In 爱采集数据采集和发布插件 component for WordPress versions 1.0.0 and earlier a medium severity vulnerability CVE-2026-77013 was detected. This vulnerability allows unauthenticated users to create WordPress user accounts and taxonomy terms. To address this issue, users should upgrade 爱采集数据采集和发布插件 to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-77013.
Read more CMSIn Forgejo versions 15.0.4 and earlier a medium severity vulnerability CVE-2026-82556 was detected. This vulnerability allows a remote attacker to exploit a server-side request forgery (SSRF) issue. To address this issue, users should upgrade Forgejo to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-82556.
Read more Developer ToolsIn ACPT (Pro) – Custom Post Types Plugin component for WordPress versions 2.0.63 and earlier a high severity vulnerability CVE-2026-32564 was detected. This vulnerability allows an attacker to execute SQL commands. To address this issue, users should upgrade ACPT (Pro) – Custom Post Types Plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-32564.
Read more CMSIn Booking and Rental Manager component for WordPress versions 2.7.5 and earlier a high severity vulnerability CVE-2026-78257 was detected. This vulnerability allows authenticated attackers with low privileges to inject arbitrary PHP objects. To address this issue, users should upgrade Booking and Rental Manager to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-78257.
Read more CMSIn ACPT (Pro) – Custom Post Types component for WordPress versions 2.0.63 and earlier a critical severity vulnerability CVE-2026-32566 was detected. This vulnerability allows an unauthenticated attacker to escalate their privileges. To address this issue, users should upgrade ACPT (Pro) – Custom Post Types to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-32566.
Read more CMSIn Music Player for WooCommerce component for WooCommerce versions 1.8.9 and earlier a high severity vulnerability CVE-2026-78283 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade Music Player for WooCommerce to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-78283.
Read more E-commerceIn Fluent Boards Pro component for WordPress versions 2.0.11 and earlier a high severity vulnerability CVE-2026-78276 was detected. This vulnerability allows authenticated attackers with editor-level access to inject a PHP Object. To address this issue, users should upgrade Fluent Boards Pro to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-78276.
Read more CMSIn Reviews and Rating – Google Reviews plugin component for WordPress versions 5.10 and earlier a medium severity vulnerability CVE-2026-2388 was detected. This vulnerability allows attackers to inject malicious scripts. To address this issue, users should upgrade Reviews and Rating – Google Reviews plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2388.
Read more CMSIn WP Data Access component for WordPress versions 5.5.68 and earlier a medium severity vulnerability CVE-2026-3235 was detected. This vulnerability allows unauthenticated attackers to access data from protected app containers. To address this issue, users should upgrade WP Data Access to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-3235.
Read more CMS