A vulnerability was found in ays-pro Quiz Maker Plugin up to 6.7.1.29 on WordPress and classified as problematic. Affected is an unknown function. Such manipulation of the argument rate_reason leads to cross site scripting.
This vulnerability is traded as CVE-2026-6817. The attack may be launched remotely. There is no exploit available.
A vulnerability has been found in wordpresschef Salon Booking System Plugin up to 10.30.25 on WordPress and classified as critical. This impacts an unknown function of the component Confirmation Email Handler. This manipulation causes path traversal.
This vulnerability appears as CVE-2026-6320. The attack may be initiated remotely. There is no available exploit.
A vulnerability, which was classified as problematic, was found in leap13 Premium Addons for Elementor Plugin up to 4.11.70 on WordPress. This affects the function versions. The manipulation of the argument custom_svg results in cross site scripting.
This vulnerability is reported as CVE-2026-4790. The attack can be launched remotely. No exploit exists.
A vulnerability, which was classified as problematic, has been found in Wireshark up to 4.6.4. The impacted element is an unknown function of the component IEEE 802.11 Protocol Dissector. The manipulation leads to null pointer dereference.
This vulnerability is documented as CVE-2026-6525. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability classified as problematic was found in strangerstudios Paid Memberships Pro Plugin up to 3.6.5 on WordPress. The affected element is the function wp_ajax_pmpro_stripe_create_webhook/wp_ajax_pmpro_stripe_delete_webhook/wp_ajax_pmpro_stripe_rebuild_webhook of the component AJAX Handler. Executing a manipulation can lead to missing authorization.
This vulnerability is registered as CVE-2026-4100. It is possible to launch the attack remotely. No exploit is available.
A patch should be applied to remediate this issue.
A vulnerability classified as problematic has been found in xlplugins NextMove Lite Plugin up to 2.23.0 on WordPress. Impacted is the function xlwcty_current_date. Performing a manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-0703. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability described as critical has been identified in cyberhobo Geo Mashup Plugin up to 1.13.18 on WordPress. This issue affects the function esc_sql of the component Geo Search Feature. Such manipulation of the argument map_post_type leads to sql injection.
This vulnerability is listed as CVE-2026-4061. The attack may be performed from remote. There is no available exploit.
A vulnerability marked as problematic has been reported in dokaninc Dokan: AI Powered WooCommerce Multivendor Marketplace Solution Plugin up to 4.3.1 on WordPress. This vulnerability affects the function prepare_reviews_for_response of the file /dokan/v1/stores/{id}/reviews of the component REST API Endpoint. This manipulation causes information disclosure.
This vulnerability is tracked as CVE-2026-3504. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability labeled as critical has been found in wclovers WCFM Plugin up to 6.7.25 on WordPress. This affects the function wcfm_delete_wcfm_customer. The manipulation results in authorization bypass.
This vulnerability is identified as CVE-2026-2554. The attack can be executed remotely. There is not any exploit available.
A vulnerability identified as critical has been detected in cyberhobo Geo Mashup Plugin up to 1.13.18 on WordPress. Affected by this issue is the function esc_sql. The manipulation leads to sql injection.
This vulnerability is referenced as CVE-2026-4062. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability categorized as critical has been discovered in cyberhobo Geo Mashup Plugin up to 1.13.18 on WordPress. Affected by this vulnerability is the function esc_sql of the file render-map.php. Executing a manipulation can lead to sql injection.
The identification of this vulnerability is CVE-2026-4060. The attack may be launched remotely. There is no exploit available.
Trellix disclosed a security breach affecting part of its source code repository, however, the company says there’s no sign of code misuse. Trellix revealed a breach that allowed unauthorized access to part of its source code repository. The company said it quickly launched an investigation with forensic experts and notified law enforcement. While the exact […]
A vulnerability classified as critical was found in PHPCityPortal. Affected by this vulnerability is an unknown functionality of the file video_show.php of the component Spotlight. The manipulation of the argument ID results in sql injection.
This vulnerability is identified as CVE-2010-0974. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability, which was classified as critical, has been found in PHPCityPortal. Affected by this issue is some unknown functionality of the file external.php. This manipulation of the argument url causes code injection.
This vulnerability is tracked as CVE-2010-0975. The attack is possible to be carried out remotely. Moreover, an exploit is present.
A vulnerability has been found in Yuri D'elia dl up to 0.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file index.php. This manipulation of the argument t causes cross site scripting.
This vulnerability is registered as CVE-2010-0963. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The affected component should be upgraded.
A vulnerability was found in Jevci.net Jevci Siparis Formu Scripti. It has been classified as problematic. This affects an unknown part. Performing a manipulation results in improper access controls.
This vulnerability is reported as CVE-2010-0965. The attack is possible to be carried out remotely. No exploit exists.