| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-77695 | Woo Refund And Exchange Lite < 4.6.4 - Unauthenticated Guest Order Message Disclosure and Manipulation | Unknown | Return Refund and Exchange For WooCommerce | - | - | 2026-08-26 06:00:22 | Deep Dive |
| CVE-2026-77757 | Directorist 8.5 - 8.9.2 - Subscriber+ Arbitrary Image Move via REST v2 Listing Submission | Unknown | Directorist: AI-Powered Business Directory, Listings & Classified Ads | - | - | 2026-08-26 06:00:22 | Deep Dive |
| CVE-2026-77758 | Stripe Payment Forms by WP Full Pay < 8.5.1 - Unauthenticated Customer Portal Subscription and Billing Data Disclosure via Unconfirmed Session | Unknown | Stripe Payment Forms by WP Full Pay | - | - | 2026-08-26 06:00:22 | Deep Dive |
| CVE-2026-77789 | Stripe Payment Forms by WP Full Pay < 8.5.1 - Cross-Customer Subscription Modification via IDOR | Unknown | Stripe Payment Forms by WP Full Pay | - | - | 2026-08-26 06:00:22 | Deep Dive |
| CVE-2026-77754 | Kirki < 6.0.14 - Unauthenticated User and Comment Author Email Disclosure via kirki_get_apis | Unknown | Kirki | - | - | 2026-08-26 06:00:22 | Deep Dive |
| CVE-2026-77790 | RegistrationMagic < 6.0.9.4 - Admin+ SQLi via 'rm_sortby' Parameter | Unknown | RegistrationMagic | - | - | 2026-08-26 06:00:22 | Deep Dive |
| CVE-2026-75798 | AI Engine 3.4.0 - 3.7.1 - Unauthenticated Arbitrary AI Query Execution via Editor Assistant | Unknown | AI Engine | - | - | 2026-08-26 06:00:21 | Deep Dive |
| CVE-2026-75797 | AI Engine 3.3.3 - 3.7.1 - Subscriber+ Arbitrary File Read via 'url' Parameter | Unknown | AI Engine | - | - | 2026-08-26 06:00:21 | Deep Dive |
| CVE-2026-77694 | Eventin < 4.1.19 - Unauthenticated Order Completion Without Payment via order_token | Unknown | Eventin | - | - | 2026-08-26 06:00:21 | Deep Dive |
| CVE-2026-77693 | Order Tip for WooCommerce < 1.6.0 - Shop Manager+ Arbitrary File Deletion via delete_exported_csv_file_ajax | Unknown | Order Tip for WooCommerce | - | - | 2026-08-26 06:00:21 | Deep Dive |
| CVE-2026-74930 | WP Project Manager 2.2.0 - 4.0.6 - Subscriber+ User Activity Feed Disclosure via IDOR | Unknown | Project Manager | - | - | 2026-08-26 06:00:21 | Deep Dive |
| CVE-2026-74929 | WP Project Manager < 4.0.7 - Subscriber+ Cross-Project Task Disclosure and Task Board Modification via IDOR | Unknown | Project Manager | - | - | 2026-08-26 06:00:21 | Deep Dive |
| CVE-2026-74851 | Pods < 3.3.9.1 - Author+ RCE via Shortcode Display Callback | Unknown | Pods | - | - | 2026-08-26 06:00:20 | Deep Dive |
| CVE-2026-74928 | WP Project Manager 2.1.0 - 4.0.6 - Unauthenticated Subscriber Account Creation via Trello Import Routes | Unknown | Project Manager | - | - | 2026-08-26 06:00:20 | Deep Dive |
| CVE-2026-19718 | BlogVault, MalCare and WP Remote 5.16 - 6.62 - Unauthenticated Site Takeover via Connection Key Recovery | Unknown | BlogVault Backup & Staging | - | - | 2026-08-26 06:00:20 | Deep Dive |
| CVE-2026-19220 | Forminator Forms < 1.57.1 - Unauthenticated Multisite Site Creation and Privilege Escalation | Unknown | Forminator Forms | - | - | 2026-08-26 06:00:20 | Deep Dive |
| CVE-2026-19226 | Royal Elementor Addons < 1.7.1066 - Contributor+ Stored XSS via Image Accordion Widget Effect Settings | Unknown | Royal Addons for Elementor | - | - | 2026-08-26 06:00:20 | Deep Dive |
| CVE-2026-16986 | Booking Package < 1.7.25 - Unauthenticated Price Manipulation via Service and Option Cost Parameters | Unknown | Booking Package | - | - | 2026-08-26 06:00:19 | Deep Dive |
| CVE-2026-16984 | WP Legal Pages < 3.7.1 - Unauthenticated API Secret Disclosure | Unknown | Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates | - | - | 2026-08-26 06:00:19 | Deep Dive |
| CVE-2026-19094 | Tutor LMS < 4.0.6 - Unauthenticated SQLi via 'offset' and 'item_per_page' Parameters | Unknown | Tutor LMS | - | - | 2026-08-26 06:00:19 | Deep Dive |