CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jul 9, 2026

Inrove Software BiEticaret Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in Inrove Software and Internet Services BiEticaret, affecting versions prior to 3.3.57. This vulnerability arises from improper neutralization of input during web page generation, allowing attackers to inject malicious scripts that are executed in the context of the user's browser.

2.9
Jul 9, 2026

HCL DevOps Deploy and HCL Launch Sensitive Data Exposure Vulnerability

A vulnerability exists in HCL DevOps Deploy and HCL Launch that could allow authenticated users to access sensitive configurations and secrets through API responses. This exposed information could potentially be exploited in further attacks against the system.

3.5
Jul 9, 2026

HCL DevOps Deploy and HCL Launch Sensitive Information Disclosure Vulnerability

A vulnerability exists in HCL DevOps Deploy and HCL Launch that allows for the unauthorized disclosure of sensitive information. The application logs potentially sensitive data in files that can be accessed by local users.

3.1
Jul 9, 2026

HCL DevOps Deploy Cross-Origin Resource Sharing Vulnerability Allowing Privileged Actions and Information Retrieval

A vulnerability exists in HCL DevOps Deploy due to improper Cross-Origin Resource Sharing (CORS) configuration. The application does not restrict domain names to trusted sources, potentially allowing attackers to perform privileged actions and access sensitive information.

3.9
Jul 9, 2026

OceanicSoft ValeApp Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in OceanicSoft ValeApp, affecting versions through 09072026. This issue arises from improper neutralization of input during web page generation, allowing attackers to inject malicious scripts that are executed in the context of the user.

2.5
Jul 9, 2026

PAVO Financial Technology Solutions PAVO Pay Authorization Bypass Vulnerability

An authorization bypass vulnerability has been identified in PAVO Pay, a product of PAVO Financial Technology Solutions Inc. This vulnerability allows exploitation of trusted identifiers and affects PAVO Pay versions through 09072026.

3.4
Jul 9, 2026

Sayax Energy Technologies OSOS Authentication Bypass Vulnerability

A vulnerability allowing authentication bypass has been identified in Sayax Energy Technologies Inc. OSOS, affecting versions through 09072026. This issue arises from the insertion of sensitive information into transmitted data.

3.5
Jul 9, 2026

Blocksy Companion WordPress Plugin Arbitrary File Upload Vulnerability

A vulnerability allowing arbitrary file upload has been identified in the Blocksy Companion plugin for WordPress, affecting all versions through 2.1.46. The issue arises in the save_attachments function, where the Custom Fonts extension improperly validates file types. It allows double-extension filenames, such as shell.woff2.php, to bypass MIME checks and be uploaded as executable files. This vulnerability is exploitable by unauthenticated users when the premium version of the plugin is active, along with the WooCommerce Extra (Advanced Reviews) and Custom Fonts extensions.

5.2
Jul 9, 2026

Hydra Booking WordPress Plugin Insecure Direct Object Reference Vulnerability

A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress, affecting versions through 1.2.1. The vulnerability exists in the '/wp-json/hydra-booking/v1/booking/details/{id}' REST endpoint. The issue arises because the 'getBookingDetails()' callback only checks for the 'tfhb_manage_options' capability, without verifying if the requested booking belongs to the authenticated host. This flaw enables authenticated attackers with Hydra Host-level access to access sensitive booking information from other hosts, including attendee details and payment information, by manipulating booking IDs.

3.6
Jul 9, 2026

Backup and Staging by WP Time Capsule Sensitive Information Exposure Vulnerability

A vulnerability allowing sensitive information exposure has been identified in the Backup and Staging by WP Time Capsule plugin for WordPress, affecting all versions through 1.22.26. The issue arises in the download_recent_decrypted_file_wptc function, where authenticated attackers with subscriber-level access or higher can download the most recently decrypted SQL database backup. This backup, stored in the 'recent_decrypted_file' option, typically contains password hashes, user credentials, and other sensitive site configuration data. Exploitation of this vulnerability requires that an administrator has previously decrypted a backup, leaving the file available in the plugin's upload directory.

