Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.1 CVE-2026-57322

WordPress weMail plugin <= 2.1.2 - Reflected Cross Site Scripting (XSS) vulnerability_CVE-2026-57322

Unauthenticated Cross Site Scripting (XSS) in weMail

weDevs weMail n/a CVE
HIGH 7.1 CVE-2026-57321

WordPress H5P plugin <= 1.17.7 - Arbitrary File Deletion vulnerability_CVE-2026-57321

Contributor Arbitrary File Deletion in H5P

icc0rz H5P n/a CVE
HIGH 7.1 CVE-2026-57319

WordPress FOX plugin <= 1.4.8 - Cross Site Scripting (XSS) vulnerability_CVE-2026-57319

Unauthenticated Cross Site Scripting (XSS) in FOX

RealMag777 FOX n/a CVE
MEDIUM 6.5 CVE-2026-57318

WordPress Site Reviews plugin <= 8.0.11 - Sensitive Data Exposure vulnerability_CVE-2026-57318

Subscriber Sensitive Data Exposure in Site Reviews

Gemini Labs Site Reviews n/a CVE
HIGH 7.1 CVE-2026-57317

WordPress Simply Schedule Appointments plugin <= 1.6.12.2 - Cross Site Scripting (XSS) vulnerability_CVE-2026-57317

Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments

NSquared Simply Schedule Appointments n/a CVE
MEDIUM 6.5 CVE-2026-57316

WordPress GetGenie plugin <= 4.4.2 - Sensitive Data Exposure vulnerability_CVE-2026-57316

Subscriber Sensitive Data Exposure in GetGenie

Roxnor GetGenie n/a CVE
HIGH 8.5 CVE-2026-57315

WordPress Blocksy Companion Pro plugin <= 2.1.45 - Remote Code Execution (RCE) vulnerability_CVE-2026-57315

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro

Creative Themes Blocksy Companion Pro n/a CVE
HIGH 7.1 CVE-2026-57314

WordPress SureCart plugin <= 4.3.2 - Reflected Cross Site Scripting (XSS) vulnerability_CVE-2026-57314

Unauthenticated Cross Site Scripting (XSS) in SureCart

SureCart SureCart n/a CVE
MEDIUM 6.5 CVE-2026-57313

WordPress SureCart plugin <= 4.2.2 - Cross Site Scripting (XSS) vulnerability_CVE-2026-57313

Subscriber Cross Site Scripting (XSS) in SureCart

SureCart SureCart n/a CVE
HIGH 7.1 CVE-2026-57312

WordPress Everest Forms plugin <= 3.4.8 - Reflected Cross Site Scripting (XSS) vulnerability_CVE-2026-57312

Unauthenticated Cross Site Scripting (XSS) in Everest Forms

wpeverest Everest Forms n/a CVE