NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-15239 The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge t... 2026-08-07 5.3 NETWORK MEDIUM NVD
CVE-2026-15211 The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being... 2026-08-07 5.9 NETWORK MEDIUM NVD
CVE-2026-15148 The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured mercha... 2026-08-07 5.3 NETWORK MEDIUM NVD
CVE-2026-12261 A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts pac... 2026-08-07 N/A None None NVD
CVE-2026-16265 The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not restrict the operation it dispa... 2026-08-07 6.5 NETWORK MEDIUM NVD
CVE-2026-16263 The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-contro... 2026-08-07 8.8 NETWORK HIGH NVD
CVE-2026-16262 The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an una... 2026-08-07 7.5 NETWORK HIGH NVD
CVE-2026-16258 The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to pe... 2026-08-07 9.8 NETWORK CRITICAL NVD
CVE-2026-16041 The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, ... 2026-08-07 7.5 NETWORK HIGH NVD
CVE-2026-16039 The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated use... 2026-08-07 6.5 NETWORK MEDIUM NVD
CVE-2026-16038 The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its ... 2026-08-07 9.1 NETWORK CRITICAL NVD
CVE-2026-16030 The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based... 2026-08-07 8.1 NETWORK HIGH NVD
CVE-2026-15386 The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds f... 2026-08-07 5.4 NETWORK MEDIUM NVD
CVE-2026-15361 The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-... 2026-08-07 8.1 NETWORK HIGH NVD
CVE-2026-15359 The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers ... 2026-08-07 6.5 NETWORK MEDIUM NVD