4.5
Jul 9, 2026

Popup Maker WordPress Plugin Authorization Bypass Vulnerability Allowing Arbitrary Plugin Installation

A vulnerability exists in the Popup Maker WordPress plugin, specifically in the 'Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder' version 1.22.0 and prior. The issue stems from an authorization bypass, where the plugin fails to properly verify user permissions. This flaw enables authenticated attackers with editor-level access or higher to exploit the legacy 'v1/connect/info' endpoint, provided they have a valid Popup Maker Pro license. The exploitation involves installing and activating any plugin from a URL controlled by the attacker, potentially leading to remote code execution.

6.1
Jul 9, 2026

WordPress Age Verification & Identity Verification Plugin Unauthorized Access Vulnerability

A vulnerability allowing unauthorized access has been identified in the Age Verification & Identity Verification by Token of Trust plugin for WordPress, affecting all versions up to and including 4.0.2. The issue arises because the handle_export_table() function is hooked to the WordPress 'init' action, which is triggered for all requests, including those from unauthenticated users, without any capability checks. This flaw enables unauthenticated attackers to download a CSV file containing sensitive WooCommerce donation data, such as order dates, order IDs, donation amounts, and admin-only order edit URLs. The data can be accessed by visiting any page on the site with the 'tot_export_table' GET parameter set to a numeric value between 0 and 3.

4.4
Jul 9, 2026

Bookero.pl WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Bookero.pl online reservation system plugin for WordPress, affecting versions through 2.2. The issue arises in the 'bookero_products' shortcode, specifically through the 'hide_products' and 'filter_products' attributes. The vulnerability is caused by inadequate input sanitization and output escaping in the 'bookero_products()' function, where the raw attribute values are directly inserted into an inline script block without proper escaping. This flaw allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the affected page.

3.5
Jul 9, 2026

Pinniped Supervisor Privilege Escalation Vulnerability via Active Directory LDAP Injection

A privilege escalation vulnerability has been identified in Pinniped Supervisor versions 0.11.0 through 0.46.0, inclusive. This issue arises when the Pinniped Supervisor is configured with an Active Directory Identity Provider and the group name attribute is left empty. Under these conditions, an attacker with knowledge of an Active Directory user's password and the ability to edit group distinguished names could manipulate group entries to gain elevated permissions in Kubernetes clusters.

3.0
Jul 9, 2026

Apache Helix REST CORS Vulnerability in Versions Through 2.0.0 Allows Unrestricted Cross-Origin Requests

A Cross-Origin Resource Sharing (CORS) vulnerability has been identified in the Apache Helix REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in all platforms through version 2.0.0. This vulnerability allows remote attackers, controlling a web page visited by an authorized user, to read responses from and send cross-origin requests to administrative REST endpoints. The issue arises because the CORS filter indiscriminately allows requests from any origin, permits credentials, and reflects arbitrary method and header values in preflight responses.

2.3
Jul 9, 2026

Block, Suspend, Report for BuddyPress Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Block, Suspend, Report for BuddyPress plugin for WordPress, affecting versions through 3.6.4. The issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with subscriber-level access and above to inject arbitrary scripts into pages. These scripts are executed when a user accesses the compromised page.

3.5
Jul 9, 2026

Nozomi Networks Guardian and CMC Incorrect Privilege Assignment Vulnerability in Arc Sensors

A vulnerability allowing incorrect privilege assignment has been identified in Nozomi Networks Guardian and CMC versions prior to 26.2.0. This vulnerability arises from Arc sensors receiving command-line interface (CLI) permissions, which should not be granted. As a result, an authenticated user with limited privileges can exploit this issue by sending administrative CLI commands through the synchronization functionality. This exploitation can lead to unauthorized changes in device configuration and potentially disrupt the device's availability.

3.6
Jul 9, 2026

Nozomi Networks Remote Collector TLS Certificate Validation Vulnerability

A vulnerability exists in Nozomi Networks Remote Collector versions prior to 26.2.0, where the n2os-tui interface disables TLS certificate verification when connecting to an upstream Guardian or CMC. This lack of validation, combined with the absence of an option to re-enable it, exposes users to potential man-in-the-middle attacks. Such attacks could intercept communications, steal sync tokens, impersonate servers, inject false asset information or vulnerabilities into the Guardian or CMC, and disrupt data flow between the Remote Collector and these services.

