In SAML Single Sign On – SSO Login component for WordPress versions up to and including 5.4.4 a critical severity vulnerability CVE-2026-15981 was detected. This vulnerability allows attackers to bypass authentication. To address this issue, users should upgrade SAML Single Sign On – SSO Login to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15981.
Read more CMSIn Clover Payment Gateway by Zaytech component for WooCommerce versions before 1.3.6 a high severity vulnerability CVE-2026-12493 was detected. This vulnerability allows unauthenticated users to mark arbitrary orders as paid. To address this issue, users should upgrade Clover Payment Gateway by Zaytech to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-12493.
Read more E-commerceIn Cal a critical severity vulnerability CVE-2026-16624 was detected. This vulnerability allows any authenticated user to create a webhook on any team and steal booking data. To address this issue, users should upgrade Cal to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-16624.
Read more ProductivityIn the Quix Page Builder component for Joomla versions prior to 6.2.1 a high severity vulnerability CVE-2026-60027 was detected. This vulnerability allows unauthenticated users to read arbitrary files via path traversal. To address this issue, users should upgrade Quix Page Builder to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-60027.
Read more CMSIn Quix Page Builder component for Joomla versions 6.2.1 and earlier a medium severity vulnerability CVE-2026-60029 was detected. This vulnerability allows authenticated users to perform a stored cross-site scripting (XSS) attack. To address this issue, users should upgrade Quix Page Builder to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-60029.
Read more CMSIn Quix Page Builder component for Joomla versions before 6.2.1 a high severity vulnerability CVE-2026-60030 was detected. This vulnerability allows authenticated users to upload media files regardless of their media management permissions. To address this issue, users should upgrade Quix Page Builder to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-60030.
Read more CMSIn Quix Page Builder component for Joomla versions 6.2.1 and earlier a high severity vulnerability CVE-2026-60026 was detected. This vulnerability allows an authenticated user to execute arbitrary PHP code. To address this issue, users should upgrade Quix Page Builder to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-60026.
Read more CMSIn Unlimited Elements For Elementor component for WordPress versions before 2.0.11 a high severity vulnerability CVE-2026-10081 was detected. This vulnerability allows unauthenticated attackers to inject malicious scripts into pages displaying Google Reviews. To address this issue, users should upgrade Unlimited Elements For Elementor to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-10081.
Read more CMSIn Reviews Feed component for WordPress versions before 2.6.5 a medium severity vulnerability CVE-2026-10724 was detected. This vulnerability allows unauthenticated attackers to execute arbitrary shortcodes. To address this issue, users should upgrade Reviews Feed to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-10724.
Read more CMS