1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 3:15 PM 16,333 active 1,443 known exploited

Catalog summary

16,333

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 3:15 PM 16,333 active 1,443 known exploited

Catalog summary

16,333

Active CVEs

8,453

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,401–3,450 of 16,333 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-57710Critical
    WordPress WoowBot Pro Max plugin <= 14.1.7 - Arbitrary File Upload vulnerability
    CVSS 9.9
    quantumcloud/WoowBot Pro Maxgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  2. CVE-2026-57711Medium
    WordPress SupportCandy plugin <= 3.4.8 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    PSM Plugins/SupportCandygeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  3. CVE-2026-57707Critical
    WordPress Simple Business Directory Pro plugin <= 15.9.4 - SQL Injection vulnerability
    CVSS 9.3
    quantumcloud/Simple Business Directory Progeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  4. CVE-2026-57709High
    WordPress Membership For WooCommerce plugin <= 3.1.0 - Arbitrary File Deletion vulnerability
    CVSS 8.6
    WP Swings/Membership For WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  5. CVE-2026-57708High
    WordPress Contact Form Entries plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    CRM Perks/Contact Form Entriesgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  6. CVE-2026-57706High
    WordPress Dokan plugin <= 5.0.6 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Dokan, Inc./Dokangeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  7. CVE-2026-57705High
    WordPress Event Tickets plugin <= 5.28.5 - Broken Access Control vulnerability
    CVSS 7.5
    Nexcess/Event Ticketsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  8. CVE-2026-57702Critical
    WordPress Amelia plugin <= 2.4.2 - SQL Injection vulnerability
    CVSS 9.3
    Melograno Venture Studio/Ameliageneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  9. CVE-2026-57698Medium
    WordPress Abandoned Cart Recovery for WooCommerce plugin <= 1.1.12 - Broken Authentication vulnerability
    CVSS 6.5
    VillaTheme/Abandoned Cart Recovery for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  10. CVE-2026-57697High
    WordPress ProfileGrid plugin <= 5.9.9.6 - Broken Authentication vulnerability
    CVSS 7.5
    Metagauss/ProfileGridgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  11. CVE-2026-57695High
    WordPress Document Gallery plugin <= 5.1.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Dan Rossiter/Document Gallerygeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  12. CVE-2026-57693Medium
    WordPress Ad Inserter plugin <= 2.8.11 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    Spacetime/Ad Insertergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  13. CVE-2026-57668High
    WordPress NEX-Forms plugin <= 9.2.2 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Basix/NEX-Formsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  14. CVE-2026-57691Medium
    WordPress Anti-Malware Security and Brute-Force Firewall plugin <= 4.23.89 - Cross Site Scripting (XSS) vulnerability
    CVSS 5.8
    Eli/Anti-Malware Security and Brute-Force Firewallgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  15. CVE-2026-57694Medium
    WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDOR) vulnerability
    CVSS 6.5
    Themeum/Tutor LMSgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  16. CVE-2026-57424Medium
    WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.4 - Broken Access Control vulnerability
    CVSS 6.5
    knitpay/Razorpay Payment Links for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  17. CVE-2026-57423High
    WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.8 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Kofi Mokome/Message Filter for Contact Form 7generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  18. CVE-2026-57422High
    WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    VillaTheme/Bopo – WooCommerce Product Bundle Buildergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  19. CVE-2026-57421High
    WordPress CRM Perks Forms plugin <= 1.1.7 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    CRM Perks/CRM Perks Formsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  20. CVE-2026-57420Medium
    WordPress Author Box WP Lens plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    Netrr/Author Box WP Lensgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  21. CVE-2026-57418Medium
    WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.13 - Broken Access Control vulnerability
    CVSS 6.5
    BoldGrid/Client Invoicing by Sprout Invoicesgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  22. CVE-2026-57417High
    WordPress Cart Lift plugin <= 3.1.57 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    RexTheme/Cart Liftgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  23. CVE-2026-57419Medium
    WordPress Stock Locations for WooCommerce plugin <= 3.1.8 - Broken Access Control vulnerability
    CVSS 6.5
    Fahad Mahmood/Stock Locations for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  24. CVE-2026-57416High
    WordPress SiteGround Email Marketing plugin <= 1.7.5 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    SiteGround/SiteGround Email Marketinggeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  25. CVE-2026-57415High
    WordPress Gift Vouchers plugin <= 4.7.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Codemenschen/Gift Vouchersgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  26. CVE-2026-57414Medium
