In wp-downloadmanager component for WordPress versions 1.68.11 and earlier a high severity vulnerability CVE-2026-18933 was detected. This vulnerability allows an administrator to upload arbitrary files. To address this issue, users should upgrade wp-downloadmanager to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-18933.
Read more CMSIn Content Egg – Affiliate Product Importer & Price Comparison component for WordPress versions 11.3.0 and earlier a high severity vulnerability CVE-2026-15979 was detected. This vulnerability allows attackers to delete arbitrary files on the server. To address this issue, users should upgrade Content Egg – Affiliate Product Importer & Price Comparison to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15979.
Read more CMSIn Documize in affected versions a high severity vulnerability CVE-2026-71234 was detected. This vulnerability allows an attacker to download attachments without proper authentication. To address this issue, users should upgrade Documize to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-71234.
Read more ProductivityIn Exclusive Addons for Elementor component for WordPress versions 2.7.9.8 and earlier a medium severity vulnerability CVE-2026-12231 was detected. This vulnerability allows authenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade Exclusive Addons for Elementor to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-12231.
Read more CMSIn Subscriptions for WooCommerce component for WordPress versions 2.0.0 and earlier a high severity vulnerability CVE-2026-15397 was detected. This vulnerability allows unauthorized users to perform actions. To address this issue, users should upgrade Subscriptions for WooCommerce to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15397.
Read more CMSIn FuseWP component for WordPress versions 1.1.24.2 and earlier a medium severity vulnerability CVE-2026-5582 was detected. This vulnerability allows attackers to trick authenticated users into performing unintended actions. To address this issue, users should upgrade FuseWP to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-5582.
Read more CMSIn SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery component for WordPress versions 3.9.7 and earlier a critical severity vulnerability CVE-2026-15014 was detected. This vulnerability allows an attacker to take over user accounts. To address this issue, users should upgrade SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15014.
Read more CMSIn SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery component for WordPress versions 3.9.7 and earlier a medium severity vulnerability CVE-2026-15670 was detected. This vulnerability allows authenticated attackers to extract sensitive information from the database. To address this issue, users should upgrade SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15670.
Read more CMSIn Phoca Commander component for Joomla versions 6.1.1 and earlier a medium severity vulnerability CVE-2026-65764 was detected. This vulnerability allows attackers to execute arbitrary scripts in the user’s browser. To address this issue, users should upgrade Phoca Commander to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-65764.
Read more CMS