Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.7 CVE-2026-54193

WordPress Fusion Builder plugin <= 3.15.4 - Arbitrary File Deletion vulnerability_CVE-2026-54193

Contributor Arbitrary File Deletion in Fusion Builder

ThemeFusion Fusion Builder n/a CVE
MEDIUM 6.5 CVE-2026-52716

WordPress WorkScout-Core plugin <= 1.7.11 - Arbitrary File Deletion vulnerability_CVE-2026-52716

Unauthenticated Arbitrary File Deletion in WorkScout-Core

purethemes WorkScout-Core n/a CVE
HIGH 8.1 CVE-2026-52707

WordPress Kastell theme <= 2.0 - Local File Inclusion vulnerability_CVE-2026-52707

Unauthenticated Local File Inclusion in Kastell

Mikado-Themes Kastell n/a CVE
HIGH 8.8 CVE-2026-49268

Apache Shiro: LDAP DN Injection in DefaultLdapRealm_CVE-2026-49268

A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied usernam...

Apache Software Foundation Apache Shiro CVE
CRITICAL 9.8 CVE-2026-49108

WordPress Moderno theme < 1.43 - PHP Object Injection vulnerability_CVE-2026-49108

Unauthenticated PHP Object Injection in Moderno < 1.43 versions.

park_of_ideas Moderno n/a CVE
HIGH 8.1 CVE-2026-40757

WordPress Château theme <= 1.2.1 - PHP Object Injection vulnerability_CVE-2026-40757

Unauthenticated PHP Object Injection in Château

Mikado-Themes Château n/a CVE
HIGH 8.1 CVE-2026-40756

WordPress Zoya theme <= 1.4 - PHP Object Injection vulnerability_CVE-2026-40756

Unauthenticated PHP Object Injection in Zoya

Mikado-Themes Zoya n/a CVE
HIGH 8.1 CVE-2026-40752

WordPress Manufaktur Solutions theme <= 1.1.1 - PHP Object Injection vulnerability_CVE-2026-40752

Unauthenticated PHP Object Injection in Manufaktur Solutions

Select-Themes Manufaktur Solutions n/a CVE
HIGH 8.1 CVE-2026-40738

WordPress Eldon theme <= 1.4.1 - PHP Object Injection vulnerability_CVE-2026-40738

Unauthenticated PHP Object Injection in Eldon

Edge-Themes Eldon n/a CVE
HIGH 8.1 CVE-2026-40733

WordPress ShiftUp theme <= 1.3 - PHP Object Injection vulnerability_CVE-2026-40733

Unauthenticated PHP Object Injection in ShiftUp

Mikado-Themes ShiftUp n/a CVE