| CVE-2026-12843 | The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not prope | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-10196 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injectio | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-0799 | In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not | — | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- High
AAvailability- High
| — |
| CVE-2025-9049 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability che | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2025-15694 | The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admi | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- Required
SScope- Unchanged
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2025-15693 | The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-brows | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- Low
IIntegrity- None
AAvailability- None
| — |
| CVE-2025-15647 | CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are comp | — | 2026-09-05 | CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Local
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- Passive
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- None
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2025-15614 | ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attacker | — | 2026-09-05 | CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Local
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- Passive
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- None
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2025-14945 | The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event attr | — | 2026-09-05 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- High
PRPrivileges Required- None
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2024-11080 | The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |