5.3

CVSS3.1

CVE-2026-24525 - WordPress CLP Varnish Cache plugin <= 1.0.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in CloudPanel CLP Varnish Cache clp-varnish-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CLP Varnish Cache: from n/a through <= 1.0.2.

πŸ“… Published: Jan. 23, 2026, 2:28 p.m. πŸ”„ Last Modified: April 24, 2026, 6:17 p.m.

4.3

CVSS3.1

CVE-2026-24524 - WordPress Tablesome plugin <= 1.2.8 - Broken Access Control vulnerability

Missing Authorization vulnerability in Essekia Tablesome tablesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tablesome: from n/a through <= 1.2.8.

πŸ“… Published: Jan. 23, 2026, 2:28 p.m. πŸ”„ Last Modified: April 24, 2026, 6:17 p.m.

5.3

CVSS3.1

CVE-2026-24523 - WordPress WP FullCalendar plugin <= 1.6 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Retrieve Embedded Sensitive Data.This issue affects WP FullCalendar: from n/a through <= 1.6.

πŸ“… Published: Jan. 23, 2026, 2:28 p.m. πŸ”„ Last Modified: April 24, 2026, 6:17 p.m.

4.3

CVSS3.1

CVE-2026-24522 - WordPress WP Subscribe plugin <= 1.2.16 - Broken Access Control vulnerability

Missing Authorization vulnerability in MyThemeShop WP Subscribe wp-subscribe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Subscribe: from n/a through <= 1.2.16.

πŸ“… Published: Jan. 23, 2026, 2:28 p.m. πŸ”„ Last Modified: April 24, 2026, 6:17 p.m.

4.3

CVSS3.1

CVE-2026-24521 - WordPress Kama Thumbnail plugin <= 3.5.1 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Timur Kamaev Kama Thumbnail kama-thumbnail allows Cross Site Request Forgery.This issue affects Kama Thumbnail: from n/a through <= 3.5.1.

πŸ“… Published: Jan. 23, 2026, 2:28 p.m. πŸ”„ Last Modified: April 16, 2026, 7:45 a.m.

4.3

CVSS3.1

CVE-2025-13921 - weDocs <= 2.1.16 - Missing Authorization to Authenticated (Subscriber+) Documentation Post Update

The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to unauthorized modification or loss of data due to a missing capability check on the 'wedocs_user_documentation_handling_capabilities' function in all versions up to, and including, 2.1…

πŸ“… Published: Jan. 23, 2026, 1:24 p.m. πŸ”„ Last Modified: April 21, 2026, 12:30 a.m.

6.4

CVSS3.1

CVE-2026-0914 - WP DSGVO Tools (GDPR) <= 3.1.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lw_…

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lw_content_block' shortcode in all versions up to, and including, 3.1.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a…

πŸ“… Published: Jan. 23, 2026, 12:26 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-14866 - Melapress Role Editor <= 1.1.1 - Improper Authorization to Authenticated (Subscriber+) Privilege Es…

The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.1. This is due to a misconfigured capability check on the 'save_secondary_roles_field' function. This makes it possible for authenticated attackers, with Subscriber-level a…

πŸ“… Published: Jan. 23, 2026, 12:26 p.m. πŸ”„ Last Modified: April 22, 2026, 8:15 p.m.

10

CVSS3.1

CVE-2025-4320 - Information Disclosure in Birebirsoft's Sufirmam

Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Authentication Bypass, Password Recovery Exploitation.This issue affects Sufirmam: through 23012026.Β NOTE: The vendor was…

πŸ“… Published: Jan. 23, 2026, 12:26 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.4

CVSS3.1

CVE-2025-4319 - Improper Access Control in Birebirsoft's Sufirmam

Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Brute Force, Password Recovery Exploitation.This issue affects Sufirmam: through 23012026.Β NOTE: The vend…

πŸ“… Published: Jan. 23, 2026, 12:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 1976 of 34,919
Β« previous page Β» next page
Filters