In ACPT (Pro) – Custom Post Types component for WordPress versions 2.0.63 and earlier a critical severity vulnerability CVE-2026-32566 was detected. This vulnerability allows an unauthenticated attacker to escalate their privileges. To address this issue, users should upgrade ACPT (Pro) – Custom Post Types to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-32566.
Read more CMSIn Fluent Boards Pro component for WordPress versions 2.0.11 and earlier a high severity vulnerability CVE-2026-78276 was detected. This vulnerability allows authenticated attackers with editor-level access to inject a PHP Object. To address this issue, users should upgrade Fluent Boards Pro to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-78276.
Read more CMSIn Reviews and Rating – Google Reviews plugin component for WordPress versions 5.10 and earlier a medium severity vulnerability CVE-2026-2388 was detected. This vulnerability allows attackers to inject malicious scripts. To address this issue, users should upgrade Reviews and Rating – Google Reviews plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2388.
Read more CMSIn WP Data Access component for WordPress versions 5.5.68 and earlier a medium severity vulnerability CVE-2026-3235 was detected. This vulnerability allows unauthenticated attackers to access data from protected app containers. To address this issue, users should upgrade WP Data Access to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-3235.
Read more CMSIn ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce component for WordPress versions 1.17.8 and earlier a critical severity vulnerability CVE-2026-18080 was detected. This vulnerability allows attackers to upload arbitrary files of any type. To address this issue, users should upgrade ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-18080.
Read more CMSIn Classified Listing – Mobile Number Verification component for WordPress versions 1.6.0 and earlier a high severity vulnerability CVE-2026-15985 was detected. This vulnerability allows unauthenticated attackers to authenticate as any user with a registered phone number. To address this issue, users should upgrade Classified Listing – Mobile Number Verification to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15985.
Read more CMSIn Mobile App for WooCommerce component for WooCommerce versions 0.4.62 and earlier a high severity vulnerability CVE-2026-27330 was detected. This vulnerability allows unauthenticated attackers to gain unauthorized access to the application. To address this issue, users should upgrade Mobile App for WooCommerce to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27330.
Read more E-commerceIn eCommerce Product Catalog component for WordPress versions 3.5.10 and earlier a medium severity vulnerability CVE-2026-76128 was detected. This vulnerability allows authenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade eCommerce Product Catalog to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-76128.
Read more CMSIn CM Map Locations – Visualize and share your locations in a few clicks component for WordPress versions 2.1.8 and earlier a high severity vulnerability CVE-2026-16601 was detected. This vulnerability allows attackers to upload arbitrary files. To address this issue, users should upgrade CM Map Locations – Visualize and share your locations in a few clicks to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-16601.
Read more CMS