Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE vulnerability search

CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-93927 WordPress Veto theme <= 1.6.0 - PHP Object Injection vulnerability Axiomthemes Veto Critical 9.8 2026-10-10 07:00:35 Deep Dive
CVE-2026-93930 WordPress Tantra theme <= 2.9.0 - PHP Object Injection vulnerability ThemeREX Group Tantra Critical 9.8 2026-10-10 07:00:35 Deep Dive
CVE-2026-93929 WordPress Travesia theme <= 1.1.16 - PHP Object Injection vulnerability ThemeREX Group Travesia Critical 9.8 2026-10-10 07:00:35 Deep Dive
CVE-2026-93931 WordPress Smash theme <= 1.12.0 - PHP Object Injection vulnerability ThemeREX Group Smash Critical 9.8 2026-10-10 07:00:35 Deep Dive
CVE-2026-106606 WordPress YITH WooCommerce Affiliates plugin <= 3.31.0 - PHP Object Injection vulnerability YITH YITH WooCommerce Affiliates High 7.2 2026-10-10 07:00:34 Deep Dive
CVE-2026-93949 WordPress Grocery Shopping Store theme <= 1.3.3 - Broken Authentication vulnerability Omegathemes Grocery Shopping Store High 7.1 2026-10-10 07:00:34 Deep Dive
CVE-2026-93950 WordPress Motors theme <= 1.4.108 - Broken Access Control vulnerability StylemixThemes Motors High 7.5 2026-10-10 07:00:34 Deep Dive
CVE-2026-108503 Unauthorized information acquisition vulnerability in ZTE Z80 Ultra product ZTE Z80 Ultra Low 3.3 2026-10-10 06:52:59 Deep Dive
CVE-2026-103427 Simple Membership <= 4.8.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Country Field wpinsider-1 Simple Membership Medium 6.4 2026-10-10 06:40:17 Deep Dive
CVE-2026-104006 SpeedyCache <= 1.4.2 - Unauthenticated Sensitive Information Exposure via Insecure Cache Configuration via Cache Write Gate Missing comment_author_* Cookie Check softaculous SpeedyCache – Cache, Optimization, Performance Low 3.7 2026-10-10 06:40:16 Deep Dive
CVE-2026-96572 WP Meteor Website Speed Optimization Addon <= 3.4.18 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name aguidrevitch WP Meteor Website Speed Optimization Addon High 7.2 2026-10-10 06:40:16 Deep Dive
CVE-2026-100196 LazyLoad Plugin <= 2.4.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content wp_media LazyLoad Plugin – Lazy Load Images, Videos, and Iframes High 7.2 2026-10-10 06:40:15 Deep Dive
CVE-2026-3717 CV Builder – Professional Resume Builder SaaS <= 1.3.1 - Missing Authorization to Unauthenticated PNG File Upload bestwpdeveloper WP CV Builder Medium 5.3 2026-10-10 06:40:15 Deep Dive
CVE-2026-107742 10Web Booster <= 2.34.8 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name 10web 10Web Booster – Website speed optimization, Cache & Page Speed optimizer High 7.2 2026-10-10 06:40:15 Deep Dive
CVE-2026-102402 Team <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ttp_filter_taxonomy' Post Meta via [tlpteam] Shortcode techlabpro1 Team – Team Members Showcase Plugin Medium 6.4 2026-10-10 06:40:14 Deep Dive
CVE-2026-6243 Frontend Admin by DynamiApps <= 3.28.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content shabti Frontend Admin by DynamiApps Medium 6.4 2026-10-10 06:40:14 Deep Dive
CVE-2026-100161 Photo Reviews for WooCommerce <= 1.2.30 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'wcpr_image_upload_id' Parameter villatheme Photo Reviews for WooCommerce High 7.2 2026-10-10 06:40:13 Deep Dive
CVE-2026-5725 Favicon Rotator <= 1.2.11 - Reflected Cross-Site Scripting via 'fvrt_' prefix archetyped Favicon Rotator Medium 6.1 2026-10-10 06:40:13 Deep Dive
CVE-2026-107712 WP Booking System <= 2.1.0.1 - Authenticated (Subscriber+) SQL Injection via 'current_month' Parameter murgroland WP Booking System – Booking Calendar Medium 6.5 2026-10-10 06:40:13 Deep Dive
CVE-2026-94538 WP File Download <= 6.3.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion/Modification via 'task' Parameter to Multiple Functions JoomUnited WP File Download High 8.1 2026-10-10 06:40:12 Deep Dive