Common Vulnerabilities and Exposures (CVE)

CVE-2026-94031

Sep 20, 2026 14:00:10 UTC

A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914. Affected by this issue is the function child_process.exec of the file src/auth/browser.ts of the component nexus_reauth MCP tool. The manipulatio...

CVE-2026-92410

Sep 20, 2026 13:52:59 UTC

The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in us...

CVE-2026-87963

Sep 20, 2026 13:52:50 UTC

The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attackers t...

CVE-2026-92965

Sep 20, 2026 13:52:30 UTC

The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied in the URL, so any visitor can make the site redeem a code of their choosing against the advertising platform, usi...

CVE-2026-92541

Sep 20, 2026 13:52:18 UTC

The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing...

CVE-2026-92540

Sep 20, 2026 13:52:04 UTC

The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new adm...

CVE-2026-92423

Sep 20, 2026 13:51:20 UTC

The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above to ...

CVE-2026-92422

Sep 20, 2026 13:51:04 UTC

The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a publicly reachable endpoint, allowing unau...

CVE-2026-87840

Sep 20, 2026 13:50:32 UTC

The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative booking-management actions, which are additionally exposed to unauthenticated users and gated only by a token the Tripzzy ...

CVE-2026-87839

Sep 20, 2026 13:50:17 UTC

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbit...

CVE-2026-87068

Sep 20, 2026 13:50:02 UTC

The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may import quizzes to publish a live, publicly r...

CVE-2026-87067

Sep 20, 2026 13:49:48 UTC

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file o...

CVE-2026-85017

Sep 20, 2026 13:49:34 UTC

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with ...

CVE-2026-84223

Sep 20, 2026 13:49:20 UTC

The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site-wide, allowing users with author-level access and above to upload a file containing JavaScript which is then served from the sit...

CVE-2026-82842

Sep 20, 2026 13:49:00 UTC

The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen...