| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-39643 | WordPress Payment Plugins for PayPal WooCommerce plugin <= 2.0.13 - Broken Access Control vulnerability | Payment Plugins | Payment Plugins for PayPal WooCommerce | - | - | 2026-04-08 08:30:32 | Deep Dive |
| CVE-2026-35492 | Kedro-Datasets has a path traversal vulnerability in PartitionedDataset allows arbitrary file write | kedro-org | kedro-plugins | Medium | 6.5 | 2026-04-07 15:03:46 | Deep Dive |
| CVE-2026-27397 | WordPress Really Simple Security Pro plugin <= 9.5.4.0 - Insecure Direct Object References (IDOR) vulnerability | Really Simple Plugins B.V. | Really Simple Security Pro | Medium | 6.5 | 2026-03-19 05:30:19 | Deep Dive |
| CVE-2026-32461 | WordPress Really Simple SSL plugin <= 9.5.7 - Broken Access Control vulnerability | Really Simple Plugins | Really Simple SSL | 中危 | - | 2026-03-13 11:42:23 | Deep Dive |
| CVE-2026-32457 | WordPress Advanced Product Fields (Product Addons) for WooCommerce plugin <= 1.6.18 - Broken Access Control vulnerability | Wombat Plugins | Advanced Product Fields (Product Addons) for WooCommerce | 中危 | - | 2026-03-13 11:42:23 | Deep Dive |
| CVE-2026-32410 | WordPress WBW Currency Switcher for WooCommerce plugin <= 2.2.5 - Broken Access Control vulnerability | WBW Plugins | WBW Currency Switcher for WooCommerce | 中危 | - | 2026-03-13 11:42:14 | Deep Dive |
| CVE-2026-28106 | WordPress B2BKing Premium plugin < 5.4.20 - Open Redirection vulnerability | Kings Plugins | B2BKing Premium | Medium | 4.7 | 2026-03-06 11:49:35 | Deep Dive |
| CVE-2026-28127 | WordPress Lawyer Directory plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability | e-plugins | Lawyer Directory | 中危 | - | 2026-03-05 05:54:30 | Deep Dive |
| CVE-2026-27396 | WordPress Directory Pro plugin <= 2.5.6 - Broken Access Control vulnerability | e-plugins | Directory Pro | 中危 | - | 2026-03-05 05:54:00 | Deep Dive |
| CVE-2026-27359 | WordPress Awa Plugins plugin <= 1.4.4 - Reflected Cross Site Scripting (XSS) vulnerability | fox-themes | Awa Plugins | 中危 | - | 2026-03-05 05:53:54 | Deep Dive |
| CVE-2026-24955 | WordPress Whizz Plugins plugin <= 1.9 - Reflected Cross Site Scripting (XSS) vulnerability | fox-themes | Whizz Plugins | - | - | 2026-02-20 15:47:09 | Deep Dive |
| CVE-2026-25321 | WordPress SupportCandy plugin <= 3.4.4 - Broken Access Control vulnerability | PSM Plugins | SupportCandy | - | - | 2026-02-19 08:26:56 | Deep Dive |
| CVE-2026-25320 | WordPress Elementor Contact Form DB plugin <= 2.1.3 - Broken Access Control vulnerability | Cool Plugins | Elementor Contact Form DB | - | - | 2026-02-19 08:26:55 | Deep Dive |
| CVE-2026-25000 | WordPress Wheel of Life plugin <= 1.2.0 - Broken Access Control vulnerability | Kraft Plugins | Wheel of Life | - | - | 2026-02-19 08:26:51 | Deep Dive |
| CVE-2026-23804 | WordPress Better Business Reviews plugin <= 0.1.1 - Broken Access Control vulnerability | BBR Plugins | Better Business Reviews | - | - | 2026-02-19 08:26:50 | Deep Dive |
| CVE-2026-24991 | WordPress Extensions For CF7 plugin <= 3.4.0 - Insecure Direct Object References (IDOR) vulnerability | HT Plugins | Extensions For CF7 | - | - | 2026-02-03 14:08:37 | Deep Dive |
| CVE-2026-22470 | WordPress FireStorm Professional Real Estate plugin <= 2.7.11 - SQL Injection vulnerability | FireStorm Plugins | FireStorm Professional Real Estate | - | - | 2026-01-22 16:52:41 | Deep Dive |
| CVE-2025-69293 | WordPress Final User plugin <= 1.2.5 - Privilege Escalation vulnerability | e-plugins | Final User | - | - | 2026-01-22 16:52:31 | Deep Dive |
| CVE-2025-69193 | WordPress WP Membership plugin <= 1.6.4 - Broken Access Control vulnerability | e-plugins | WP Membership | - | - | 2026-01-22 16:52:31 | Deep Dive |
| CVE-2025-69292 | WordPress WP Membership plugin <= 1.6.4 - Privilege Escalation vulnerability | e-plugins | WP Membership | - | - | 2026-01-22 16:52:31 | Deep Dive |