1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 5:15 PM 16,339 active 1,443 known exploited

Catalog summary

16,339

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 5:15 PM 16,339 active 1,443 known exploited

Catalog summary

16,339

Active CVEs

8,456

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,601–3,650 of 16,339 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-1359High
    Genolve – AI image AI video generation <= 5.0.5 - Authenticated (Contributor+) Incorrect Authorization to Privilege Escalation via theopt
    CVSS 8.8
    genolve/Genolve – Genolve AI Business Graphics, AI Imagesgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  2. CVE-2026-15010Medium
    bbp style pack <= 6.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Topic Form Additional Fields
    CVSS 6.4
    robin-w/bbp style packgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  3. CVE-2026-10041Medium
    WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Vendor Data Manipulation via Multiple AJAX Handlers
    CVSS 4.3
    wclovers/WCFM – Frontend Manager for WooCommercegeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  4. CVE-2026-6939High
    CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Stored Cross-Site Scripting via 'approval_code' Parameter
    CVSS 7.2
    corvusinfo/CorvusPay WooCommerce Payment Gatewaygeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  5. CVE-2026-15155High
    Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection
    CVSS 8.8
    wpdevteam/Essential Addons for Elementor – Popular Elementor Templates & Widgetsgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 15, 2026View HOL analysis
  6. CVE-2026-12103Medium
    Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action
    CVSS 4.3
    subratamal/Wallet for WooCommercegeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  7. CVE-2026-12126Medium
    WCFM Marketplace <= 3.7.3 - Authenticated (Vendor+) Stored Cross-Site Scripting via Attachment 'post_title'
    CVSS 6.4
    wclovers/WCFM Marketplace – Multivendor Marketplace for WooCommercegeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  8. CVE-2026-4661High
    WP CTA <= 2.2.2 - Unauthenticated Time-Based Blind SQL Injection via 'fildname' Parameter
    CVSS 7.5
    blendmedia/WP CTA – Call Now Button, Sticky Button & Call to Action Buildergeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  9. CVE-2026-12994Medium
    WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manage Controller
    CVSS 5.3
    wclovers/WCFM – Frontend Manager for WooCommercegeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  10. CVE-2026-11591Medium
    Widgets for Google Reviews <= 13.3 - Authenticated (Editor+) Stored Cross-Site Scripting via 'fomo-title' and 'fomo-text' Parameters
    CVSS 4.4
    trustindex/Widgets for Google Reviewsgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  11. CVE-2026-1382Medium
    fresh Podcaster <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'freshpodcaster' Shortcode Attributes
    CVSS 6.4
    freshlabs/fresh Podcastergeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 14, 2026View HOL analysis
  12. CVE-2025-5017Medium
    Catalyst Connect Zoho CRM Client Portal <= 2.2.0 - Authenticated (Administrator+) SQL Injection via uid Parameter
    CVSS 4.9
    catalyst2020/Catalyst Connect Zoho CRM Client Portalgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 14, 2026View HOL analysis
  13. CVE-2026-6801Medium
    Context Blog <= 1.3.5 - Unauthenticated Sensitive Information Exposure via 'postID' Parameter
    CVSS 5.3
    postmagthemes/Context Bloggeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  14. CVE-2026-10865Medium
    Cost Calculator Builder <= 4.0.11 - Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys
    CVSS 5.3
    stylemix/Cost Calculator Buildergeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  15. CVE-2026-12738Medium
    WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Status Modification via wpep_draft_confirm AJAX Action
    CVSS 4.3
    saadiqbal/WP Easy Pay – Payment and Donation form Builder for Squaregeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  16. CVE-2026-11898Medium
    White Label CMS <= 2.7.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import Settings
    CVSS 4.4
    videousermanuals/White Label CMSgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2025-6784High