2.9
Jul 9, 2026

Nozomi Networks Guardian and CMC Denial-of-Service Vulnerability via Oversized Audit Log Entries

A denial-of-service vulnerability has been identified in Nozomi Networks Guardian and CMC versions prior to 26.2.0. This vulnerability arises from unbounded resource allocation in the audit logging feature, where excessively large input can be submitted and recorded without any size limit. An unauthenticated attacker could exploit this by sending requests with large inputs, potentially filling up available disk space and causing the system to become inoperable.

4.3
Jul 9, 2026

Nozomi Networks Guardian and CMC Missing Authentication Vulnerability in SSH Keys Synchronization Endpoint

A missing authentication vulnerability exists in the SSH keys synchronization endpoint of Nozomi Networks Guardian and CMC versions prior to 26.2.0. This vulnerability allows an unauthenticated attacker to send a request to the SSH keys synchronization endpoint and retrieve a list of users who have uploaded their public SSH keys, along with their associated groups and the uploaded keys.

4.3
Jul 9, 2026

Nozomi Networks Guardian and CMC Open Redirect Vulnerability in SAML Single Sign-On

A vulnerability allowing open redirection has been identified in the SAML Single Sign-On feature of Nozomi Networks Guardian and CMC applications, prior to version 26.2.0. This vulnerability arises from inadequate validation of user-controlled redirection parameters. An unauthenticated attacker could exploit this by sending a crafted request to the SAML sign-in endpoint, which would then corrupt the cached SAML redirection for other users. As a result, this could facilitate phishing and credential theft, while also disrupting SAML authentication for all impacted users.

3.9
Jul 9, 2026

Nozomi Networks Guardian and CMC Stored HTML Injection Vulnerability in Diagram Tab and Graph View

A stored HTML injection vulnerability has been identified in Nozomi Networks Guardian and CMC versions prior to 26.2.0. This vulnerability arises in the Diagram tab and Graph view, where a shared input validation function fails to adequately restrict user input. An authenticated user with administrative privileges can exploit this by injecting malicious HTML tags into N2OS configuration data through various input vectors. When the affected data is viewed in the Diagram tab and Graph view, the injected HTML is rendered in the browser, potentially leading to phishing attacks and open redirects. However, full exploitation of cross-site scripting and direct information disclosure is mitigated by existing input validation and Content Security Policy configurations.

2.8
Jul 9, 2026

WordPress Connect Contact Form 7 and Mailchimp Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the WordPress Connect Contact Form 7 and Mailchimp plugin, affecting all versions up to and including 0.9.78.06. The issue arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages. These scripts execute when a privileged user, such as an administrator, performs a contact lookup for the email address submitted via the Contact Form 7 form. This exploitation defers the execution of the injected script until an administrator interacts with the affected entry.

4.0
Jul 9, 2026

Download Manager Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Download Manager plugin for WordPress, affecting all versions through 3.3.61. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts via the 'note_before' and 'note_after' shortcode attributes. The issue arises from inadequate input sanitization and output escaping, enabling the execution of injected scripts when users access the affected pages.

5.4
Jul 9, 2026

Mail Mint WordPress Plugin SQL Injection Vulnerability in Contact IDs Parameter

A time-based SQL injection vulnerability has been identified in the Mail Mint WordPress plugin, specifically in versions through 1.24.2. The issue arises in the 'contact_ids' parameter, where insufficient escaping of user-supplied data allows authenticated attackers with administrator-level access to append malicious SQL queries. This exploitation could lead to the extraction of sensitive information from the database.

3.5
Jul 9, 2026

miniOrange OTP Login, Verification and SMS Notifications Authentication Bypass Vulnerability Allowing Administrator Account Takeover

A vulnerability exists in the miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress, affecting all versions up to and including 5.5.1. The issue arises from the 'um_reset_password_process_hook()' function, which fails to perform server-side verification of OTP validation. Instead, it relies on a public 'form_nonce' that the plugin sends to unauthenticated users via the 'moumprvar' JavaScript object on the Ultimate Member password reset page. The function also accepts the 'username_b' parameter, allowing attackers to target any WordPress user without role restrictions or a validated OTP session. This flaw enables unauthenticated attackers to generate a password-reset URL for any Administrator account, which can be used to gain full control of that account. Exploitation requires the Ultimate Member Password Reset Form integration to be active and the plugin not to be set for phone-only resets.

