Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.9 CVE-2026-7547

Woosa <= 2.0.5 - Authenticated (Administrator+) Arbitrary File Read via 'log_file' Parameter_CVE-2026-7547

The Woosa – Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in versions up to and includin...

teamwsa Woosa – Marktplaats for WooCommerce CVE
CRITICAL 9.8 CVE-2026-7515

BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style_CVE-2026-7515

The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter...

betterdocs BetterDocs Pro CVE
CRITICAL 9.8 CVE-2026-54414

FileRise shared-folder upload path traversal allows arbitrary file write and admin takeover_CVE-2026-54414

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbi...

error311 FileRise CVE
MEDIUM 6.4 CVE-2026-4328

Advanced Import: One-Click Demo Import for WordPress <= 1.4.6 - Authenticated (Author+) Server-Side Request Forgery via 'demo_file' Parameter_CVE-2026-4328

The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.6. This is due to t...

addonspress Advanced Import CVE
MEDIUM 6.4 CVE-2026-1856

Appointment Booking Calendar <= 1.4.4 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Booking Field Label_CVE-2026-1856

The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking field labels in all versions ...

creavi Creavi Appointment Booking Calendar CVE
MEDIUM 5.3 CVE-2026-12644

CVE-2026-12644_CVE-2026-12644

Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of built-in Object.prototype me...

n/a ts-deepmerge CVE
MEDIUM 4.4 CVE-2026-12430

Blocksy Companion <= 2.1.45 - Authenticated (Editor+) Stored Cross-Site Scripting via 'product_description' Parameter_CVE-2026-12430

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2....

creativethemeshq Blocksy Companion CVE
MEDIUM 6.4 CVE-2026-12157

BetterDocs <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'blockId' Block Attribute_CVE-2026-12157

The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...

wpdevteam BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot CVE
MEDIUM 6.5 CVE-2026-11989

Bit integrations <= 2.8.7 - Unauthenticated Server-Side Request Forgery via Form Field Upload Mapping_CVE-2026-11989

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Server-Side Reque...

bitpressadmin Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation CVE
MEDIUM 5.9 CVE-2026-11752

CVE-2026-11752_CVE-2026-11752

A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS module can resolve control-pla...

LY Corporation Armeria 1.38.0 CVE