Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.3 CVE-2026-57657

WordPress Gmail SMTP plugin <= 1.2.3.19 - Cross Site Request Forgery (CSRF) vulnerability_CVE-2026-57657

Unauthenticated Cross Site Request Forgery (CSRF) in Gmail SMTP

Noor Alam Gmail SMTP n/a CVE
MEDIUM 5.9 CVE-2026-57656

WordPress Hester Core plugin <= 1.1.8 - Cross Site Scripting (XSS) vulnerability_CVE-2026-57656

Author Cross Site Scripting (XSS) in Hester Core

peregrinethemes Hester Core n/a CVE
HIGH 8.2 CVE-2026-57655

WordPress Child theme Wizard plugin <= 1.4 - Cross Site Request Forgery (CSRF) vulnerability_CVE-2026-57655

Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard

Jay Versluis Child Theme Wizard n/a CVE
MEDIUM 6.5 CVE-2026-57654

WordPress Affiliates Manager plugin <= 2.9.49 - Broken Access Control vulnerability_CVE-2026-57654

Affiliate Broken Access Control in Affiliates Manager

wp.insider Affiliates Manager n/a CVE
HIGH 8.5 CVE-2026-57653

WordPress WP Job Portal plugin <= 2.5.2 - SQL Injection vulnerability_CVE-2026-57653

Contributor SQL Injection in WP Job Portal

wpjobportal WP Job Portal n/a CVE
MEDIUM 5.3 CVE-2026-57652

WordPress JS Help Desk plugin <= 3.1.0 - Insecure Direct Object References (IDOR) vulnerability_CVE-2026-57652

Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk

JoomSky JS Help Desk n/a CVE
MEDIUM 6.5 CVE-2026-57651

WordPress Ghost Kit plugin <= 3.6.0 - Cross Site Scripting (XSS) vulnerability_CVE-2026-57651

Contributor Cross Site Scripting (XSS) in Ghost Kit

nK Ghost Kit n/a CVE
MEDIUM 6.5 CVE-2026-57650

WordPress Magazine Blocks plugin <= 1.8.3 - Cross Site Scripting (XSS) vulnerability_CVE-2026-57650

Contributor Cross Site Scripting (XSS) in Magazine Blocks

BlockArt Magazine Blocks n/a CVE
MEDIUM 4.3 CVE-2026-57649

WordPress Shoppable Images Lite plugin <= 1.3 - Broken Access Control vulnerability_CVE-2026-57649

Subscriber Broken Access Control in Shoppable Images Lite

studiowombat Shoppable Images Lite n/a CVE
MEDIUM 4.3 CVE-2026-57648

WordPress Nelio Content plugin <= 4.3.4 - Broken Access Control vulnerability_CVE-2026-57648

Contributor Broken Access Control in Nelio Content

Nelio Software Nelio Content n/a CVE