Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.3 CVE-2026-42381

WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.1 - SQL Injection vulnerability_CVE-2026-42381

Unauthenticated SQL Injection in Funnel Builder by FunnelKit

FunnelKit Funnel Builder by FunnelKit n/a CVE
MEDIUM 6.5 CVE-2026-42378

WordPress WP Full Stripe Free plugin <= 8.4.1 - Broken Authentication vulnerability_CVE-2026-42378

Subscriber Broken Authentication in WP Full Stripe Free

Themeisle WP Full Stripe Free n/a CVE
MEDIUM 6.5 CVE-2026-41556

WordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnerability_CVE-2026-41556

Subscriber Cross Site Scripting (XSS) in ProfilePress

properfraction ProfilePress n/a CVE
MEDIUM 5.8 CVE-2026-40799

WordPress Simple Cloudflare Turnstile plugin <= 1.38.0 - Broken Authentication vulnerability_CVE-2026-40799

Unauthenticated Broken Authentication in Simple Cloudflare Turnstile

RelyWP Simple Cloudflare Turnstile n/a CVE
CRITICAL 9.3 CVE-2026-40798

WordPress wpForo Forum plugin <= 3.0.4 - SQL Injection vulnerability_CVE-2026-40798

Unauthenticated SQL Injection in wpForo Forum

Tomdever wpForo Forum n/a CVE
MEDIUM 6.5 CVE-2026-40796

WordPress WPPizza plugin <= 3.19.9 - Sensitive Data Exposure vulnerability_CVE-2026-40796

Subscriber Sensitive Data Exposure in WPPizza

ollybach WPPizza n/a CVE
MEDIUM 6.5 CVE-2026-40795

WordPress Amelia plugin <= 2.2 - Broken Access Control vulnerability_CVE-2026-40795

Subscriber Broken Access Control in Amelia

TMS Amelia n/a CVE
MEDIUM 6.5 CVE-2026-40794

WordPress myCred plugin <= 3.0.3 - Broken Access Control vulnerability_CVE-2026-40794

Subscriber Broken Access Control in myCred

myCred myCred n/a CVE
MEDIUM 6.5 CVE-2026-40793

WordPress Groundhogg plugin < 4.4.1 - Broken Access Control vulnerability_CVE-2026-40793

Subscriber Broken Access Control in Groundhogg < 4.4.1 versions.

Groundhogg Groundhogg n/a CVE
MEDIUM 6.3 CVE-2026-40792

WordPress KiviCare plugin <= 4.2.1 - Insecure Direct Object References (IDOR) vulnerability_CVE-2026-40792

Subscriber Insecure Direct Object References (IDOR) in KiviCare

Iqonic Design KiviCare n/a CVE