Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-42640

WordPress Classified Listing plugin <= 5.3.8 - Broken Access Control vulnerability_CVE-2026-42640

Unauthenticated Broken Access Control in Classified Listing

Mamunur Rashid Classified Listing n/a CVE
CRITICAL 9.3 CVE-2026-42639

WordPress GD Rating System plugin <= 3.6.2 - SQL Injection vulnerability_CVE-2026-42639

Unauthenticated SQL Injection in GD Rating System

Dev4Press GD Rating System n/a CVE
HIGH 8.1 CVE-2026-42411

WordPress CloudSecure WP Security plugin <= 1.4.7 - Broken Authentication vulnerability_CVE-2026-42411

Unauthenticated Broken Authentication in CloudSecure WP Security

XServer CloudSecure WP Security n/a CVE
CRITICAL 9.3 CVE-2026-42386

WordPress Order Delivery Date for WooCommerce plugin <= 4.5.1 - SQL Injection vulnerability_CVE-2026-42386

Unauthenticated SQL Injection in Order Delivery Date for WooCommerce

tychesoftwares Order Delivery Date for WooCommerce n/a CVE
HIGH 7.5 CVE-2026-42384

WordPress Simply Schedule Appointments plugin < 1.6.11.2 - Sensitive Data Exposure vulnerability_CVE-2026-42384

Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.

NSquared Simply Schedule Appointments n/a CVE
CRITICAL 9.3 CVE-2026-42381

WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.1 - SQL Injection vulnerability_CVE-2026-42381

Unauthenticated SQL Injection in Funnel Builder by FunnelKit

FunnelKit Funnel Builder by FunnelKit n/a CVE
MEDIUM 6.5 CVE-2026-42378

WordPress WP Full Stripe Free plugin <= 8.4.1 - Broken Authentication vulnerability_CVE-2026-42378

Subscriber Broken Authentication in WP Full Stripe Free

Themeisle WP Full Stripe Free n/a CVE
MEDIUM 6.5 CVE-2026-41556

WordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnerability_CVE-2026-41556

Subscriber Cross Site Scripting (XSS) in ProfilePress

properfraction ProfilePress n/a CVE
MEDIUM 5.8 CVE-2026-40799

WordPress Simple Cloudflare Turnstile plugin <= 1.38.0 - Broken Authentication vulnerability_CVE-2026-40799

Unauthenticated Broken Authentication in Simple Cloudflare Turnstile

RelyWP Simple Cloudflare Turnstile n/a CVE
CRITICAL 9.3 CVE-2026-40798

WordPress wpForo Forum plugin <= 3.0.4 - SQL Injection vulnerability_CVE-2026-40798

Unauthenticated SQL Injection in wpForo Forum

Tomdever wpForo Forum n/a CVE