1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 12:15 PM 16,237 active 1,443 known exploited

Catalog summary

16,237

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 8, 2026, 12:15 PM 16,237 active 1,443 known exploited

Catalog summary

16,237

Active CVEs

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 501–550 of 16,237 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-66447Critical
    WordPress WordPress File Upload plugin <= 5.1.7 - SQL Injection vulnerability
    CVSS 9.3
    nickboss/WordPress File Uploadgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  2. CVE-2026-66440High
    WordPress WPIDE – File Manager & Code Editor plugin <= 3.5.7 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    XplodedThemes/WPIDE – File Manager & Code Editorgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  3. CVE-2026-66439High
    WordPress Advanced AJAX Product Filters plugin <= 3.2.0.3 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    BeRocket/Advanced AJAX Product Filtersgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  4. CVE-2026-66425Medium
    WordPress Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin <= 1.9.0 - Broken Authentication vulnerability
    CVSS 6.5
    Saad Iqbal/Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Buildergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  5. CVE-2026-65581Critical
    WordPress AI ANN theme <= 1.29.0 - PHP Object Injection vulnerability
    CVSS 9.8
    Axiomthemes/AI ANNgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  6. CVE-2026-65579Critical
    WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerability
    CVSS 9.8
    axiomthemes/Agricolageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  7. CVE-2026-65578Critical
    WordPress Agora theme <= 1.9 - PHP Object Injection vulnerability
    CVSS 9.8
    AncoraThemes/Agorageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  8. CVE-2026-65577Critical
    WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerability
    CVSS 9.8
    AncoraThemes/Advicegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  9. CVE-2026-65576Critical
    WordPress Adrena theme <= 1.2.14 - PHP Object Injection vulnerability
    CVSS 9.8
    AncoraThemes/Adrenageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  10. CVE-2026-65575Critical
    WordPress Accalia theme <= 1.5.3 - PHP Object Injection vulnerability
    CVSS 9.8
    AncoraThemes/Accaliageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  11. CVE-2026-65574Critical
    WordPress Abogado theme <= 1.18 - PHP Object Injection vulnerability
    CVSS 9.8
    AncoraThemes/Abogadogeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  12. CVE-2026-65573Critical
    WordPress Abelle theme <= 1.22 - PHP Object Injection vulnerability
    CVSS 9.8
    ThemeREX/Abellegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  13. CVE-2026-65572Critical
    WordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerability
    CVSS 9.8
    Axiomthemes/A.Williamsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  14. CVE-2026-65571Critical
    WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerability
    CVSS 9.8
    Axiomthemes/69 Clothinggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  15. CVE-2026-65570High
    WordPress Login with phone number plugin <= 1.8.70 - Bypass vulnerability vulnerability
    CVSS 8.1
    Hamid Alinia/Login with phone numbergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  16. CVE-2026-65569High
    WordPress WP Job Portal plugin <= 2.5.6 - SQL Injection vulnerability
    CVSS 8.5
    wpjobportal/WP Job Portalgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  17. CVE-2026-65565High
    WordPress Survey Maker plugin <= 5.2.3.3 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Ays Pro/Survey Makergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  18. CVE-2026-65560High
    WordPress Houzez Property Feed plugin <= 2.5.48 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Property Hive/Houzez Property Feedgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  19. CVE-2026-65559High
    WordPress Order Delivery Date for WooCommerce plugin <= 4.6.0 - Privilege Escalation vulnerability
    CVSS 7.2
    tychesoftwares/Order Delivery Date for WooCommercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  20. CVE-2026-65556Critical
    WordPress WPBruiser {no- Captcha anti-Spam} plugin <= 3.1.43 - PHP Object Injection vulnerability
    CVSS 9.8
    MihChe/WPBruiser {no- Captcha anti-Spam}generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  21. CVE-2026-65554High
    WordPress AnsPress – Question and answer plugin 4.4.4 - Broken Access Control vulnerability
    CVSS 7.1
    lattepress/AnsPress – Question and answergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  22. CVE-2026-65553Critical
    WordPress Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code Execution (RCE) vulnerability
    CVSS 10.0
    wbolt.com/Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  23. CVE-2026-65552Critical
    WordPress Export User Data plugin <= 2.2.6 - PHP Object Injection vulnerability
    CVSS 9.8
    qstudio/Export User Datageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  24. CVE-2026-65549High
    WordPress Jeg Elementor Kit plugin <= 3.2.10 - PHP Object Injection vulnerability
    CVSS 7.2
    jegtheme/Jeg Kit for Elementorgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  25. CVE-2026-65548Critical