4.5
Jul 9, 2026

Customer Reviews for WooCommerce Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Customer Reviews for WooCommerce plugin for WordPress. This issue affects all versions through 5.113.0 and arises from inadequate input sanitization and output escaping. The vulnerability allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages. These scripts are executed when users access the affected pages.

4.9
Jul 9, 2026

GamiPress WordPress Plugin Insecure Direct Object Reference Vulnerability

A vulnerability allowing insecure direct object reference has been identified in the GamiPress WordPress plugin, specifically in versions through 7.9.4. The issue arises from a lack of proper validation on the 'access' parameter, which is user-controlled. This vulnerability enables unauthenticated attackers to access private GamiPress activity log entries of any user. The exposed logs include details on badge earnings, points balance changes, and event records from integrated plugins like WooCommerce, LearnDash, and BuddyPress. The exploitation is made easier because the 'gamipress' nonce is available to all front-end users, allowing for straightforward bypassing of authentication requirements.

6.1
Jul 9, 2026

Mang Board WP Reflected Cross-Site Scripting Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Mang Board WP plugin for WordPress, affecting all versions through 2.3.4. The vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages. These scripts could be executed if the attacker successfully persuades a user to perform an action, such as clicking a link.

4.3
Jul 9, 2026

Ultimate Post WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the Ultimate Post plugin for WordPress, specifically in versions through 5.0.31. The issue arises in the 'moreResultsText' block attribute of the 'ultimate-post/advanced-search' block. This vulnerability is due to inadequate input sanitization and output escaping in the 'Advanced_Search::content()' render callback. While the attribute value is filtered with 'wp_kses()' to remove disallowed HTML tags, it does not escape HTML special characters, such as double quotes, in plain text. Consequently, the unescaped data is directly added to the 'data-viewmoretext' HTML attribute without using 'esc_attr()'. As a result, authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages, which will execute when a user accesses the compromised page.

3.5
Jul 9, 2026

WPFunnels Local File Inclusion Vulnerability Allowing Arbitrary PHP Code Execution

A local file inclusion vulnerability has been identified in the WPFunnels plugin for WordPress, specifically in versions through 3.12.7. The issue arises in the settings module, where the 'logKey' parameter can be exploited by authenticated users with administrator-level access. This vulnerability allows the inclusion and execution of arbitrary PHP files on the server, potentially leading to unauthorized access, data exposure, or code execution, especially in scenarios where uploaded PHP files can be included.

3.8
Jul 9, 2026

ERP Complete HR, Accounting and CRM Suite SQL Injection Vulnerability

A SQL injection vulnerability has been identified in the ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress. This vulnerability affects all versions through 1.17.5 and allows authenticated attackers with HR Manager-level access to manipulate SQL queries. The issue arises from inadequate escaping of user-supplied data in the 'orderby' parameter, enabling the injection of additional SQL commands that could be used to extract sensitive information from the database.

3.6
Jul 9, 2026

User Frontend WordPress Plugin Insecure Direct Object Reference Vulnerability Allowing Unauthenticated Post Modification

A vulnerability exists in the User Frontend WordPress plugin, specifically in the AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration features, in all versions through 4.3.7. The issue is an Insecure Direct Object Reference (IDOR) that allows unauthenticated users to manipulate the 'wpuf_files_data' parameter without proper validation. This exploitation enables attackers to overwrite the post title, content, and excerpt of any post on the site, including those written by administrators. The vulnerability can be exploited by accessing any WPUF post submission form, which is available to users without a WordPress role, as the wpuf_submit_post AJAX action only requires a nonce and lacks a capability check for the post-editing process.

3.9
Jul 9, 2026

User Frontend WordPress Plugin Authorization Bypass Vulnerability Allowing Unauthenticated Attachment Deletion

A vulnerability exists in the User Frontend WordPress plugin, specifically in versions through 4.3.7. The issue arises from the plugin's failure to properly verify user authorization, allowing unauthenticated users to delete arbitrary media attachments with a post author of 0. This includes files uploaded by guests or through registration forms. The vulnerability is exploited via the 'wpuf_file_del' AJAX action, on sites where a WPUF shortcode is active on the front end. This configuration exposes a valid nonce, bypassing the only access control in place.

