NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-16955 The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external... 2026-08-08 5.0 NETWORK MEDIUM NVD
CVE-2026-16953 The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action sol... 2026-08-08 4.8 NETWORK MEDIUM NVD
CVE-2026-16948 The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects t... 2026-08-08 8.1 NETWORK HIGH NVD
CVE-2026-16608 The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the ... 2026-08-08 5.3 NETWORK MEDIUM NVD
CVE-2026-16595 The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing a... 2026-08-08 6.5 NETWORK MEDIUM NVD
CVE-2026-16594 The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing a... 2026-08-08 7.5 NETWORK HIGH NVD
CVE-2026-16590 The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing a... 2026-08-08 6.5 NETWORK MEDIUM NVD
CVE-2026-16589 The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its auth... 2026-08-08 7.7 NETWORK HIGH NVD
CVE-2026-16578 The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability chec... 2026-08-08 7.5 NETWORK HIGH NVD
CVE-2026-16574 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs... 2026-08-08 5.4 NETWORK MEDIUM NVD
CVE-2026-16562 The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on... 2026-08-08 6.5 NETWORK MEDIUM NVD
CVE-2026-16559 The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by... 2026-08-08 6.8 NETWORK MEDIUM NVD
CVE-2026-16558 The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and doe... 2026-08-08 5.4 NETWORK MEDIUM NVD
CVE-2026-16535 The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthentica... 2026-08-08 6.1 NETWORK MEDIUM NVD
CVE-2026-16282 The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured serv... 2026-08-08 5.3 NETWORK MEDIUM NVD