Common Vulnerabilities and Exposures (CVE)

CVE-2026-84738

Sep 18, 2026 11:13:08 UTC

The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leadi...

CVE-2026-84902

Sep 18, 2026 11:12:54 UTC

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users with contributor-level access and above to overwrite the Element...

CVE-2026-84903

Sep 18, 2026 11:12:39 UTC

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password check before rendering the content of a user-supplied post, allowing users with Contributor-level access and above to r...

CVE-2026-84904

Sep 18, 2026 11:12:25 UTC

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and neve...

CVE-2026-21806

Sep 18, 2026 11:12:24 UTC

HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which could enable an unauthorized at...

CVE-2026-28198

Sep 18, 2026 11:12:23 UTC

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a specially formed access credential. Suc...

CVE-2026-85009

Sep 18, 2026 11:12:10 UTC

The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverable s...

CVE-2026-85122

Sep 18, 2026 11:11:54 UTC

The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then ren...

CVE-2026-85123

Sep 18, 2026 11:11:39 UTC

The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to create WordPress accounts on a site whose...

CVE-2026-85127

Sep 18, 2026 11:11:25 UTC

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is e...

CVE-2026-85350

Sep 18, 2026 11:11:10 UTC

The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, allowing unauthenticated users to buy arbitrary products at the campaign's di...

CVE-2026-56597

Sep 18, 2026 11:11:09 UTC

HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underlying...

CVE-2026-87767

Sep 18, 2026 11:10:56 UTC

The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter before using it in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to ...

CVE-2026-93494

Sep 18, 2026 11:10:42 UTC

A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a ByteBuf (a...

CVE-2026-87770

Sep 18, 2026 11:10:41 UTC

The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using them in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform ...