7.1
CVE-2026-32517 - WordPress Contact Manager plugin <= 9.1 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kleor Contact Manager contact-manager allows Reflected XSS.This issue affects Contact Manager: from n/a through <= 9.1.
8.5
CVE-2026-32516 - WordPress Miraculous Core Plugin plugin < 2.1.2 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Blind SQL Injection.This issue affects Miraculous Core Plugin: from n/a through < 2.1.2.
7.5
CVE-2026-32515 - WordPress Miraculous theme < 2.1.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in kamleshyadav Miraculous miraculous allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Miraculous: from n/a through < 2.1.2.
6.5
CVE-2026-32514 - WordPress Petitioner plugin <= 0.7.3 - Broken Access Control vulnerability
Missing Authorization vulnerability in Anton Voytenko Petitioner petitioner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Petitioner: from n/a through <= 0.7.3.
8.8
CVE-2026-32513 - WordPress JS Archive List plugin <= 6.1.7 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows Object Injection.This issue affects JS Archive List: from n/a through <= 6.1.7.
9.8
CVE-2026-32512 - WordPress Pelicula theme < 1.10 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows Object Injection.This issue affects Pelicula: from n/a through < 1.10.
5.4
CVE-2026-32511 - WordPress StΓ₯l theme < 1.7 - Arbitrary Object Instantiation vulnerability
Deserialization of Untrusted Data vulnerability in Mikado-Themes StΓ₯l stal allows Object Injection.This issue affects StΓ₯l: from n/a through < 1.7.
5.4
CVE-2026-32510 - WordPress Kamperen theme < 1.3 - Arbitrary Object Instantiation vulnerability
Deserialization of Untrusted Data vulnerability in Edge-Themes Kamperen kamperen allows Object Injection.This issue affects Kamperen: from n/a through < 1.3.
5.4
CVE-2026-32509 - WordPress Gracey theme < 1.4 - Arbitrary Object Instantiation vulnerability
Deserialization of Untrusted Data vulnerability in Edge-Themes Gracey gracey allows Object Injection.This issue affects Gracey: from n/a through < 1.4.
5.4
CVE-2026-32508 - WordPress Halstein theme < 1.8 - Arbitrary Object Instantiation vulnerability
Deserialization of Untrusted Data vulnerability in Mikado-Themes Halstein halstein allows Object Injection.This issue affects Halstein: from n/a through < 1.8.