In Nexter Blocks component for WordPress versions before 5.0.2 a medium severity vulnerability CVE-2025-15678 was detected. This vulnerability allows users to upload a file containing malicious JavaScript that executes when the file is accessed. To address this issue, users should upgrade Nexter Blocks to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-15678.
Read more CMSIn EONSR AEO Agent component for WordPress versions 3.7.9 and earlier a medium severity vulnerability CVE-2026-11588 was detected. This vulnerability allows unauthenticated attackers to create administrator-attributed published posts containing arbitrary web scripts. To address this issue, users should upgrade EONSR AEO Agent to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-11588.
Read more CMSIn Gutenberg Essential Blocks component for WordPress versions before 6.4.0 a high severity vulnerability CVE-2026-13154 was detected. This vulnerability allows unauthenticated users to read non-public published entries. To address this issue, users should upgrade Gutenberg Essential Blocks to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-13154.
Read more CMSIn WPCargo Track & Trace component for WordPress versions before 8.0.4 a critical severity vulnerability CVE-2026-12713 was detected. This vulnerability allows unauthenticated users to perform SQL injection attacks. To address this issue, users should upgrade WPCargo Track & Trace to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-12713.
Read more CMSIn Gutenberg Essential Blocks component for WordPress versions before 6.4.0 a high severity vulnerability CVE-2026-13153 was detected. This vulnerability allows unauthenticated users to read the lifetime number of units sold for any published product. To address this issue, users should upgrade Gutenberg Essential Blocks to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-13153.
Read more CMSIn Smash Balloon Social Photo Feed – Easy Social Feeds Plugin component for WordPress versions 6.11.3 and earlier a medium severity vulnerability CVE-2026-15452 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade Smash Balloon Social Photo Feed – Easy Social Feeds Plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15452.
Read more CMSIn wp-downloadmanager component for WordPress versions 1.68.11 and earlier a high severity vulnerability CVE-2026-18933 was detected. This vulnerability allows an administrator to upload arbitrary files. To address this issue, users should upgrade wp-downloadmanager to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-18933.
Read more CMSIn Content Egg – Affiliate Product Importer & Price Comparison component for WordPress versions 11.3.0 and earlier a high severity vulnerability CVE-2026-15979 was detected. This vulnerability allows attackers to delete arbitrary files on the server. To address this issue, users should upgrade Content Egg – Affiliate Product Importer & Price Comparison to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15979.
Read more CMSIn Documize in affected versions a high severity vulnerability CVE-2026-71234 was detected. This vulnerability allows an attacker to download attachments without proper authentication. To address this issue, users should upgrade Documize to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-71234.
Read more Productivity