In Beaver Builder Page Builder – Drag and Drop Website Builder component for WordPress versions 2.10.3.1 and earlier a medium severity vulnerability CVE-2026-18021 was detected. This vulnerability allows attackers to execute arbitrary shortcodes. To address this issue, users should upgrade Beaver Builder Page Builder – Drag and Drop Website Builder to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-18021.
Read more CMSIn Live Composer – Free WordPress Website Builder component for WordPress versions 2.1.18 and earlier a high severity vulnerability CVE-2026-16502 was detected. This vulnerability allows authenticated attackers to inject a PHP Object. To address this issue, users should upgrade Live Composer – Free WordPress Website Builder to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-16502.
Read more CMSIn EDD Product Catalog Feed by PixelYourSite component for WordPress versions 1.0.2 and earlier a high severity vulnerability CVE-2026-9331 was detected. This vulnerability allows authenticated attackers to delete arbitrary option values. To address this issue, users should upgrade EDD Product Catalog Feed by PixelYourSite to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-9331.
Read more CMSIn OpenVPN versions 2.5.0 through 2.8.6 a medium severity vulnerability CVE-2026-82325 was detected. This vulnerability allows local authenticated users to cause a system crash. To address this issue, users should upgrade OpenVPN to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-82325.
Read more SecurityIn Powerkit component for WordPress versions 3.0.4 and earlier a medium severity vulnerability CVE-2026-2390 was detected. This vulnerability allows attackers to inject arbitrary web scripts. To address this issue, users should upgrade Powerkit to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2390.
Read more CMSIn Flamingo component for WordPress versions 2.6.2 and earlier a medium severity vulnerability CVE-2026-12853 was detected. This vulnerability allows unauthorized users to perform restricted actions. To address this issue, users should upgrade Flamingo to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-12853.
Read more CMSIn Otter Blocks component for WordPress versions 3.1.7 and earlier a medium severity vulnerability CVE-2026-4945 was detected. This vulnerability allows unauthenticated attackers to pay for a lower-cost product while obtaining entitlement for a premium product. To address this issue, users should upgrade Otter Blocks to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-4945.
Read more CMSIn User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor component for WordPress versions 3.15.7 and earlier a high severity vulnerability CVE-2026-6431 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-6431.
Read more CMSIn JetFormBuilder component for WordPress versions before 3.6.5.2 a medium severity vulnerability CVE-2026-19859 was detected. This vulnerability allows unauthenticated users to execute arbitrary shortcodes. To address this issue, users should upgrade JetFormBuilder to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-19859.
Read more CMS