Unauthenticated Improper Output Neutralization for Logs via log_js_errors AJAX Action_CVE-2026-9016

The Debug Log Manager – Conveniently Monitor and Inspect Errors plugin for WordPress is vulnerable to Improper Output Neutralization for Logs in al...

qriouslad Debug Log Manager – Conveniently Monitor and Inspect Errors CVE
MEDIUM 5.3 CVE-2026-8839

MapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Reference via REST API Endpoints_CVE-2026-8839

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and i...

chrisvrichardson MapPress Maps for WordPress CVE
MEDIUM 4.3 CVE-2026-8611

Klamra Paycal for Aspaclaria <= 1.1.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'invoice_id' Parameter_CVE-2026-8611

The Klamra Paycal for Aspaclaria plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.4...

klamra22 Klamra Paycal for Aspaclaria CVE
MEDIUM 4.3 CVE-2026-7624

SEO Plugin by Squirrly SEO <= 12.4.16 - Missing Authorization to Authenticated (Contributor+) Privileged Cloud API Operations_CVE-2026-7624

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 12.4.16. This is du...

cifi SEO Plugin by Squirrly SEO CVE
MEDIUM 6.1 CVE-2026-11150

CVE-2026-11150_CVE-2026-11150

Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) vi...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11148

CVE-2026-11148_CVE-2026-11148

Inappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to leak cross-origin data via ...

Google Chrome 149.0.7827.53 CVE
CRITICAL 9.6 CVE-2026-11146

CVE-2026-11146_CVE-2026-11146

Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the ...

Google Chrome 149.0.7827.53 CVE
MEDIUM 6.5 CVE-2026-11145

CVE-2026-11145_CVE-2026-11145

Race in Geolocation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page....

Google Chrome 149.0.7827.53 CVE
HIGH 8.8 CVE-2026-11144

CVE-2026-11144_CVE-2026-11144

Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted ...

Google Chrome 149.0.7827.53 CVE