| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Oct 08, 2026, 00:10:13 | ||||
|
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.
vulnerable
|
Oct 08, 2026, 04:10:55 |
Min -
Max 6.3.11
|
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 's' Search Parameter via comments-atom Feed in all versions up to, and including, 6.3.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that the front-end server serves the retained... | |
|
VikRentCar Car Rental Management System
vulnerable
|
Oct 08, 2026, 04:10:47 |
Min -
Max 1.4.6
|
Unauthenticated Cross Site Scripting (XSS) in VikRentCar <= 1.4.6 versions. | |
|
vulnerable
|
Oct 08, 2026, 04:10:18 |
Min -
Max 2.7.1
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gateway: from n/a through 2.7.1. | |
|
vulnerable
|
Oct 08, 2026, 03:10:15 |
Min -
Max 6.2.3
|
Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions. | |
|
vulnerable
|
Oct 08, 2026, 02:10:52 |
Min -
Max 1.0.1
|
The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers to forge payment confirmations and change the status of arbitrary orders on any installation where that secret has been left at its default empty value. | |
|
WordPress + Microsoft Office 365 / Azure AD | LOGIN
vulnerable
|
Oct 07, 2026, 22:10:15 |
Min -
Max 44.1
|
Subscriber Broken Access Control in WPO365 <= 44.1 versions. | |
|
WC Nova Poshta Shipping – Integration of Nova Poshta delivery service for WooCommerce
vulnerable
|
Oct 07, 2026, 21:10:51 |
Min -
Max 1.23.3
|
Missing Authorization vulnerability in Kirillbdev WC Ukraine Shipping wc-ukr-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WC Ukraine Shipping: from n/a through 1.23.2. | |
|
WP User Manager – User Profile Builder & Membership
vulnerable
|
Oct 07, 2026, 21:10:46 |
Min -
Max 2.9.21
|
Improper Access Control vulnerability in WP User Manager WP User Manager wp-user-manager allows Privilege Abuse.This issue affects WP User Manager: from n/a through 2.9.20. | |
|
vulnerable
|
Oct 07, 2026, 21:10:33 |
Min -
Max 9.3.03.002
|
Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions. | |
|
B Blocks – The ultimate block collection
vulnerable
|
Oct 07, 2026, 20:10:52 |
Min -
Max 2.1.9
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a through 2.1.8. | |