    Code Engine <= 0.3.5 - Authenticated (Contributor+) Remote Code Execution
    CVSS 8.8
    tigroumeow/Code Engine – PHP Snippets, AI Functions & Automation for WordPressgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  18. CVE-2026-11901Medium
    WP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via PayPal IPN Handler
    CVSS 5.3
    thimpress/WP Hotel Bookinggeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 14, 2026View HOL analysis
  19. CVE-2026-13378High
    Form Vibes <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting via Contact Form 7 Form Field
    CVSS 7.2
    wpvibes/Form Vibes – Save Contact Form 7 & Elementor Form Entries to Databasegeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  20. CVE-2026-1832Medium
    ThriveDesk <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Cache Deletion
    CVSS 4.3
    thrivedesk/Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDeskgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  21. CVE-2026-14262High
    Simple JWT Login <= 3.6.6 - Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation via 'payload' Parameter
    CVSS 8.8
    nicu_m/Simple JWT Login – Allows you to use JWT on REST endpoints.generic
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  22. CVE-2026-15335High
    Booking Package <= 1.7.20 - Unauthenticated SQL Injection via 'email' Form Parameter
    CVSS 7.5
    masaakitanaka/Booking Packagegeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 14, 2026View HOL analysis
  23. CVE-2026-12141Medium
    Premium Addons for Elementor <= 4.11.84 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'premium_tooltip_text' Parameter
    CVSS 4.9
    leap13/Premium Addons for Elementor – Powerful Elementor Templates & Widgetsgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 14, 2026View HOL analysis
  24. CVE-2026-13250Medium
    Solace Extra <= 1.5.3 - Missing Authorization to Unauthenticated Arbitrary Content Deletion via delete_previously_imported AJAX Action
    CVSS 5.3
    solacewp/Solace Extrageneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  25. CVE-2026-7559Medium
    Affilia <= 3.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Status Modification
    CVSS 4.3
    redefiningtheweb/Affiliate Program & Referral Tracking for WooCommerce & WordPress – Affiliageneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  26. CVE-2026-15096Medium
    Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Module 'b_width_map' Field
    CVSS 6.4
    themifyme/Themify Buildergeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  27. CVE-2025-13968Medium
    Starboard Suite Reservation Calendars <= 3.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
    CVSS 6.4
    starboardsuite/Starboard Suite Reservation Calendarsgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 15, 2026View HOL analysis
  28. CVE-2026-13116Medium
    PDF Invoices & Packing Slips for WooCommerce <= 5.14.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'order_id' Shortcode Attribute
    CVSS 4.3
    wpovernight/PDF Invoices & Packing Slips for WooCommercegeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  29. CVE-2026-3576High
    Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter
    CVSS 7.2
    xtreeme/Planyo online reservation systemgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  30. CVE-2026-9738Medium
    Print, PDF, Email by PrintFriendly <= 5.5.10 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'content_position_css' Parameter
    CVSS 4.4
    printfriendly/Print, PDF & Email by PrintFriendlygeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  31. CVE-2026-3552Medium
    SurfLink < 2.6.0 - Missing Authorization to Authenticated (Subscriber+) 410 Gone URL Import via 'surfl_import_410' AJAX Action
    CVSS 4.3
    surflabtech/SurfLink – Link Manager & Backup Restoregeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  32. CVE-2026-2354High
    Swiss Toolkit For WP <= 1.4.6 - Authenticated (Author+) Arbitrary File Upload via upload_extension_files()
    CVSS 8.8
    wpmessiah/Swiss Toolkit For WPgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  33. CVE-2026-15097Medium
    Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'height_slider' Slider Module Field
    CVSS 6.4
    themifyme/Themify Buildergeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 15, 2026View HOL analysis
