In Ultimate Gift Cards For WooCommerce component for WooCommerce versions 3.2.9 and earlier a medium severity vulnerability CVE-2026-84760 was detected. This vulnerability allows unauthenticated attackers to gain unauthorized access to restricted functionalities. To address this issue, users should upgrade Ultimate Gift Cards For WooCommerce to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-84760.
Read more E-commerceIn WooCommerce Product Attachment component for WooCommerce versions 2.3.3 and earlier a high severity vulnerability CVE-2026-81774 was detected. This vulnerability allows attackers to expose sensitive data. To address this issue, users should upgrade WooCommerce Product Attachment to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-81774.
Read more E-commerceIn Ninja Forms – Layout & Styles component for WordPress versions 3.0.31 and earlier a high severity vulnerability CVE-2026-81772 was detected. This vulnerability allows unauthenticated attackers to perform PHP object injection. To address this issue, users should upgrade Ninja Forms – Layout & Styles to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-81772.
Read more CMSIn Upsell Order Bump Offer for WooCommerce component for WooCommerce versions 3.1.5 and earlier a high severity vulnerability CVE-2026-81288 was detected. This vulnerability allows unauthenticated attackers to perform Cross-Site Scripting attacks. To address this issue, users should upgrade Upsell Order Bump Offer for WooCommerce to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-81288.
Read more E-commerceIn WPBakery Page Builder component for WordPress versions 8.7.4 and earlier a medium severity vulnerability CVE-2026-15101 was detected. This vulnerability allows authenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade WPBakery Page Builder to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15101.
Read more CMSIn WP User Frontend component for WordPress versions 4.3.10 and earlier a high severity vulnerability CVE-2026-81283 was detected. This vulnerability allows attackers to perform a PHP Object Injection. To address this issue, users should upgrade WP User Frontend to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-81283.
Read more CMSIn Welcart e-Commerce plugin component for WordPress versions 2.12.1 and earlier a high severity vulnerability CVE-2026-19914 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade Welcart e-Commerce plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-19914.
Read more CMSIn miniOrange extensions component for Joomla a high severity vulnerability CVE-2026-78074 was detected. This vulnerability allows unauthenticated actors to delete arbitrary installed extensions. To address this issue, users should upgrade miniOrange extensions to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-78074.
Read more CMSIn Helix Ultimate component for Joomla versions 2.2.10 and earlier a medium severity vulnerability CVE-2026-78076 was detected. This vulnerability allows an authenticated user to modify layout parameters for arbitrary menu items without proper authorization. To address this issue, users should upgrade Helix Ultimate to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-78076.
Read more CMS