7.2
CVE-2026-24963 - WordPress Amelia plugin <= 1.2.38 - Privilege Escalation vulnerability
Incorrect Privilege Assignment vulnerability in ameliabooking Amelia ameliabooking allows Privilege Escalation.This issue affects Amelia: from n/a through <= 1.2.38.
9.9
CVE-2026-24960 - WordPress Charety theme < 2.0.2 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Charety charety allows Using Malicious Files.This issue affects Charety: from n/a through < 2.0.2.
7.5
CVE-2026-24385 - WordPress Podlove Web Player plugin <= 5.9.1 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in gerritvanaaken Podlove Web Player podlove-web-player allows Object Injection.This issue affects Podlove Web Player: from n/a through <= 5.9.1.
9.1
CVE-2026-23802 - WordPress AI Engine plugin <= 3.3.2 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine ai-engine allows Using Malicious Files.This issue affects AI Engine: from n/a through <= 3.3.2.
8.1
CVE-2026-23801 - WordPress The Issue theme <= 1.6.11 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes The Issue theissue allows PHP Local File Inclusion.This issue affects The Issue: from n/a through <= 1.6.11.
6.5
CVE-2026-23799 - WordPress Tutor LMS plugin <= 3.9.5 - Broken Access Control vulnerability
Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.5.
8.8
CVE-2026-23798 - WordPress PowerPress Podcasting plugin <= 11.15.10 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in blubrry PowerPress Podcasting powerpress allows Object Injection.This issue affects PowerPress Podcasting: from n/a through <= 11.15.10.
6.5
CVE-2026-23546 - WordPress Classified Listing plugin <= 5.3.4 - Sensitive Data Exposure vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in RadiusTheme Classified Listing classified-listing allows Retrieve Embedded Sensitive Data.This issue affects Classified Listing: from n/a through <= 5.3.4.
9.8
CVE-2026-22501 - WordPress Mounthood theme <= 1.3.2 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in axiomthemes Mounthood mounthood allows Object Injection.This issue affects Mounthood: from n/a through <= 1.3.2.
9.8
CVE-2026-22497 - WordPress Jardi theme <= 1.7.2 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in AncoraThemes Jardi jardi allows Object Injection.This issue affects Jardi: from n/a through <= 1.7.2.