  34. CVE-2026-7620Medium
    Notification for Telegram <= 3.5.1 - Missing Authorization to Authenticated (Subscriber+) Cron Modification via nftb_cron_action_set AJAX Action
    CVSS 4.3
    rainafarai/Notification for Telegramgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  35. CVE-2026-13114High
    Motors <= 1.4.112 - Unauthenticated Stored Cross-Site Scripting via Comment Content and User Biographical Info
    CVSS 7.2
    stylemix/Motors – Car Dealership & Classified Listings Plugingeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  36. CVE-2026-13353High
    WP Ultimate CSV Importer <= 8.0.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'MappedFields' Parameter
    CVSS 8.8
    smackcoders/WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excelgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  37. CVE-2026-7544Medium
    Mux Video Uploader <= 1.1.4 - Authenticated (Subscriber+) Information Exposure
    CVSS 4.3
    2coders/Mux Video Uploadergeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  38. CVE-2026-15072Medium
    KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in KCQueryBuilder
    CVSS 6.5
    iqonicdesign/KiviCare – Clinic & Patient Management System (EHR)generic
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  39. CVE-2026-15338High
    LA-Studio Element Kit for Elementor <= 1.6.1 - Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting
    CVSS 7.5
    choijun/LA-Studio Element Kit for Elementorgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 14, 2026View HOL analysis
  40. CVE-2026-12426Medium
    Members <= 3.2.22 - Unauthenticated Sensitive Information Disclosure via REST API Pagination Side Channel
    CVSS 5.3
    supercleanse/Members – Membership & User Role Editor Plugingeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 14, 2026View HOL analysis
  41. CVE-2026-3367Medium
    Lockme OAuth2 calendars integration <= 2.11.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'App ID' Setting
    CVSS 4.4
    lustmored/Lockme calendars integrationgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  42. CVE-2026-10628Medium
    Points and Rewards for WooCommerce <= 2.10.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions
    CVSS 4.3
    wpswings/Points and Rewards for WooCommercegeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2026-13262Medium
    Majestic Support <= 1.1.9 - Authenticated (Subscriber+) SQL Injection via 'val' Parameter
    CVSS 6.5
    ahmadmj/Majestic Support – The Leading-Edge Help Desk & Customer Support Plugingeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  44. CVE-2026-15073Medium
    KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in DoctorSessionController
    CVSS 6.5
    iqonicdesign/KiviCare – Clinic & Patient Management System (EHR)generic
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2026-5743Medium
    Mixed Media Gallery Blocks <= 3.3.3.1 - Authenticated (Author+) Stored Cross-Site Scripting via sliderMaxHeight Block Attribute
    CVSS 6.4
    gallerycreator/SimpLy Gallerygeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  46. CVE-2026-8678Medium
    MyParcel <= 4.25.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Data Disclosure and Modification via wcmp_get_shipment_options and wcmp_save_shipment_options AJAX Actions
    CVSS 4.3
    richardperdaan/MyParcelgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  47. CVE-2026-13756High
    WP Grid Builder <= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation via 'key' Parameter
    CVSS 8.8
    WP Grid Builder/WP Grid Buildergeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  48. CVE-2026-11426Medium
    UnderConstructionPage PRO <= 5.76 - Authenticated (Subscriber+) Arbitrary File Read via template_thumbnail Parameter
    CVSS 6.5
    WebFactory/Under Construction Page (Pro)generic
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  49. CVE-2026-14480Critical
    OpenPLC v3 External Control of File Name or Path
    CVSS 9.9
    OpenPLC/OpenPLCgeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  50. CVE-2026-44383High
    Hydro-Québec Le Circuit Electrique charging station backend Insufficient Session Expiration
    CVSS 7.5
    Hydro-Québec/Le Circuit Electrique charging station backendgeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
Page 73 of 327
Previous7172737475Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,456

