Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-8617

SearchPlus <= 1.7.1 - Missing Authorization to Unauthenticated Settings Modification and Deletion via searchplus_save_token & searchplus_reset_token AJAX Actions_CVE-2026-8617

The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, and including, 1.7.1. This i...

ailchev SearchPlus CVE
MEDIUM 4.3 CVE-2026-8614

Assistio <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Deletion via assistio_plugin_delete_assistio_settings AJAX Action_CVE-2026-8614

The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verificati...

assistioai Assistio CVE
MEDIUM 5.3 CVE-2026-7617

Secufor_OAuth <= 1.0.7 - Missing Authorization to Unauthenticated Account Logout via 'secuforoauth_unregister_action' AJAX Action_CVE-2026-7617

The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7. This is due to the plugin ...

secufor Secufor_OAuth CVE
MEDIUM 4.3 CVE-2026-6292

MP Customize Login Page <= 1.0 - Cross-Site Request Forgery to Settings Update_CVE-2026-6292

The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to and including 1.0. This i...

manuelpadillac MP Customize Login Page CVE
MEDIUM 5.3 CVE-2026-12094

Advanced Contact Form 7 <= 1.0.0 - Missing Authorization to Unauthenticated Arbitrary Contact Form Submission Deletion via 'form_id' Parameter_CVE-2026-12094

The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on t...

iamranit Advanced Contact Form 7 – Compact DB CVE
MEDIUM 4.3 CVE-2026-11997

Bulk SEO Image <= 1.1 - Cross-Site Request Forgery to Settings Update_CVE-2026-11997

The Bulk SEO Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1. This is due to missing or ...

seo_tools Bulk SEO Image CVE
MEDIUM 6.4 CVE-2026-11370

WP Meta SEO <= 4.5.18 - Authenticated (Contributor+) Server-Side Request Forgery via 'new_link' Parameter_CVE-2026-11370

The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.5.18 via the 'new_link' p...

joomunited WP Meta SEO CVE
MEDIUM 4.3 CVE-2026-10552

Blue Captcha <= 2.0.1 - Cross-Site Request Forgery via 'blcap_action' Parameter_CVE-2026-10552

The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1. This is due to missing or ...

jotis Blue Captcha CVE
MEDIUM 6.5 CVE-2026-9539

libslirp TCP URG OOB Read Information Leak_CVE-2026-9539

An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on h...

freedesktop.org libslirp CVE
MEDIUM 6.2 CVE-2026-12488

GeoVision GV-VMS V20 GV-Cloud memory corruption vulnerability_CVE-2026-12488

A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2.  A specially crafted network request can l...

GeoVision Inc. GeoVision V20.0.2 CVE