    WordPress ChatBot for eCommerce – WoowBot plugin <= 4.6.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    QuantumCloud/ChatBot for eCommerce &#8211; WoowBotgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  27. CVE-2026-57413Medium
    WordPress Instant Image Generator plugin <= 2.1.4 - Server Side Request Forgery (SSRF) vulnerability
    CVSS 6.4
    bdthemes/Instant Image Generatorgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  28. CVE-2026-57412Medium
    WordPress Gift Vouchers plugin <= 4.6.9 - Broken Access Control vulnerability
    CVSS 6.5
    Codemenschen/Gift Vouchersgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  29. CVE-2026-57411High
    WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= 3.2.2 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Aman/CF7 Views &#8211; Complete Entry Management for Contact Form 7generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  30. CVE-2026-57410High
    WordPress MailerPress plugin <= 2.0.2 - Privilege Escalation vulnerability
    CVSS 8.8
    MailerPress Team/MailerPressgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  31. CVE-2026-57409High
    WordPress Active Products Tables for WooCommerce plugin <= 1.1.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    RealMag777/Active Products Tables for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  32. CVE-2026-57408Medium
    WordPress Peach Payments Gateway plugin <= 4.0.2 - Broken Access Control vulnerability
    CVSS 6.5
    peachpayments/Peach Payments Gatewaygeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  33. CVE-2026-57406Medium
    WordPress FundEngine plugin <= 1.7.6 - Broken Access Control vulnerability
    CVSS 6.5
    Roxnor/FundEnginegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  34. CVE-2026-57407High
    WordPress PDF Generator for WordPress plugin <= 1.6.2 - Server Side Request Forgery (SSRF) vulnerability
    CVSS 7.2
    WP Swings/PDF Generator for WordPressgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  35. CVE-2026-57404Medium
    WordPress Booking and Rental Manager plugin <= 2.6.9 - Broken Access Control vulnerability
    CVSS 6.5
    magepeopleteam/Booking and Rental Managergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  36. CVE-2026-57405High
    WordPress Open Shop theme <= 1.7.1 - Broken Access Control vulnerability
    CVSS 7.1
    themehunk/Open Shopgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  37. CVE-2026-57403High
    WordPress GD Security Headers plugin <= 1.8 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Milan Petrovic/GD Security Headersgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  38. CVE-2026-57402Medium
    WordPress Flexible Refund and Return Order for WooCommerce plugin <= 1.0.51 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    wpdesk/Flexible Refund and Return Order for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  39. CVE-2026-57401Critical
    WordPress SureDash plugin <= 1.8.0 - Arbitrary File Deletion vulnerability
    CVSS 9.9
    Brainstorm Force/SureDashgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  40. CVE-2026-57400Medium
    WordPress Event Tickets Manager for WooCommerce plugin <= 1.5.5 - Broken Access Control vulnerability
    CVSS 6.5
    WP Swings/Event Tickets Manager for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  41. CVE-2026-57398High
    WordPress Real Estate Manager Pro plugin <= 12.8.3 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    WebCodingPlace/Real Estate Manager Progeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  42. CVE-2026-57399High
    WordPress Proxy & VPN Blocker plugin <= 3.5.8 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Proxy &amp; VPN Blocker/Proxy &amp; VPN Blockergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  43. CVE-2026-57395Medium
    WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability
    CVSS 6.5
    Themefic/Tourficgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  44. CVE-2026-57396High
    WordPress Free Gifts for WooCommerce plugin <= 13.1.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Flintop/Free Gifts for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  45. CVE-2026-57394High
    WordPress Newsletters plugin <= 4.14 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Tribulant Software/Newslettersgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  46. CVE-2026-57392Medium
    WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability
    CVSS 6.5
    Themefic/Tourficgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  47. CVE-2026-57391Medium
    WordPress Loops & Logic plugin <= 4.2.3 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    Tangible/Loops & Logicgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  48. CVE-2026-57390Medium
    WordPress Extra Product Options Builder for WooCommerce plugin <= 1.2.167 - Broken Access Control vulnerability
    CVSS 6.5
    EDGARROJAS/Extra Product Options Builder for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  49. CVE-2026-57389High
    WordPress Groundhogg plugin <= 4.4.1 - Arbitrary File Deletion vulnerability
    CVSS 8.6
    Adrian Tobey/Groundhogggeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  50. CVE-2026-57388High
    WordPress Hydra Booking plugin <= 1.1.44 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Themefic/Hydra Bookinggeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
Page 69 of 327
Previous6768697071Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,453

