Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.1 CVE-2026-56045

WordPress Automatic plugin < 3.135.1 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56045

Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.

ValvePress Automatic n/a CVE
HIGH 7.1 CVE-2026-56044

WordPress Blog2Social plugin <= 8.9.2 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56044

Unauthenticated Cross Site Scripting (XSS) in Blog2Social

Adenion Blog2Social n/a CVE
HIGH 7.1 CVE-2026-56043

WordPress Customer Reviews for WooCommerce plugin <= 5.110.1 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56043

Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce

CusRev Customer Reviews for WooCommerce n/a CVE
HIGH 7.1 CVE-2026-56041

WordPress Responsive Lightbox plugin <= 2.7.6 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56041

Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox

dFactory Responsive Lightbox n/a CVE
HIGH 7.1 CVE-2026-56040

WordPress Gutenverse Form plugin <= 2.4.7 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56040

Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form

WordPress.com Gutenverse Form n/a CVE
HIGH 7.1 CVE-2026-56039

WordPress Quick Interest Slider plugin <= 3.1.6 - Reflected Cross Site Scripting (XSS) vulnerability_CVE-2026-56039

Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider

WordPress.com Quick Interest Slider n/a CVE
HIGH 8.8 CVE-2026-56038

WordPress Frisbii Pay plugin <= 1.8.2 - Privilege Escalation vulnerability_CVE-2026-56038

Contributor Privilege Escalation in Frisbii Pay

Frisbii Frisbii Pay n/a CVE
HIGH 8.6 CVE-2026-56035

WordPress BitFire Security plugin <= 5.0.3 - Multiple Vulnerabilities vulnerability_CVE-2026-56035

Unauthenticated Multiple Vulnerabilities in BitFire Security

Cory Marsh BitFire Security n/a CVE
HIGH 8.1 CVE-2026-56031

WordPress Uncanny Automator plugin <= 7.3.1.2 - PHP Object Injection vulnerability_CVE-2026-56031

Unauthenticated PHP Object Injection in Uncanny Automator

Uncanny Owl Uncanny Automator n/a CVE
HIGH 7.5 CVE-2026-56029

WordPress CorvusPay WooCommerce Payment Gateway plugin <= 2.7.4 - Broken Authentication vulnerability_CVE-2026-56029

Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway

corvuspay CorvusPay WooCommerce Payment Gateway n/a CVE