Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2025-49403

WordPress Premium Age Verification / Restriction for WordPress Plugin <= 3.0.2 - Arbitrary File Download Vulnerability_CVE-2025-49403

Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress

AA-Team Premium Age Verification / Restriction for WordPress n/a CVE
MEDIUM 5.5 CVE-2026-40722

WordPress Yoast SEO Premium plugin <= 26.6 - Broken Access Control vulnerability_CVE-2026-40722

Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This is...

Yoast BV Yoast SEO Premium n/a CVE
MEDIUM 4.8 CVE-2026-27870

CROSS-SITE SCRIPTING (XSS) VIA MALICIOUS FILE UPLOAD ON REGESTA SMART HD-PLC OF TELDAT_CVE-2026-27870

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action IS required) who has the ...

Teldat Regesta Smart HD-PLC - TLDPH16D2 11.02.05.10.02 CVE
MEDIUM 6.9 CVE-2026-27869

WEB SERVICE (HTTP) DENIAL OF SERVICE VIA SLOW HEADERS ON REGESTA SMART HD-PLC OF TELDAT_CVE-2026-27869

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has t...

Teldat Regesta Smart HD-PLC - TLDPH16D2 11.02.05.10.02 CVE
MEDIUM 6.9 CVE-2026-27868

PUBLICATION OF SENSITIVE INFORMATION ON REGESTA SMART HD-PLC OF TELDAT_CVE-2026-27868

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has t...

Teldat Regesta Smart HD-PLC - TLDPH16D2 11.02.05.10.02 CVE
HIGH 8.8 CVE-2026-12165

Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter_CVE-2026-12165

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privilege Escalation in all vers...

contest-gallery Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe CVE
MEDIUM 6.6 CVE-2026-12115

Counter Box <= 2.0.13 - Authenticated (Administrator+) PHP Object Injection via Import_CVE-2026-12115

The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions...

wpcalc Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress CVE
MEDIUM 6.4 CVE-2026-8607

myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrap' Shortcode Attribute_CVE-2026-8607

The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cro...

saadiqbal Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred CVE
MEDIUM 6.4 CVE-2026-8494

Permalink Manager Lite <= 2.5.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title_CVE-2026-8494

The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in a...

mbis Permalink Manager Lite CVE
CRITICAL 10 CVE-2026-28615

CVE-2026-28615_CVE-2026-28615

In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead to local escalation of pri...

Google Android 17 CVE