Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-41556

WordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnerability_CVE-2026-41556

Subscriber Cross Site Scripting (XSS) in ProfilePress

properfraction ProfilePress n/a CVE
MEDIUM 5.8 CVE-2026-40799

WordPress Simple Cloudflare Turnstile plugin <= 1.38.0 - Broken Authentication vulnerability_CVE-2026-40799

Unauthenticated Broken Authentication in Simple Cloudflare Turnstile

RelyWP Simple Cloudflare Turnstile n/a CVE
MEDIUM 6.5 CVE-2026-40796

WordPress WPPizza plugin <= 3.19.9 - Sensitive Data Exposure vulnerability_CVE-2026-40796

Subscriber Sensitive Data Exposure in WPPizza

ollybach WPPizza n/a CVE
MEDIUM 6.5 CVE-2026-40795

WordPress Amelia plugin <= 2.2 - Broken Access Control vulnerability_CVE-2026-40795

Subscriber Broken Access Control in Amelia

TMS Amelia n/a CVE
MEDIUM 6.5 CVE-2026-40794

WordPress myCred plugin <= 3.0.3 - Broken Access Control vulnerability_CVE-2026-40794

Subscriber Broken Access Control in myCred

myCred myCred n/a CVE
MEDIUM 6.5 CVE-2026-40793

WordPress Groundhogg plugin < 4.4.1 - Broken Access Control vulnerability_CVE-2026-40793

Subscriber Broken Access Control in Groundhogg < 4.4.1 versions.

Groundhogg Groundhogg n/a CVE
MEDIUM 6.3 CVE-2026-40792

WordPress KiviCare plugin <= 4.2.1 - Insecure Direct Object References (IDOR) vulnerability_CVE-2026-40792

Subscriber Insecure Direct Object References (IDOR) in KiviCare

Iqonic Design KiviCare n/a CVE
MEDIUM 6.5 CVE-2026-40790

WordPress WP SMS plugin <= 7.2.1 - Sensitive Data Exposure vulnerability_CVE-2026-40790

Subscriber Sensitive Data Exposure in WP SMS

VeronaLabs WP SMS n/a CVE
MEDIUM 6.5 CVE-2026-40782

WordPress WPAdverts plugin <= 2.3.0 - Broken Access Control vulnerability_CVE-2026-40782

Unauthenticated Broken Access Control in WPAdverts

Greg Winiarski WPAdverts n/a CVE
MEDIUM 6.5 CVE-2026-40773

WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.9 - Broken Access Control vulnerability_CVE-2026-40773

Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress

rtCamp Inc. rtMedia for WordPress, BuddyPress and bbPress n/a CVE