Common Vulnerabilities and Exposures (CVE)

CVE-2026-66670

Aug 24, 2026 11:54:58 UTC

Unauthenticated Local File Inclusion in Måne <= 1.7 versions.

CVE-2026-66650

Aug 24, 2026 11:54:58 UTC

Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.

CVE-2026-66648

Aug 24, 2026 11:54:57 UTC

Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.

CVE-2026-66610

Aug 24, 2026 11:54:56 UTC

Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.

CVE-2026-66587

Aug 24, 2026 11:54:55 UTC

Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

CVE-2026-66585

Aug 24, 2026 11:54:55 UTC

Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.

CVE-2026-32558

Aug 24, 2026 11:54:54 UTC

Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.

CVE-2026-32551

Aug 24, 2026 11:54:53 UTC

Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.

CVE-2026-32478

Aug 24, 2026 11:54:52 UTC

Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.

CVE-2026-32477

Aug 24, 2026 11:54:52 UTC

Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.

CVE-2026-32476

Aug 24, 2026 11:54:51 UTC

Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions.

CVE-2026-32471

Aug 24, 2026 11:54:50 UTC

Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.

CVE-2026-28190

Aug 24, 2026 11:54:49 UTC

Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.

CVE-2026-28171

Aug 24, 2026 11:54:49 UTC

Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.

CVE-2026-28167

Aug 24, 2026 11:54:48 UTC

Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.