Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.9 CVE-2026-57656

WordPress Hester Core plugin <= 1.1.8 - Cross Site Scripting (XSS) vulnerability_CVE-2026-57656

Author Cross Site Scripting (XSS) in Hester Core

peregrinethemes Hester Core n/a CVE
MEDIUM 6.5 CVE-2026-57654

WordPress Affiliates Manager plugin <= 2.9.49 - Broken Access Control vulnerability_CVE-2026-57654

Affiliate Broken Access Control in Affiliates Manager

wp.insider Affiliates Manager n/a CVE
MEDIUM 5.3 CVE-2026-57652

WordPress JS Help Desk plugin <= 3.1.0 - Insecure Direct Object References (IDOR) vulnerability_CVE-2026-57652

Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk

JoomSky JS Help Desk n/a CVE
MEDIUM 6.5 CVE-2026-57651

WordPress Ghost Kit plugin <= 3.6.0 - Cross Site Scripting (XSS) vulnerability_CVE-2026-57651

Contributor Cross Site Scripting (XSS) in Ghost Kit

nK Ghost Kit n/a CVE
MEDIUM 6.5 CVE-2026-57650

WordPress Magazine Blocks plugin <= 1.8.3 - Cross Site Scripting (XSS) vulnerability_CVE-2026-57650

Contributor Cross Site Scripting (XSS) in Magazine Blocks

BlockArt Magazine Blocks n/a CVE
MEDIUM 4.3 CVE-2026-57649

WordPress Shoppable Images Lite plugin <= 1.3 - Broken Access Control vulnerability_CVE-2026-57649

Subscriber Broken Access Control in Shoppable Images Lite

studiowombat Shoppable Images Lite n/a CVE
MEDIUM 4.3 CVE-2026-57648

WordPress Nelio Content plugin <= 4.3.4 - Broken Access Control vulnerability_CVE-2026-57648

Contributor Broken Access Control in Nelio Content

Nelio Software Nelio Content n/a CVE
MEDIUM 5.4 CVE-2026-57646

WordPress Majestic Support plugin <= 1.1.7 - Insecure Direct Object References (IDOR) vulnerability_CVE-2026-57646

Subscriber Insecure Direct Object References (IDOR) in Majestic Support

Majestic Support Majestic Support n/a CVE
MEDIUM 6.5 CVE-2026-57641

WordPress Real Estate 7 theme <= 3.5.9 - Cross Site Request Forgery (CSRF) vulnerability_CVE-2026-57641

Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7

Contempoinc Real Estate 7 n/a CVE
MEDIUM 4.3 CVE-2026-57640

WordPress MasterStudy LMS plugin <= 3.7.30 - Broken Access Control vulnerability_CVE-2026-57640

Subscriber Broken Access Control in MasterStudy LMS

Stylemix MasterStudy LMS n/a CVE