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,401–3,450 of 16,333 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-57710Critical
    WordPress WoowBot Pro Max plugin <= 14.1.7 - Arbitrary File Upload vulnerability
    CVSS 9.9
    quantumcloud/WoowBot Pro Maxgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  2. CVE-2026-57711Medium
    WordPress SupportCandy plugin <= 3.4.8 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    PSM Plugins/SupportCandygeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  3. CVE-2026-57707Critical
    WordPress Simple Business Directory Pro plugin <= 15.9.4 - SQL Injection vulnerability
    CVSS 9.3
    quantumcloud/Simple Business Directory Progeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  4. CVE-2026-57709High
    WordPress Membership For WooCommerce plugin <= 3.1.0 - Arbitrary File Deletion vulnerability
    CVSS 8.6
    WP Swings/Membership For WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  5. CVE-2026-57708High
    WordPress Contact Form Entries plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    CRM Perks/Contact Form Entriesgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  6. CVE-2026-57706High
    WordPress Dokan plugin <= 5.0.6 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Dokan, Inc./Dokangeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  7. CVE-2026-57705High
    WordPress Event Tickets plugin <= 5.28.5 - Broken Access Control vulnerability
    CVSS 7.5
    Nexcess/Event Ticketsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  8. CVE-2026-57702Critical
    WordPress Amelia plugin <= 2.4.2 - SQL Injection vulnerability
    CVSS 9.3
    Melograno Venture Studio/Ameliageneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  9. CVE-2026-57698Medium
    WordPress Abandoned Cart Recovery for WooCommerce plugin <= 1.1.12 - Broken Authentication vulnerability
    CVSS 6.5
    VillaTheme/Abandoned Cart Recovery for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  10. CVE-2026-57697High
    WordPress ProfileGrid plugin <= 5.9.9.6 - Broken Authentication vulnerability
    CVSS 7.5
    Metagauss/ProfileGridgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  11. CVE-2026-57695High
    WordPress Document Gallery plugin <= 5.1.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Dan Rossiter/Document Gallerygeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  12. CVE-2026-57693Medium
    WordPress Ad Inserter plugin <= 2.8.11 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    Spacetime/Ad Insertergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  13. CVE-2026-57668High
    WordPress NEX-Forms plugin <= 9.2.2 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Basix/NEX-Formsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  14. CVE-2026-57691Medium
    WordPress Anti-Malware Security and Brute-Force Firewall plugin <= 4.23.89 - Cross Site Scripting (XSS) vulnerability
    CVSS 5.8
    Eli/Anti-Malware Security and Brute-Force Firewallgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  15. CVE-2026-57694Medium
    WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDOR) vulnerability
    CVSS 6.5
    Themeum/Tutor LMSgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  16. CVE-2026-57424Medium
    WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.4 - Broken Access Control vulnerability
    CVSS 6.5
    knitpay/Razorpay Payment Links for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  17. CVE-2026-57423High
    WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.8 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Kofi Mokome/Message Filter for Contact Form 7generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  18. CVE-2026-57422High
    WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    VillaTheme/Bopo – WooCommerce Product Bundle Buildergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  19. CVE-2026-57421High
    WordPress CRM Perks Forms plugin <= 1.1.7 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    CRM Perks/CRM Perks Formsgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  20. CVE-2026-57420Medium
    WordPress Author Box WP Lens plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    Netrr/Author Box WP Lensgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  21. CVE-2026-57418Medium
    WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.13 - Broken Access Control vulnerability
    CVSS 6.5
    BoldGrid/Client Invoicing by Sprout Invoicesgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  22. CVE-2026-57417High
    WordPress Cart Lift plugin <= 3.1.57 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    RexTheme/Cart Liftgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  23. CVE-2026-57419Medium
    WordPress Stock Locations for WooCommerce plugin <= 3.1.8 - Broken Access Control vulnerability
    CVSS 6.5
    Fahad Mahmood/Stock Locations for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  24. CVE-2026-57416High
    WordPress SiteGround Email Marketing plugin <= 1.7.5 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    SiteGround/SiteGround Email Marketinggeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  25. CVE-2026-57415High
    WordPress Gift Vouchers plugin <= 4.7.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Codemenschen/Gift Vouchersgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  26. CVE-2026-57414Medium