6.7
Jul 9, 2026

AcyMailing WordPress Plugin Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting vulnerability has been identified in the AcyMailing WordPress plugin, specifically in versions through 10.10.2. This vulnerability arises from inadequate input sanitization and output escaping, allowing authenticated attackers with contributor-level access or higher to inject arbitrary web scripts. These scripts are executed when a user accesses the affected page.

5.6
Jul 9, 2026

WordPress ProfileGrid WooCommerce Integration Missing Authorization Vulnerability

A vulnerability exists in the WordPress ProfileGrid WooCommerce Integration plugin, specifically in versions through 3.4. The issue stems from a lack of proper capability checks and nonce validation in the 'pg_install_profilegrid' AJAX handler. This flaw allows authenticated users with Subscriber-level access and above to install and activate the ProfileGrid plugin without authorization.

3.6
Jul 9, 2026

Cloud Foundry UAA LDAP StartTLS Impersonation Vulnerability Allowing Password Harvesting and Admin Scope Granting

A vulnerability exists in Cloud Foundry UAA versions prior to v78.13.0 and in cf-deployment versions prior to v56.2.0. This vulnerability allows a network attacker positioned between UAA and its LDAP directory to impersonate the directory using any certificate from a trusted CA. The attacker can then harvest the LDAP bind password and all end-user passwords transmitted during simple-bind authentication. Additionally, the attacker can return forged group memberships that grant admin scopes. This issue affects deployments that authenticate users against LDAP over StartTLS.

3.9
Jul 9, 2026

Cloud Foundry bosh-windows-stemcell-builder Cryptographically Weak Password Generation Allows Remote SSH Brute-Force Attacks

A vulnerability exists in Cloud Foundry's bosh-windows-stemcell-builder, specifically in versions prior to 2019.98. The issue arises from the use of a weak random number generator in the GenerateRandomPassword function, which enables remote attackers to brute-force SSH login credentials over TCP port 22.

3.0
Jul 9, 2026

Cloud Foundry BOSH Windows Stemcell Builder Incorrect Permission Assignment Allows Local Privilege Escalation to SYSTEM

A vulnerability exists in BOSH-Ecosystem BOSH Windows Stemcell Builder, specifically in the BOSH.Utils.psm1 file, prior to version 2019.98. This vulnerability allows low-privilege authenticated users to overwrite service_wrapper.exe or bosh-agent.exe. Exploiting this issue can lead to gaining NT AUTHORITY\SYSTEM privileges upon the next service restart or reboot, potentially allowing full control over the host.

2.0
Jul 9, 2026

Cloud Foundry BOSH CLI Argument Injection Vulnerability Allows Local Command Execution

A vulnerability exists in BOSH CLI versions prior to 7.10.4, allowing a compromised BOSH Director to inject arbitrary OpenSSH options into the local SSH process. This occurs when an operator uses non-interactive SSH commands, such as 'bosh ssh -c' or 'bosh logs -f'. The injected options can lead to unauthorized command execution on the operator's workstation.

2.9
Jul 9, 2026

BOSH CLI Missing TLS Certificate Verification Vulnerability Allows Root Code Execution via Man-in-the-Middle Credential Replay

A vulnerability exists in BOSH CLI versions prior to v7.10.4, where the CLI fails to verify the server certificate during HTTPS uploads of compiled CPI packages and rendered job templates to the VM's DAV blobstore. This issue occurs despite a CA certificate being available in the installation manifest. A network attacker could exploit this by terminating the TLS connection, capturing Basic-auth credentials, and accessing the rendered-templates archive, which contains all bootstrap secrets for the new BOSH Director. The attacker could then replay these credentials against the VM's agent to execute root code.

2.5
Jul 9, 2026

BOSH CLI Tool Path Traversal Vulnerability in Blobs.yml Allows Arbitrary File Writes

A path traversal vulnerability has been identified in the BOSH CLI tool, specifically in versions prior to 7.10.4. This vulnerability allows an attacker to write arbitrary files and exfiltrate sensitive information by exploiting the 'blobs.yml' path key traversal issue.

