Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.3 CVE-2026-11775

User Admin Simplifier <= 3.0.0 - Cross-Site Request Forgery_CVE-2026-11775

The User Admin Simplifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due...

adamsilverstein User Admin Simplifier CVE
MEDIUM 6.9 CVE-2026-56132

CVE-2026-56132_CVE-2026-56132

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled...

libexpat project libexpat CVE
MEDIUM 4.9 CVE-2026-56131

CVE-2026-56131_CVE-2026-56131

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a ...

libexpat project libexpat CVE
MEDIUM 4.3 CVE-2026-10779

Classified Listing <= 5.4.2 - Missing Authorization to Authenticated (Subscriber+) Feature Modification via Multiple AJAX Handlers ('listingId'/'id' Parameters)_CVE-2026-10779

The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and...

techlabpro1 Classified Listing – AI-Powered Classified ads & Business Directory CVE
MEDIUM 4.3 CVE-2026-9013

Bogo <= 3.9.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via REST API_CVE-2026-9013

The Bogo plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.1 via the bogo_rest_create_...

rocklobsterinc Bogo CVE
CRITICAL 9.1 CVE-2026-8713

Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion via Form Entry Value_CVE-2026-8713

The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_dele...

themefusion Avada (Fusion) Builder CVE
MEDIUM 6.5 CVE-2026-8118

Royal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1058 – 1.7.1059 – Authenticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File Source_CVE-2026-8118

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary File Read in versions 1.7.1...

wproyal Royal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1058 CVE
MEDIUM 4.9 CVE-2026-7547

Woosa <= 2.0.5 - Authenticated (Administrator+) Arbitrary File Read via 'log_file' Parameter_CVE-2026-7547

The Woosa – Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in versions up to and includin...

teamwsa Woosa – Marktplaats for WooCommerce CVE
CRITICAL 9.8 CVE-2026-7515

BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style_CVE-2026-7515

The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter...

betterdocs BetterDocs Pro CVE
CRITICAL 9.8 CVE-2026-54414

FileRise shared-folder upload path traversal allows arbitrary file write and admin takeover_CVE-2026-54414

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbi...

error311 FileRise CVE