    WordPress ChatBot for eCommerce – WoowBot plugin <= 4.6.1 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    QuantumCloud/ChatBot for eCommerce &#8211; WoowBotgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  27. CVE-2026-57413Medium
    WordPress Instant Image Generator plugin <= 2.1.4 - Server Side Request Forgery (SSRF) vulnerability
    CVSS 6.4
    bdthemes/Instant Image Generatorgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  28. CVE-2026-57412Medium
    WordPress Gift Vouchers plugin <= 4.6.9 - Broken Access Control vulnerability
    CVSS 6.5
    Codemenschen/Gift Vouchersgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  29. CVE-2026-57411High
    WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= 3.2.2 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Aman/CF7 Views &#8211; Complete Entry Management for Contact Form 7generic
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  30. CVE-2026-57410High
    WordPress MailerPress plugin <= 2.0.2 - Privilege Escalation vulnerability
    CVSS 8.8
    MailerPress Team/MailerPressgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  31. CVE-2026-57409High
    WordPress Active Products Tables for WooCommerce plugin <= 1.1.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    RealMag777/Active Products Tables for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  32. CVE-2026-57408Medium
    WordPress Peach Payments Gateway plugin <= 4.0.2 - Broken Access Control vulnerability
    CVSS 6.5
    peachpayments/Peach Payments Gatewaygeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  33. CVE-2026-57406Medium
    WordPress FundEngine plugin <= 1.7.6 - Broken Access Control vulnerability
    CVSS 6.5
    Roxnor/FundEnginegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  34. CVE-2026-57407High
    WordPress PDF Generator for WordPress plugin <= 1.6.2 - Server Side Request Forgery (SSRF) vulnerability
    CVSS 7.2
    WP Swings/PDF Generator for WordPressgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  35. CVE-2026-57404Medium
    WordPress Booking and Rental Manager plugin <= 2.6.9 - Broken Access Control vulnerability
    CVSS 6.5
    magepeopleteam/Booking and Rental Managergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  36. CVE-2026-57405High
    WordPress Open Shop theme <= 1.7.1 - Broken Access Control vulnerability
    CVSS 7.1
    themehunk/Open Shopgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  37. CVE-2026-57403High
    WordPress GD Security Headers plugin <= 1.8 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Milan Petrovic/GD Security Headersgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  38. CVE-2026-57402Medium
    WordPress Flexible Refund and Return Order for WooCommerce plugin <= 1.0.51 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    wpdesk/Flexible Refund and Return Order for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  39. CVE-2026-57401Critical
    WordPress SureDash plugin <= 1.8.0 - Arbitrary File Deletion vulnerability
    CVSS 9.9
    Brainstorm Force/SureDashgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  40. CVE-2026-57400Medium
    WordPress Event Tickets Manager for WooCommerce plugin <= 1.5.5 - Broken Access Control vulnerability
    CVSS 6.5
    WP Swings/Event Tickets Manager for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  41. CVE-2026-57398High
    WordPress Real Estate Manager Pro plugin <= 12.8.3 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    WebCodingPlace/Real Estate Manager Progeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  42. CVE-2026-57399High
    WordPress Proxy & VPN Blocker plugin <= 3.5.8 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Proxy &amp; VPN Blocker/Proxy &amp; VPN Blockergeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  43. CVE-2026-57395Medium
    WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability
    CVSS 6.5
    Themefic/Tourficgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  44. CVE-2026-57396High
    WordPress Free Gifts for WooCommerce plugin <= 13.1.0 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Flintop/Free Gifts for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  45. CVE-2026-57394High
    WordPress Newsletters plugin <= 4.14 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Tribulant Software/Newslettersgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  46. CVE-2026-57392Medium
    WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability
    CVSS 6.5
    Themefic/Tourficgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  47. CVE-2026-57391Medium
    WordPress Loops & Logic plugin <= 4.2.3 - Cross Site Scripting (XSS) vulnerability
    CVSS 6.5
    Tangible/Loops & Logicgeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  48. CVE-2026-57390Medium
    WordPress Extra Product Options Builder for WooCommerce plugin <= 1.2.167 - Broken Access Control vulnerability
    CVSS 6.5
    EDGARROJAS/Extra Product Options Builder for WooCommercegeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  49. CVE-2026-57389High
    WordPress Groundhogg plugin <= 4.4.1 - Arbitrary File Deletion vulnerability
    CVSS 8.6
    Adrian Tobey/Groundhogggeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
  50. CVE-2026-57388High
    WordPress Hydra Booking plugin <= 1.1.44 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Themefic/Hydra Bookinggeneric
    PublishedJul 13, 2026First seen at HOL Jul 13, 2026Updated Jul 13, 2026View HOL analysis
Page 69 of 327
Previous6768697071Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard