Common Vulnerabilities and Exposures (CVE)

CVE-2026-14817

Aug 4, 2026 17:42:39 UTC

The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with c...

CVE-2026-16042

Aug 4, 2026 17:42:33 UTC

The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.

CVE-2026-16291

Aug 4, 2026 17:42:27 UTC

The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating...

CVE-2026-16292

Aug 4, 2026 17:42:20 UTC

The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, ...

CVE-2026-18830

Aug 4, 2026 17:42:20 UTC

Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS...

CVE-2026-16062

Aug 4, 2026 17:42:13 UTC

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP...

CVE-2026-16057

Aug 4, 2026 17:42:06 UTC

The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user t...

CVE-2026-16274

Aug 4, 2026 17:41:58 UTC

The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, ...

CVE-2026-16276

Aug 4, 2026 17:41:52 UTC

The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users with contributor-level access and above to read daily revenue figures n...

CVE-2024-1132

Aug 4, 2026 17:41:50 UTC

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within t...

CVE-2025-15672

Aug 4, 2026 17:41:46 UTC

The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execu...

CVE-2025-15673

Aug 4, 2026 17:41:38 UTC

The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.

CVE-2026-14557

Aug 4, 2026 17:41:32 UTC

The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verifie...

CVE-2026-15231

Aug 4, 2026 17:41:26 UTC

The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to dis...

CVE-2024-1635

Aug 4, 2026 17:40:35 UTC

A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connecti...