NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-14831 The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking duration on the server side when ad... 2026-08-06 5.3 NETWORK MEDIUM NVD
CVE-2026-14812 The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, a... 2026-08-06 10.0 NETWORK CRITICAL NVD
CVE-2026-14306 The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content, allowing authent... 2026-08-06 4.3 NETWORK MEDIUM NVD
CVE-2026-14225 The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-rendering actions, checking only... 2026-08-06 2.7 NETWORK LOW NVD
CVE-2026-13399 The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unaut... 2026-08-06 7.5 NETWORK HIGH NVD
CVE-2026-13342 The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-based login restriction feature, a... 2026-08-06 5.3 NETWORK MEDIUM NVD
CVE-2026-12901 The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attac... 2026-08-06 5.9 NETWORK MEDIUM NVD
CVE-2026-12584 The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifica... 2026-08-06 7.5 NETWORK HIGH NVD
CVE-2026-12501 The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merc... 2026-08-06 5.3 NETWORK MEDIUM NVD
CVE-2026-11976 The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) a... 2026-08-06 10.0 NETWORK CRITICAL NVD
CVE-2026-11803 A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this... 2026-08-06 7.8 LOCAL HIGH NVD
CVE-2026-11361 The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete,... 2026-08-06 5.9 NETWORK MEDIUM NVD
CVE-2026-10599 The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being... 2026-08-06 7.5 NETWORK HIGH NVD
CVE-2026-10524 The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are added to the ca... 2026-08-06 7.5 NETWORK HIGH NVD
CVE-2025-6508 The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to be loaded, overriding the exist... 2026-08-06 4.3 NETWORK MEDIUM NVD