CVE-2024-110809.8Critical—9.8CriticalPost Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injectionpickplugins post grid1 HR AGO
CVE-2026-765736.4Medium—6.4MediumPods <= 3.3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'not_found' Shortcode Attributesc0ttkclark pods – custom content types and fields1 HR AGO
CVE-2026-815438.8High—8.8HighAbandoned Cart Pro for WooCommerce <= 10.7.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalationtyche softwares abandoned cart pro for woocommerce1 HR AGO
CVE-2026-836257.2High—7.2HighContact Form by Supsystic <= 1.10.2 - Unauthenticated Stored Cross-Site Scripting via IP Address Headersupsysticcom contact form by supsystic1 HR AGO
CVE-2026-750184.3Medium—4.3MediumCustom Contact Forms <= 7.16 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Deletion and Post Meta Modification via Nested 'fields[].ID' / 'choices[].ID' Parametersoutlawgt custom contact forms1 HR AGO
CVE-2026-854146.4Medium—6.4MediumGallery : FooGallery <= 3.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_settings' Shortcode Attributefooplugins gallery : foogallery1 HR AGO
CVE-2026-755866.1Medium—6.1MediumUnlimited Elements For Elementor <= 2.0.17 - Reflected Cross-Site Scripting via 'formData[id]' Parameterunitecms unlimited elements for elementor1 HR AGO
CVE-2026-43615.0Medium—5.0MediumDivi <= 4.27.6 - Authenticated (Contributor+) Server-Side Request Forgery via 'image_src' Parameterelegant themes divi2 HR AGO
CVE-2026-38536.4Medium—6.4MediumDivi <= 4.27.6 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Slider 'image_src' Shortcode Parameterelegant themes divi2 HR AGO
CVE-2026-159847.2High—7.2HighQuickCal <= 1.0.20 - Unauthenticated Stored Cross-Site Scripting via Custom Field Parametersthemovation quickcal2 HR AGO
CVE-2026-184067.2High—7.2HighSureForms <= 2.12.2 - Unauthenticated Stored Cross-Site Scripting via Text Field Entity-Encoded Payloadbrainstormforce sureforms – contact form builder, ai forms, payment form, survey & quiz2 HR AGO
CVE-2026-198878.8High—8.8HighWelcart e-Commerce <= 2.12.1 - Unauthenticated Arbitrary File Deletion via PHP Object Injection via 'reserve' Checkout Parameter and 'option' EDY Callbackuscnanbu welcart e-commerce2 HR AGO
CVE-2026-784387.2High—7.2HighW3 Total Cache <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutatorboldgrid w3 total cache2 HR AGO
CVE-2026-149756.5Medium—6.5MediumWP File Download <= 6.3.8 - Authenticated (Subscriber+) Arbitrary File Read via Path Traversal in 'remoteurl' Parameterjoomunited wp file download2 HR AGO
CVE-2026-197697.2High—7.2HighNinja Forms <= 3.15.1 - Unauthenticated Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Keykstover ninja forms – the contact form builder that grows with you2 HR AGO