| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-66455 | WordPress ReactPress plugin <= 3.4.0 - Broken Access Control vulnerability | rockiger | ReactPress | Medium | 6.0 | 2026-08-13 13:36:59 | Deep Dive |
| CVE-2026-66454 | WordPress WP Social Avatar plugin <= 1.5 - Broken Access Control vulnerability | Maruti Mohanty | WP Social Avatar | Medium | 6.5 | 2026-08-13 13:36:58 | Deep Dive |
| CVE-2026-66453 | WordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vulnerability | Dimitri Grassi | Salon booking system | Critical | 9.8 | 2026-08-13 13:36:58 | Deep Dive |
| CVE-2026-66450 | WordPress Geo Mashup plugin <= 1.13.18 - Local File Inclusion vulnerability | Dylan Kuhn | Geo Mashup | High | 8.1 | 2026-08-13 13:36:57 | Deep Dive |
| CVE-2026-66449 | WordPress Geo Mashup plugin <= 1.13.18 - Cross Site Scripting (XSS) vulnerability | Dylan Kuhn | Geo Mashup | High | 7.1 | 2026-08-13 13:36:56 | Deep Dive |
| CVE-2026-66446 | WordPress If-So Dynamic Content Personalization plugin <= 1.10 - SQL Injection vulnerability | If-So Dynamic Content | If-So Dynamic Content Personalization | Critical | 9.3 | 2026-08-13 13:36:56 | Deep Dive |
| CVE-2026-66444 | WordPress Payment Forms for Paystack plugin <= 4.0.5 - Sensitive Data Exposure vulnerability | kendysond | Payment Forms for Paystack | Medium | 6.5 | 2026-08-13 13:36:55 | Deep Dive |
| CVE-2026-66441 | WordPress MultiVendorX plugin <= 5.0.10 - Broken Access Control vulnerability | MultiVendorX | MultiVendorX | High | 7.5 | 2026-08-13 13:36:54 | Deep Dive |
| CVE-2026-66443 | WordPress REST API Log plugin <= 1.7.1 - Sensitive Data Exposure vulnerability | Pete Nelson | REST API Log | High | 7.5 | 2026-08-13 13:36:54 | Deep Dive |
| CVE-2026-66436 | WordPress Active Products Tables for WooCommerce plugin <= 1.1.1 - SQL Injection vulnerability | RealMag777 | Active Products Tables for WooCommerce | Critical | 9.3 | 2026-08-13 13:36:53 | Deep Dive |
| CVE-2026-66431 | WordPress Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugin <= 1.0.7 - Broken Access Control vulnerability | WoompaLoompa | Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) | High | 7.5 | 2026-08-13 13:36:52 | Deep Dive |
| CVE-2026-66432 | WordPress WPJAM Basic plugin <= 7.0.2.1 - Sensitive Data Exposure vulnerability | denishua | WPJAM Basic | High | 7.5 | 2026-08-13 13:36:52 | Deep Dive |
| CVE-2026-66430 | WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.10 - SQL Injection vulnerability | CODEPRESS | Visitor Traffic Real Time Statistics Pro | High | 8.5 | 2026-08-13 13:36:51 | Deep Dive |
| CVE-2026-66426 | WordPress WP-Stats plugin <= 2.56 - Cross Site Scripting (XSS) vulnerability | Lester Chan | WP-Stats | High | 7.1 | 2026-08-13 13:36:50 | Deep Dive |
| CVE-2026-66429 | WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.10 - Cross Site Scripting (XSS) vulnerability | CODEPRESS | Visitor Traffic Real Time Statistics Pro | High | 7.1 | 2026-08-13 13:36:50 | Deep Dive |
| CVE-2026-66424 | WordPress SMS Alert Order Notifications plugin <= 3.9.7 - Privilege Escalation vulnerability | Cozy Vision Technologies Pvt. Ltd. | SMS Alert Order Notifications | Critical | 9.8 | 2026-08-13 13:36:49 | Deep Dive |
| CVE-2026-65582 | WordPress AI Hub theme <= 1.3.10 - Arbitrary File Download vulnerability | LiquidThemes | AI Hub | High | 7.7 | 2026-08-13 13:36:49 | Deep Dive |
| CVE-2026-65580 | WordPress Agrion theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability | bracketweb | Agrion | High | 7.1 | 2026-08-13 13:36:48 | Deep Dive |
| CVE-2026-61984 | WordPress WPMobile.App plugin <= 11.77 - Broken Access Control vulnerability | Amauri | WPMobile.App | High | 7.5 | 2026-08-13 13:36:47 | Deep Dive |
| CVE-2026-61980 | WordPress OMGF Pro plugin <= 5.2.7 - Arbitrary File Download vulnerability | Daan.dev | OMGF Pro | High | 7.5 | 2026-08-13 13:36:47 | Deep Dive |