Common Vulnerabilities and Exposures (CVE)

CVE-2026-85002

Sep 28, 2026 00:48:09 UTC

The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting atta...

CVE-2026-86609

Sep 28, 2026 00:48:09 UTC

The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to pe...

CVE-2026-86839

Sep 28, 2026 00:48:08 UTC

The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authentica...

CVE-2026-86841

Sep 28, 2026 00:48:08 UTC

The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users grante...

CVE-2026-89000

Sep 28, 2026 00:48:08 UTC

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side, allowing users with contributor-level access and above...

CVE-2026-89001

Sep 28, 2026 00:48:08 UTC

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing users with contributor-level access and abo...

CVE-2026-89003

Sep 28, 2026 00:48:08 UTC

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to ...

CVE-2026-89006

Sep 28, 2026 00:48:08 UTC

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2026-92436

Sep 28, 2026 00:48:08 UTC

The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauth...

CVE-2026-92995

Sep 28, 2026 00:48:07 UTC

The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization.

CVE-2026-96895

Sep 28, 2026 00:48:07 UTC

The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block, which could allow users with a role as low as contributor to pe...

CVE-2026-96896

Sep 28, 2026 00:48:07 UTC

The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and de...

CVE-2026-96897

Sep 28, 2026 00:48:07 UTC

The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that is available to logged-out users, allowing unauthenticated attackers to force the creation of a fixed author-role ...

CVE-2026-96899

Sep 28, 2026 00:48:07 UTC

The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it and echoing it into the document head when the post is rendered, allowing users w...

CVE-2026-97227

Sep 28, 2026 00:48:07 UTC

The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its p...