9.1

CVSS3.1

CVE-2026-24379 - WordPress WP Job Portal plugin <= 2.4.3 - Insecure Direct Object References (IDOR) vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Portal: from n/a through <= 2.4.3.

πŸ“… Published: Jan. 22, 2026, 4:52 p.m. πŸ”„ Last Modified: April 1, 2026, 2:14 p.m.

7.5

CVSS3.1

CVE-2026-24377 - WordPress Nexter Blocks plugin <= 4.6.3 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Retrieve Embedded Sensitive Data.This issue affects Nexter Blocks: from n/a through <= 4.6.3.

πŸ“… Published: Jan. 22, 2026, 4:52 p.m. πŸ”„ Last Modified: April 1, 2026, 2:14 p.m.

5.4

CVSS3.1

CVE-2026-24374 - WordPress RegistrationMagic plugin <= 6.0.6.9 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Cross Site Request Forgery.This issue affects RegistrationMagic: from n/a through <= 6.0.6.9.

πŸ“… Published: Jan. 22, 2026, 4:52 p.m. πŸ”„ Last Modified: April 1, 2026, 2:14 p.m.

9.8

CVSS3.1

CVE-2026-24371 - WordPress BA Book Everything plugin <= 1.8.16 - Broken Access Control vulnerability

Missing Authorization vulnerability in bookingalgorithms BA Book Everything ba-book-everything allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BA Book Everything: from n/a through <= 1.8.16.

πŸ“… Published: Jan. 22, 2026, 4:52 p.m. πŸ”„ Last Modified: April 1, 2026, 2:14 p.m.

8.8

CVSS3.1

CVE-2026-24368 - WordPress The Grid plugin < 2.8.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Theme-one The Grid the-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Grid: from n/a through < 2.8.0.

πŸ“… Published: Jan. 22, 2026, 4:52 p.m. πŸ”„ Last Modified: April 1, 2026, 2:14 p.m.

8.8

CVSS3.1

CVE-2026-24367 - WordPress Traveler theme < 3.2.8 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through < 3.2.8.

πŸ“… Published: Jan. 22, 2026, 4:52 p.m. πŸ”„ Last Modified: April 1, 2026, 2:14 p.m.

5.3

CVSS3.1

CVE-2026-24366 - WordPress YITH WooCommerce Request A Quote plugin <= 2.46.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in YITHEMES YITH WooCommerce Request A Quote yith-woocommerce-request-a-quote allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH WooCommerce Request A Quote: from n/a through <= 2.46.0.

πŸ“… Published: Jan. 22, 2026, 4:52 p.m. πŸ”„ Last Modified: April 1, 2026, 2:14 p.m.

5.4

CVSS3.1

CVE-2026-24365 - WordPress Stock Manager for WooCommerce plugin < 3.6.0 - Cross Site Request Forgery (CSRF) vulnerab…

Cross-Site Request Forgery (CSRF) vulnerability in storeapps Stock Manager for WooCommerce woocommerce-stock-manager allows Cross Site Request Forgery.This issue affects Stock Manager for WooCommerce: from n/a through < 3.6.0.

πŸ“… Published: Jan. 22, 2026, 4:52 p.m. πŸ”„ Last Modified: April 1, 2026, 2:14 p.m.

6.5

CVSS3.1

CVE-2026-24361 - WordPress LearnPress – Course Review plugin <= 4.1.9 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress &#8211; Course Review learnpress-course-review allows Stored XSS.This issue affects LearnPress &#8211; Course Review: from n/a through <= 4.1.9.

πŸ“… Published: Jan. 22, 2026, 4:52 p.m. πŸ”„ Last Modified: April 1, 2026, 2:14 p.m.

4.6

CVSS3.1

CVE-2026-24360 - WordPress Seriously Simple Podcasting plugin <= 3.14.1 - Server Side Request Forgery (SSRF) vulnera…

Server-Side Request Forgery (SSRF) vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Server Side Request Forgery.This issue affects Seriously Simple Podcasting: from n/a through <= 3.14.1.

πŸ“… Published: Jan. 22, 2026, 4:52 p.m. πŸ”„ Last Modified: April 1, 2026, 2:14 p.m.
Total resulsts: 343757
Page 1455 of 34,376
Β« previous page Β» next page
Filters