Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.1 CVE-2026-56041

WordPress Responsive Lightbox plugin <= 2.7.6 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56041

Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox

dFactory Responsive Lightbox n/a CVE
HIGH 7.1 CVE-2026-56040

WordPress Gutenverse Form plugin <= 2.4.7 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56040

Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form

WordPress.com Gutenverse Form n/a CVE
HIGH 7.1 CVE-2026-56039

WordPress Quick Interest Slider plugin <= 3.1.6 - Reflected Cross Site Scripting (XSS) vulnerability_CVE-2026-56039

Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider

WordPress.com Quick Interest Slider n/a CVE
HIGH 8.8 CVE-2026-56038

WordPress Frisbii Pay plugin <= 1.8.2 - Privilege Escalation vulnerability_CVE-2026-56038

Contributor Privilege Escalation in Frisbii Pay

Frisbii Frisbii Pay n/a CVE
CRITICAL 9.3 CVE-2026-56036

WordPress 워드프레스 결제 심플페이 plugin <= 5.5.6 - SQL Injection vulnerability_CVE-2026-56036

Unauthenticated SQL Injection in 워드프레스 결제 심플페이

codemstory 워드프레스 결제 심플페이 5.5.6 CVE
HIGH 8.6 CVE-2026-56035

WordPress BitFire Security plugin <= 5.0.3 - Multiple Vulnerabilities vulnerability_CVE-2026-56035

Unauthenticated Multiple Vulnerabilities in BitFire Security

Cory Marsh BitFire Security n/a CVE
CRITICAL 9.3 CVE-2026-56034

WordPress Library Management System plugin <= 3.5.7 - SQL Injection vulnerability_CVE-2026-56034

Unauthenticated SQL Injection in Library Management System

Online Web Tutor Library Management System n/a CVE
CRITICAL 9.8 CVE-2026-56033

WordPress Dokan Pro plugin <= 5.0.4 - Privilege Escalation vulnerability_CVE-2026-56033

Unauthenticated Privilege Escalation in Dokan Pro

Dokan Multivendor Plugin Dokan Pro n/a CVE
CRITICAL 9.8 CVE-2026-56032

WordPress Buddyboss Platform plugin <= 3.0.4 - PHP Object Injection vulnerability_CVE-2026-56032

Subscriber PHP Object Injection in Buddyboss Platform

BuddyBoss Buddyboss Platform n/a CVE
HIGH 8.1 CVE-2026-56031

WordPress Uncanny Automator plugin <= 7.3.1.2 - PHP Object Injection vulnerability_CVE-2026-56031

Unauthenticated PHP Object Injection in Uncanny Automator

Uncanny Owl Uncanny Automator n/a CVE