    WordPress Betheme theme <= 28.4.2 - Remote Code Execution (RCE) vulnerability
    CVSS 9.9
    Muffingroup/Bethemegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  26. CVE-2026-65547High
    WordPress Creative Mail plugin <= 1.6.9 - SQL Injection vulnerability
    CVSS 8.5
    Constant Contact/Creative Mailgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  27. CVE-2026-65546Critical
    WordPress Qode Tours plugin <= 3.1.3.1 - SQL Injection vulnerability
    CVSS 9.3
    QODE/Qode Toursgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  28. CVE-2026-65545High
    WordPress AI Engine plugin <= 3.6.8 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Jordy Meow/AI Enginegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  29. CVE-2026-65544High
    WordPress Super Socializer plugin <= 7.14.5 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Rajat Varlani/Super Socializergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  30. CVE-2026-65543High
    WordPress Vimeo plugin <= 1.2.2 - Sensitive Data Exposure vulnerability
    CVSS 7.5
    vimeodev/Vimeogeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  31. CVE-2026-65542High
    WordPress Super Socializer plugin <= 7.14.5 - Broken Authentication vulnerability
    CVSS 8.8
    Rajat Varlani/Super Socializergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  32. CVE-2026-65541High
    WordPress Staff Training plugin <= 1.0.7 - Broken Access Control vulnerability
    CVSS 7.3
    solutioned/Staff Traininggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  33. CVE-2026-65523High
    WordPress Formidable Forms Signature Online Contract Automation plugin <= 2.0.1 - Insecure Direct Object References (IDOR) vulnerability
    CVSS 7.5
    approveme/Formidable Forms Signature Online Contract Automationgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  34. CVE-2026-65520Critical
    WordPress WP OAuth Server plugin <= 6.2.0 - SQL Injection vulnerability
    CVSS 9.3
    miniOrange/WP OAuth Servergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  35. CVE-2026-65517High
    WordPress Easy PayPal Buy Now Button plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Scott Paterson/Easy PayPal Buy Now Buttongeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  36. CVE-2026-65515High
    WordPress AffiliateWP plugin <= 2.35.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    AffiliateWP/AffiliateWPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  37. CVE-2026-65513High
    WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    NSquared/Simply Schedule Appointmentsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  38. CVE-2026-65509High
    WordPress wpDataTables plugin <= 7.5.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    wpDataTables/wpDataTablesgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  39. CVE-2026-65508Critical
    WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vulnerability
    CVSS 9.3
    NSquared/Simply Schedule Appointmentsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  40. CVE-2026-65507Critical
    WordPress AIWU plugin <= 1.5.6 - Privilege Escalation vulnerability
    CVSS 9.8
    Sergey/AIWUgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  41. CVE-2026-65504High
    WordPress BOX NOW Delivery Croatia plugin <= 3.3.0 - Broken Access Control vulnerability
    CVSS 7.5
    ivanbebek/BOX NOW Delivery Croatiageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  42. CVE-2026-65502Medium
    WordPress Element Pack Elementor Addons plugin <= 8.7.13 - Captcha Bypass vulnerability
    CVSS 5.3
    bdthemes/Element Pack Elementor Addonsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  43. CVE-2026-61982High
    WordPress SiteGuard WP Plugin plugin <= 1.8.6 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    jp-secure/SiteGuard WP Plugingeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  44. CVE-2026-61964High
    WordPress Ninja Tables plugin <= 5.2.9 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    WPManageNinja/Ninja Tablesgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  45. CVE-2026-61963High
    WordPress Media LIbrary Assistant plugin <= 3.38 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    David Lingren/Media LIbrary Assistantgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  46. CVE-2026-61961High
    WordPress EmbedPress plugin <= 4.5.6 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    WPDeveloper/EmbedPressgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  47. CVE-2026-61959Medium
    WordPress Business Directory plugin <= 6.4.24 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    Strategy11 Team/Business Directorygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  48. CVE-2026-32548Medium
    WordPress SureCart plugin <= 4.6.2 - Broken Access Control vulnerability
    CVSS 5.3
    SureCart/SureCartgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  49. CVE-2026-32469Medium
    WordPress CAPTCHA 4WP plugin <= 7.6.0 - Captcha Bypass vulnerability
    CVSS 5.3
    WPKube/CAPTCHA 4WPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  50. CVE-2026-28180Medium
    WordPress Mercado Pago payments for WooCommerce plugin <= 8.9.0 - Insecure Direct Object References (IDOR) vulnerability
    CVSS 5.3
    Mercado Pago/Mercado Pago payments for WooCommercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
Page 11 of 325
Previous910111213Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,391

