8.8
CVE-2025-13062 - Supreme Modules Lite <= 2.5.62 - Authenticated (Author+) Arbitrary File Upload via JSON Upload Bypaβ¦
The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.5.62. This is due to insufficient file type validation detecting JSON files, allowing double extension files to bypass sanitization while being accepted as a valid JSON file.β¦
5.3
CVE-2025-12895 - Kalium <= 3.29 - Missing Authorization to Unauthenticated Mail Relay via kalium_vc_contact_form_reqβ¦
The Kalium 3 | Creative WordPress & WooCommerce Theme theme for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the kalium_vc_contact_form_request() function in all versions up to, and including, 3.29. This makes it possible for unauthenticated attackers tβ¦
4.3
CVE-2026-22646 -
Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the application's internal structuβ¦
5.3
CVE-2026-22645 -
The application discloses all used components, versions and license information to unauthenticated actors, giving attackers the opportunity to target known security vulnerabilities of used components.
5.3
CVE-2026-22644 -
Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access.
0.0
CVE-2026-22643 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
0.0
CVE-2026-22642 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
0.0
CVE-2026-22641 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
0.0
CVE-2026-22640 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
0.0
CVE-2026-22639 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.