Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.1 CVE-2026-57658

WordPress TemplateSpare plugin <= 4.2.0 - Arbitrary File Upload vulnerability_CVE-2026-57658

Administrator Arbitrary File Upload in TemplateSpare

Templatespare TemplateSpare n/a CVE
CRITICAL 9.3 CVE-2026-56070

WordPress Advance Product Search plugin <= 1.4.4 - SQL Injection vulnerability_CVE-2026-56070

Unauthenticated SQL Injection in Advance Product Search

ThemeHunk Advance Product Search n/a CVE
CRITICAL 9.3 CVE-2026-56068

WordPress JetEngine plugin <= 3.8.10.2 - SQL Injection vulnerability_CVE-2026-56068

Unauthenticated SQL Injection in JetEngine

Crocoblock. Jetimpex Inc. JetEngine n/a CVE
CRITICAL 9.3 CVE-2026-56067

WordPress JetSmartFilters plugin <= 3.8.3 - SQL Injection vulnerability_CVE-2026-56067

Unauthenticated SQL Injection in JetSmartFilters

Crocoblock. Jetimpex Inc. JetSmartFilters n/a CVE
CRITICAL 9.3 CVE-2026-56062

WordPress Quotes llama plugin <= 3.1.5 - SQL Injection vulnerability_CVE-2026-56062

Unauthenticated SQL Injection in Quotes llama

oooorgle Quotes llama n/a CVE
CRITICAL 9.9 CVE-2026-56059

WordPress Travel Booking theme <= 2.2.5 - Arbitrary File Upload vulnerability_CVE-2026-56059

Subscriber Arbitrary File Upload in Travel Booking

PhysCode Travel Booking n/a CVE
CRITICAL 9.9 CVE-2026-56058

WordPress Quform plugin <= 2.23.0 - Arbitrary File Upload vulnerability_CVE-2026-56058

Subscriber Arbitrary File Upload in Quform

ThemeCatcher Quform n/a CVE
CRITICAL 9.8 CVE-2026-56057

WordPress Uncanny Automator Pro plugin <= 7.3.0.6 - PHP Object Injection vulnerability_CVE-2026-56057

Subscriber PHP Object Injection in Uncanny Automator Pro

Uncanny Owl Uncanny Automator Pro n/a CVE
CRITICAL 9.3 CVE-2026-56036

WordPress 워드프레스 결제 심플페이 plugin <= 5.5.6 - SQL Injection vulnerability_CVE-2026-56036

Unauthenticated SQL Injection in 워드프레스 결제 심플페이

codemstory 워드프레스 결제 심플페이 5.5.6 CVE
CRITICAL 9.3 CVE-2026-56034

WordPress Library Management System plugin <= 3.5.7 - SQL Injection vulnerability_CVE-2026-56034

Unauthenticated SQL Injection in Library Management System

Online Web Tutor Library Management System n/a CVE