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 501–550 of 16,237 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-66447Critical
    WordPress WordPress File Upload plugin <= 5.1.7 - SQL Injection vulnerability
    CVSS 9.3
    nickboss/WordPress File Uploadgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  2. CVE-2026-66440High
    WordPress WPIDE – File Manager & Code Editor plugin <= 3.5.7 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    XplodedThemes/WPIDE – File Manager & Code Editorgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  3. CVE-2026-66439High
    WordPress Advanced AJAX Product Filters plugin <= 3.2.0.3 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    BeRocket/Advanced AJAX Product Filtersgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  4. CVE-2026-66425Medium
    WordPress Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin <= 1.9.0 - Broken Authentication vulnerability
    CVSS 6.5
    Saad Iqbal/Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Buildergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 8, 2026View HOL analysis
  5. CVE-2026-65581Critical
    WordPress AI ANN theme <= 1.29.0 - PHP Object Injection vulnerability
    CVSS 9.8
    Axiomthemes/AI ANNgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  6. CVE-2026-65579Critical
    WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerability
    CVSS 9.8
    axiomthemes/Agricolageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  7. CVE-2026-65578Critical
    WordPress Agora theme <= 1.9 - PHP Object Injection vulnerability
    CVSS 9.8
    AncoraThemes/Agorageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  8. CVE-2026-65577Critical
    WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerability
    CVSS 9.8
    AncoraThemes/Advicegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  9. CVE-2026-65576Critical
    WordPress Adrena theme <= 1.2.14 - PHP Object Injection vulnerability
    CVSS 9.8
    AncoraThemes/Adrenageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  10. CVE-2026-65575Critical
    WordPress Accalia theme <= 1.5.3 - PHP Object Injection vulnerability
    CVSS 9.8
    AncoraThemes/Accaliageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  11. CVE-2026-65574Critical
    WordPress Abogado theme <= 1.18 - PHP Object Injection vulnerability
    CVSS 9.8
    AncoraThemes/Abogadogeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  12. CVE-2026-65573Critical
    WordPress Abelle theme <= 1.22 - PHP Object Injection vulnerability
    CVSS 9.8
    ThemeREX/Abellegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  13. CVE-2026-65572Critical
    WordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerability
    CVSS 9.8
    Axiomthemes/A.Williamsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  14. CVE-2026-65571Critical
    WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerability
    CVSS 9.8
    Axiomthemes/69 Clothinggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  15. CVE-2026-65570High
    WordPress Login with phone number plugin <= 1.8.70 - Bypass vulnerability vulnerability
    CVSS 8.1
    Hamid Alinia/Login with phone numbergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  16. CVE-2026-65569High
    WordPress WP Job Portal plugin <= 2.5.6 - SQL Injection vulnerability
    CVSS 8.5
    wpjobportal/WP Job Portalgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  17. CVE-2026-65565High
    WordPress Survey Maker plugin <= 5.2.3.3 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Ays Pro/Survey Makergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  18. CVE-2026-65560High
    WordPress Houzez Property Feed plugin <= 2.5.48 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Property Hive/Houzez Property Feedgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  19. CVE-2026-65559High
    WordPress Order Delivery Date for WooCommerce plugin <= 4.6.0 - Privilege Escalation vulnerability
    CVSS 7.2
    tychesoftwares/Order Delivery Date for WooCommercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  20. CVE-2026-65556Critical
    WordPress WPBruiser {no- Captcha anti-Spam} plugin <= 3.1.43 - PHP Object Injection vulnerability
    CVSS 9.8
    MihChe/WPBruiser {no- Captcha anti-Spam}generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  21. CVE-2026-65554High
    WordPress AnsPress – Question and answer plugin 4.4.4 - Broken Access Control vulnerability
    CVSS 7.1
    lattepress/AnsPress – Question and answergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  22. CVE-2026-65553Critical
    WordPress Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code Execution (RCE) vulnerability
    CVSS 10.0
    wbolt.com/Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件generic
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  23. CVE-2026-65552Critical
    WordPress Export User Data plugin <= 2.2.6 - PHP Object Injection vulnerability
    CVSS 9.8
    qstudio/Export User Datageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  24. CVE-2026-65549High
    WordPress Jeg Elementor Kit plugin <= 3.2.10 - PHP Object Injection vulnerability
    CVSS 7.2
    jegtheme/Jeg Kit for Elementorgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  25. CVE-2026-65548Critical
    WordPress Betheme theme <= 28.4.2 - Remote Code Execution (RCE) vulnerability
    CVSS 9.9