2.8
Jul 9, 2026

Fediverse Embeds WordPress Plugin Unauthenticated Server-Side Request Forgery Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in the Fediverse Embeds WordPress plugin, affecting versions prior to 1.5.8. The vulnerability arises because the plugin's site-info endpoint does not properly validate the destination of server-side requests before fetching them. This flaw allows anonymous users to make requests to internal and private-network URLs, retrieving parsed page metadata from those locations. The issue is exacerbated by the exposure of the gating nonce on public pages with embeds, which can be exploited by unauthenticated users.

4.4
Jul 9, 2026

Fediverse Embeds WordPress Plugin Server-Side Request Forgery Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in the Fediverse Embeds WordPress plugin, affecting versions prior to 1.5.8. The vulnerability arises because the plugin's media-proxying endpoint does not properly validate the destination of server-side requests. This flaw allows anonymous users to make the site fetch arbitrary URLs, including internal and private-network addresses, and read back the response body. The issue effectively creates an open proxy, enabling full-read SSRF exploitation.

4.5
Jul 9, 2026

Everest Forms WordPress Plugin Unauthenticated Missing Authorization via Site Assistant REST Endpoints

A vulnerability exists in the Everest Forms WordPress plugin in versions prior to 3.5.0, where several REST API endpoints related to the onboarding assistant do not properly restrict access. The capability check can be bypassed by omitting or altering a specific request header, allowing unauthenticated attackers to read onboarding status, modify plugin options, and send test emails to arbitrary addresses.

7.2
Jul 9, 2026

WP Support Plus Responsive Ticket System Unauthenticated Session Cookie Forgery Vulnerability

A vulnerability exists in the WP Support Plus Responsive Ticket System WordPress plugin, affecting versions through 9.1.2. The issue arises because the plugin does not sign or verify its guest-session cookie. This flaw allows unauthenticated attackers to forge the cookie and impersonate any ticket owner, identified by email address. Attackers can then read, reply to, and close the victim's support tickets.

5.9
Jul 9, 2026

WP DSGVO Tools (GDPR) WordPress Plugin Unauthenticated Personal Data Export Vulnerability

A vulnerability exists in the WP DSGVO Tools (GDPR) WordPress plugin in versions prior to 3.1.40. The plugin's data subject access request feature lacks proper authorization checks, enabling unauthenticated attackers to generate and download personal data exports of any user, customer, or commenter by simply providing their email address. The exported data includes the individual's name, postal address, phone number, email, and comment content.

7.1
Jul 9, 2026

Everest Forms WordPress Plugin Temporary CSV File Exposure Vulnerability

A vulnerability exists in the Everest Forms WordPress plugin in versions prior to 3.5.0, where temporary CSV files created during email notification processing are not consistently deleted. These files are left publicly accessible in the uploads directory, allowing unauthenticated attackers to access other users' form submission records through predictable, enumerable filenames. Exploitation requires the Everest Forms Pro add-on to be active, as the CSV email attachment feature is only available with Pro. The vulnerability arises when a form has multiple email notifications, with the CSV attachment enabled on a notification that is processed before the one where it is disabled. In such cases, the entry identifiers, which are sequential and returned to the submitter in the response, can be easily enumerated to retrieve the exposed CSV files.

6.4
Jul 9, 2026

Divi Form Builder Missing Authorization Vulnerability Allowing Privilege Escalation

A vulnerability exists in the Divi Form Builder plugin for WordPress, in versions through 5.1.8, allowing for unauthorized changes to user accounts. The issue arises because the update_user() function accepts user ID parameters from form submissions without proper authorization checks. As a result, authenticated attackers with subscriber-level access or higher can modify the email addresses and passwords of any user, including administrators, leading to complete account takeover.

2.6
Jul 9, 2026

Cloud Foundry BOSH CLI Shell Injection Vulnerability

A shell injection vulnerability has been identified in Cloud Foundry BOSH CLI versions prior to 7.10.5. This vulnerability allows a compromised or malicious BOSH Director to execute arbitrary shell commands on the operator's workstation. The issue arises when the operator uses the 'bosh ssh', 'bosh scp', or 'bosh logs -f' commands with default flags.

2.6