6.5

CVSS3.1

CVE-2026-32535 - WordPress JS Help Desk plugin <= 3.0.3 - Insecure Direct Object References (IDOR) vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through <= 3.0.3.

๐Ÿ“… Published: March 25, 2026, 4:15 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 1:36 p.m.

8.5

CVSS3.1

CVE-2026-32534 - WordPress JS Help Desk plugin <= 3.0.3 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL Injection.This issue affects JS Help Desk: from n/a through <= 3.0.3.

๐Ÿ“… Published: March 25, 2026, 4:15 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 11:34 a.m.

6.5

CVSS3.1

CVE-2026-32533 - WordPress LatePoint plugin <= 5.2.6 - Insecure Direct Object References (IDOR) vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in LatePoint LatePoint latepoint allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LatePoint: from n/a through <= 5.2.6.

๐Ÿ“… Published: March 25, 2026, 4:15 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 1:19 p.m.

7.1

CVSS3.1

CVE-2026-32532 - WordPress Contact Form & Lead Form Elementor Builder plugin <= 2.0.1 - Cross Site Scripting (XSS) vโ€ฆ

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder lead-form-builder allows Stored XSS.This issue affects Contact Form & Lead Form Elementor Builder: from n/a through <= 2.0.1.

๐Ÿ“… Published: March 25, 2026, 4:15 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 11:34 a.m.

8.1

CVSS3.1

CVE-2026-32531 - WordPress Kunco theme < 1.4.5 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kunco kunco allows PHP Local File Inclusion.This issue affects Kunco: from n/a through < 1.4.5.

๐Ÿ“… Published: March 25, 2026, 4:15 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 11:35 a.m.

8.8

CVSS3.1

CVE-2026-32530 - WordPress Creator LMS plugin <= 1.1.18 - Privilege Escalation vulnerability

Incorrect Privilege Assignment vulnerability in WPFunnels Creator LMS creatorlms allows Privilege Escalation.This issue affects Creator LMS: from n/a through <= 1.1.18.

๐Ÿ“… Published: March 25, 2026, 4:15 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 1:40 p.m.

7.1

CVSS3.1

CVE-2026-32529 - WordPress Molla theme < 1.5.19 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in don-themes Molla molla allows Reflected XSS.This issue affects Molla: from n/a through < 1.5.19.

๐Ÿ“… Published: March 25, 2026, 4:15 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 11:35 a.m.

7.1

CVSS3.1

CVE-2026-32528 - WordPress Riode | Multi-Purpose WooCommerce theme < 1.6.29 - Reflected Cross Site Scripting (XSS) vโ€ฆ

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in don-themes Riode riode allows Reflected XSS.This issue affects Riode: from n/a through < 1.6.29.

๐Ÿ“… Published: March 25, 2026, 4:15 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 11:35 a.m.

0.0

CVE-2026-32527 - WordPress WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin <=โ€ฆ

Missing Authorization vulnerability in CRM Perks WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-insightly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Insightly for Contact Form 7, WPForms, Elementor, Formidable aโ€ฆ

๐Ÿ“… Published: March 25, 2026, 4:15 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 11:35 a.m.

7.1

CVSS3.1

CVE-2026-32526 - WordPress Abandoned Cart Recovery for WooCommerce plugin <= 1.1.10 - Cross Site Scripting (XSS) vulโ€ฆ

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Stored XSS.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.10.

๐Ÿ“… Published: March 25, 2026, 4:15 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 11:35 a.m.
Total resulsts: 340585
Page 26 of 34,059
ยซ previous page ยป next page
Filters