    Muffingroup/Bethemegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  26. CVE-2026-65547High
    WordPress Creative Mail plugin <= 1.6.9 - SQL Injection vulnerability
    CVSS 8.5
    Constant Contact/Creative Mailgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  27. CVE-2026-65546Critical
    WordPress Qode Tours plugin <= 3.1.3.1 - SQL Injection vulnerability
    CVSS 9.3
    QODE/Qode Toursgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  28. CVE-2026-65545High
    WordPress AI Engine plugin <= 3.6.8 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Jordy Meow/AI Enginegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  29. CVE-2026-65544High
    WordPress Super Socializer plugin <= 7.14.5 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Rajat Varlani/Super Socializergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  30. CVE-2026-65543High
    WordPress Vimeo plugin <= 1.2.2 - Sensitive Data Exposure vulnerability
    CVSS 7.5
    vimeodev/Vimeogeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  31. CVE-2026-65542High
    WordPress Super Socializer plugin <= 7.14.5 - Broken Authentication vulnerability
    CVSS 8.8
    Rajat Varlani/Super Socializergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  32. CVE-2026-65541High
    WordPress Staff Training plugin <= 1.0.7 - Broken Access Control vulnerability
    CVSS 7.3
    solutioned/Staff Traininggeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  33. CVE-2026-65523High
    WordPress Formidable Forms Signature Online Contract Automation plugin <= 2.0.1 - Insecure Direct Object References (IDOR) vulnerability
    CVSS 7.5
    approveme/Formidable Forms Signature Online Contract Automationgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  34. CVE-2026-65520Critical
    WordPress WP OAuth Server plugin <= 6.2.0 - SQL Injection vulnerability
    CVSS 9.3
    miniOrange/WP OAuth Servergeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  35. CVE-2026-65517High
    WordPress Easy PayPal Buy Now Button plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Scott Paterson/Easy PayPal Buy Now Buttongeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  36. CVE-2026-65515High
    WordPress AffiliateWP plugin <= 2.35.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    AffiliateWP/AffiliateWPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  37. CVE-2026-65513High
    WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    NSquared/Simply Schedule Appointmentsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  38. CVE-2026-65509High
    WordPress wpDataTables plugin <= 7.5.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    wpDataTables/wpDataTablesgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  39. CVE-2026-65508Critical
    WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vulnerability
    CVSS 9.3
    NSquared/Simply Schedule Appointmentsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  40. CVE-2026-65507Critical
    WordPress AIWU plugin <= 1.5.6 - Privilege Escalation vulnerability
    CVSS 9.8
    Sergey/AIWUgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  41. CVE-2026-65504High
    WordPress BOX NOW Delivery Croatia plugin <= 3.3.0 - Broken Access Control vulnerability
    CVSS 7.5
    ivanbebek/BOX NOW Delivery Croatiageneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  42. CVE-2026-65502Medium
    WordPress Element Pack Elementor Addons plugin <= 8.7.13 - Captcha Bypass vulnerability
    CVSS 5.3
    bdthemes/Element Pack Elementor Addonsgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  43. CVE-2026-61982High
    WordPress SiteGuard WP Plugin plugin <= 1.8.6 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    jp-secure/SiteGuard WP Plugingeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  44. CVE-2026-61964High
    WordPress Ninja Tables plugin <= 5.2.9 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    WPManageNinja/Ninja Tablesgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  45. CVE-2026-61963High
    WordPress Media LIbrary Assistant plugin <= 3.38 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    David Lingren/Media LIbrary Assistantgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  46. CVE-2026-61961High
    WordPress EmbedPress plugin <= 4.5.6 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    WPDeveloper/EmbedPressgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  47. CVE-2026-61959Medium
    WordPress Business Directory plugin <= 6.4.24 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    Strategy11 Team/Business Directorygeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  48. CVE-2026-32548Medium
    WordPress SureCart plugin <= 4.6.2 - Broken Access Control vulnerability
    CVSS 5.3
    SureCart/SureCartgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  49. CVE-2026-32469Medium
    WordPress CAPTCHA 4WP plugin <= 7.6.0 - Captcha Bypass vulnerability
    CVSS 5.3
    WPKube/CAPTCHA 4WPgeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
  50. CVE-2026-28180Medium
    WordPress Mercado Pago payments for WooCommerce plugin <= 8.9.0 - Insecure Direct Object References (IDOR) vulnerability
    CVSS 5.3
    Mercado Pago/Mercado Pago payments for WooCommercegeneric
    PublishedAug 6, 2026First seen at HOL Aug 6, 2026Updated Aug 6, 2026View HOL analysis
Page 11 of 325
Previous910111213Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard