| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-28189 | WordPress Participants Database plugin <= 2.7.8.4 - Arbitrary File Deletion vulnerability | Roland Barker | Participants Database | High | 7.4 | 2026-08-13 13:36:40 | Deep Dive |
| CVE-2026-28188 | WordPress Hydra Booking plugin <= 1.2.2 - Broken Access Control vulnerability | themefic | Hydra Booking | High | 7.3 | 2026-08-13 13:36:40 | Deep Dive |
| CVE-2026-28187 | WordPress Knowledge Base for Documentation, FAQs with AI Assistance plugin <= 17.211.0 - Cross Site Scripting (XSS) vulnerability | echoplugins | Knowledge Base for Documentation, FAQs with AI Assistance | High | 7.1 | 2026-08-13 13:36:39 | Deep Dive |
| CVE-2026-28186 | WordPress Travelfic Toolkit plugin <= 1.5.1 - Broken Access Control vulnerability | themefic | Travelfic Toolkit | High | 8.1 | 2026-08-13 13:36:38 | Deep Dive |
| CVE-2026-28185 | WordPress Log in with Google plugin <= 1.4.2 - Broken Authentication vulnerability | rtCamp | Log in with Google | Critical | 9.8 | 2026-08-13 13:36:38 | Deep Dive |
| CVE-2026-28181 | WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Control vulnerability | AcyMailing Newsletter Team | AcyMailing SMTP Newsletter | Medium | 6.5 | 2026-08-13 13:36:36 | Deep Dive |
| CVE-2026-28182 | WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Cross Site Scripting (XSS) vulnerability | AcyMailing Newsletter Team | AcyMailing SMTP Newsletter | Medium | 6.5 | 2026-08-13 13:36:36 | Deep Dive |
| CVE-2026-28176 | WordPress Booking Activities plugin <= 1.18.4 - PHP Object Injection vulnerability | Booking Activities Team | Booking Activities | High | 8.8 | 2026-08-13 13:36:35 | Deep Dive |
| CVE-2026-28174 | WordPress WP Event SOlution plugin <= 4.1.18 - Sensitive Data Exposure vulnerability | Arraytics | WP Event SOlution | Medium | 6.5 | 2026-08-13 13:36:34 | Deep Dive |
| CVE-2026-28175 | WordPress Visitors Traffic Real Time Statistics plugin <= 8.11 - Cross Site Scripting (XSS) vulnerability | wp-buy | Visitors Traffic Real Time Statistics | High | 7.1 | 2026-08-13 13:36:34 | Deep Dive |
| CVE-2026-28173 | WordPress WP Event SOlution plugin <= 4.1.19 - Arbitrary Content Deletion vulnerability | Arraytics | WP Event SOlution | High | 7.1 | 2026-08-13 13:36:33 | Deep Dive |
| CVE-2026-28170 | WordPress Blog Floating Button plugin <= 1.4.20 - Cross Site Scripting (XSS) vulnerability | 1meril | Blog Floating Button | High | 7.1 | 2026-08-13 13:36:33 | Deep Dive |
| CVE-2026-28168 | WordPress CubeWP plugin <= 1.1.30 - SQL Injection vulnerability | Imran Tauqeer | CubeWP | High | 8.5 | 2026-08-13 13:36:32 | Deep Dive |
| CVE-2026-28161 | WordPress Service Finder Booking plugin <= 6.2 - Privilege Escalation vulnerability | Aonetheme | Service Finder Booking | High | 8.8 | 2026-08-13 13:36:31 | Deep Dive |
| CVE-2026-28159 | WordPress Service Finder Booking plugin <= 6.2 - Broken Access Control vulnerability | Aonetheme | Service Finder Booking | Medium | 6.5 | 2026-08-13 13:36:31 | Deep Dive |
| CVE-2026-28158 | WordPress Do Lasso plugin <= 358 - Cross Site Scripting (XSS) vulnerability | Lasso Analytics, Inc. | Do Lasso | High | 7.1 | 2026-08-13 13:36:30 | Deep Dive |
| CVE-2026-28156 | WordPress Do Lasso plugin <= 358 - SQL Injection vulnerability | Lasso Analytics, Inc. | Do Lasso | High | 8.5 | 2026-08-13 13:36:29 | Deep Dive |
| CVE-2026-28157 | WordPress Do Lasso plugin <= 358 - Path Traversal vulnerability | Lasso Analytics, Inc. | Do Lasso | High | 7.5 | 2026-08-13 13:36:29 | Deep Dive |
| CVE-2026-28155 | WordPress Do Lasso plugin <= 358 - Insecure Direct Object References (IDOR) vulnerability | Lasso Analytics, Inc. | Do Lasso | Medium | 6.5 | 2026-08-13 13:36:28 | Deep Dive |
| CVE-2026-28149 | WordPress Headless Single Sign On plugin <= 1.6 - PHP Object Injection vulnerability | miniOrange | Headless Single Sign On | Critical | 9.8 | 2026-08-13 13:36:27 | Deep Dive |