Total CVEs

140,409

Critical Severity

3,747

High Severity

13,543

Last 7 Days

1,657
Quick preset (or use dates below)
Clear Filters
Showing 7,061 - 7,080 of 13,935 CVEs
CVE-2026-39543 MEDIUM - 5.3

Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.21.4.

Vendor: Themefic
Product: Tourfic
Published: Apr 08, 2026
Source: NVD
CVE-2026-39542 MEDIUM - 5.3

Insertion of Sensitive Information Into Sent Data vulnerability in Doofinder Doofinder for WooCommerce doofinder-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Doofinder for WooCommerce: from n/a through <= 2.10.13.

Vendor: Doofinder
Product: Doofinder for WooCommerce
Published: Apr 08, 2026
Source: NVD
CVE-2026-39541 MEDIUM - 5.9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Stored XSS.This issue affects Hydra Booking: from n/a through <= 1.1.38.

Vendor: Themefic
Product: Hydra Booking
Published: Apr 08, 2026
Source: NVD
CVE-2026-39536 MEDIUM - 5.3

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Chill RSVP and Event Management rsvp allows Retrieve Embedded Sensitive Data.This issue affects RSVP and Event Management: from n/a through <= 2.7.16.

Vendor: WP Chill
Product: RSVP and Event Management
Published: Apr 08, 2026
Source: NVD
CVE-2026-39535 MEDIUM - 5.3

Missing Authorization vulnerability in fullworks Display Eventbrite Events widget-for-eventbrite-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display Eventbrite Events: from n/a through <= 6.5.6.

Vendor: fullworks
Product: Display Eventbrite Events
Published: Apr 08, 2026
Source: NVD
CVE-2026-39528 MEDIUM - 5.3

Missing Authorization vulnerability in WP Delicious WP Delicious delicious-recipes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Delicious: from n/a through <= 1.9.5.

Vendor: WP Delicious
Product: WP Delicious
Published: Apr 08, 2026
Source: NVD
CVE-2026-39526 MEDIUM - 5.4

Authorization Bypass Through User-Controlled Key vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpStream: from n/a through < 4.11.2.

Vendor: wpstream
Product: WpStream
Published: Apr 08, 2026
Source: NVD
CVE-2026-39521 MEDIUM - 4.9

Server-Side Request Forgery (SSRF) vulnerability in Nelio Software Nelio Content nelio-content allows Server Side Request Forgery.This issue affects Nelio Content: from n/a through <= 4.3.1.

Vendor: Nelio Software
Product: Nelio Content
Published: Apr 08, 2026
Source: NVD
CVE-2026-39520 MEDIUM - 5.3

Missing Authorization vulnerability in weDevs weDocs wedocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects weDocs: from n/a through <= 2.1.18.

Vendor: weDevs
Product: weDocs
Published: Apr 08, 2026
Source: NVD
CVE-2026-39517 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Filter blog-filter allows DOM-Based XSS.This issue affects Blog Filter: from n/a through <= 1.7.6.

Vendor: A WP Life
Product: Blog Filter
Published: Apr 08, 2026
Source: NVD
CVE-2026-39516 MEDIUM - 5.3

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Retrieve Embedded Sensitive Data.This issue affects Nexter Blocks: from n/a through <= 4.7.0.

Vendor: POSIMYTH
Product: Nexter Blocks
Published: Apr 08, 2026
Source: NVD
CVE-2026-39509 MEDIUM - 5.3

Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through <= 8.5.10.

Vendor: wpWax
Product: Directorist
Published: Apr 08, 2026
Source: NVD
CVE-2026-39508 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Kohlbach Advanced Coupons for WooCommerce Coupons advanced-coupons-for-woocommerce-free allows DOM-Based XSS.This issue affects Advanced Coupons for WooCommerce Coupons: from n/a thro...

Vendor: Josh Kohlbach
Product: Advanced Coupons for WooCommerce Coupons
Published: Apr 08, 2026
Source: NVD
CVE-2026-39506 MEDIUM - 4.3

Missing Authorization vulnerability in Jordy Meow AI Engine (Pro) ai-engine-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Engine (Pro): from n/a through < 3.4.2.

Vendor: Jordy Meow
Product: AI Engine (Pro)
Published: Apr 08, 2026
Source: NVD
CVE-2026-39505 MEDIUM - 5.3

Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.14.2.

Vendor: Craig Hewitt
Product: Seriously Simple Podcasting
Published: Apr 08, 2026
Source: NVD
CVE-2026-39504 MEDIUM - 5.4

Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InstaWP Connect: from n/a through <= 0.1.2.5.

Vendor: InstaWP
Product: InstaWP Connect
Published: Apr 08, 2026
Source: NVD
CVE-2026-39501 MEDIUM - 5.3

Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FOX: from n/a through <= 1.4.5.

Vendor: RealMag777
Product: FOX
Published: Apr 08, 2026
Source: NVD
CVE-2026-39500 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat themesflat-addons-for-elementor themesflat-addons-for-elementor allows Stored XSS.This issue affects themesflat-addons-for-elementor: from n/a through <= 2.3.2.

Vendor: Themesflat
Product: themesflat-addons-for-elementor
Published: Apr 08, 2026
Source: NVD
CVE-2026-39488 MEDIUM - 6.3

Missing Authorization vulnerability in SureCart SureCart surecart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SureCart: from n/a through <= 4.0.2.

Vendor: SureCart
Product: SureCart
Published: Apr 08, 2026
Source: NVD
CVE-2026-39485 MEDIUM - 4.3

Missing Authorization vulnerability in embedplus Youtube Embed Plus youtube-embed-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youtube Embed Plus: from n/a through <= 14.2.4.

Vendor: embedplus
Product: Youtube Embed Plus
Published: Apr 08, 2026
Source: NVD