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 3,601–3,650 of 16,339 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-1359High
    Genolve – AI image AI video generation <= 5.0.5 - Authenticated (Contributor+) Incorrect Authorization to Privilege Escalation via theopt
    CVSS 8.8
    genolve/Genolve – Genolve AI Business Graphics, AI Imagesgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  2. CVE-2026-15010Medium
    bbp style pack <= 6.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Topic Form Additional Fields
    CVSS 6.4
    robin-w/bbp style packgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  3. CVE-2026-10041Medium
    WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Vendor Data Manipulation via Multiple AJAX Handlers
    CVSS 4.3
    wclovers/WCFM – Frontend Manager for WooCommercegeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  4. CVE-2026-6939High
    CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Stored Cross-Site Scripting via 'approval_code' Parameter
    CVSS 7.2
    corvusinfo/CorvusPay WooCommerce Payment Gatewaygeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  5. CVE-2026-15155High
    Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection
    CVSS 8.8
    wpdevteam/Essential Addons for Elementor – Popular Elementor Templates & Widgetsgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 15, 2026View HOL analysis
  6. CVE-2026-12103Medium
    Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action
    CVSS 4.3
    subratamal/Wallet for WooCommercegeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  7. CVE-2026-12126Medium
    WCFM Marketplace <= 3.7.3 - Authenticated (Vendor+) Stored Cross-Site Scripting via Attachment 'post_title'
    CVSS 6.4
    wclovers/WCFM Marketplace – Multivendor Marketplace for WooCommercegeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  8. CVE-2026-4661High
    WP CTA <= 2.2.2 - Unauthenticated Time-Based Blind SQL Injection via 'fildname' Parameter
    CVSS 7.5
    blendmedia/WP CTA – Call Now Button, Sticky Button & Call to Action Buildergeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  9. CVE-2026-12994Medium
    WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manage Controller
    CVSS 5.3
    wclovers/WCFM – Frontend Manager for WooCommercegeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  10. CVE-2026-11591Medium
    Widgets for Google Reviews <= 13.3 - Authenticated (Editor+) Stored Cross-Site Scripting via 'fomo-title' and 'fomo-text' Parameters
    CVSS 4.4
    trustindex/Widgets for Google Reviewsgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  11. CVE-2026-1382Medium
    fresh Podcaster <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'freshpodcaster' Shortcode Attributes
    CVSS 6.4
    freshlabs/fresh Podcastergeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 14, 2026View HOL analysis
  12. CVE-2025-5017Medium
    Catalyst Connect Zoho CRM Client Portal <= 2.2.0 - Authenticated (Administrator+) SQL Injection via uid Parameter
    CVSS 4.9
    catalyst2020/Catalyst Connect Zoho CRM Client Portalgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 14, 2026View HOL analysis
  13. CVE-2026-6801Medium
    Context Blog <= 1.3.5 - Unauthenticated Sensitive Information Exposure via 'postID' Parameter
    CVSS 5.3
    postmagthemes/Context Bloggeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  14. CVE-2026-10865Medium
    Cost Calculator Builder <= 4.0.11 - Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys
    CVSS 5.3
    stylemix/Cost Calculator Buildergeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  15. CVE-2026-12738Medium
    WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Status Modification via wpep_draft_confirm AJAX Action
    CVSS 4.3
    saadiqbal/WP Easy Pay – Payment and Donation form Builder for Squaregeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  16. CVE-2026-11898Medium
    White Label CMS <= 2.7.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import Settings
    CVSS 4.4
    videousermanuals/White Label CMSgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 15, 2026View HOL analysis
  17. CVE-2025-6784High
    Code Engine <= 0.3.5 - Authenticated (Contributor+) Remote Code Execution
    CVSS 8.8
    tigroumeow/Code Engine – PHP Snippets, AI Functions & Automation for WordPressgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  18. CVE-2026-11901Medium
    WP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via PayPal IPN Handler
    CVSS 5.3
    thimpress/WP Hotel Bookinggeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 14, 2026View HOL analysis
  19. CVE-2026-13378High
    Form Vibes <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting via Contact Form 7 Form Field
    CVSS 7.2
    wpvibes/Form Vibes – Save Contact Form 7 & Elementor Form Entries to Databasegeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  20. CVE-2026-1832Medium
    ThriveDesk <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Cache Deletion
    CVSS 4.3
    thrivedesk/Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDeskgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  21. CVE-2026-14262High
    Simple JWT Login <= 3.6.6 - Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation via 'payload' Parameter
    CVSS 8.8
    nicu_m/Simple JWT Login – Allows you to use JWT on REST endpoints.generic
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  22. CVE-2026-15335High
    Booking Package <= 1.7.20 - Unauthenticated SQL Injection via 'email' Form Parameter
    CVSS 7.5
    masaakitanaka/Booking Packagegeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 14, 2026View HOL analysis
  23. CVE-2026-12141Medium
    Premium Addons for Elementor <= 4.11.84 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'premium_tooltip_text' Parameter
    CVSS 4.9
    leap13/Premium Addons for Elementor – Powerful Elementor Templates & Widgetsgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 14, 2026View HOL analysis
  24. CVE-2026-13250Medium
    Solace Extra <= 1.5.3 - Missing Authorization to Unauthenticated Arbitrary Content Deletion via delete_previously_imported AJAX Action
    CVSS 5.3
    solacewp/Solace Extrageneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  25. CVE-2026-7559Medium
    Affilia <= 3.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Status Modification
    CVSS 4.3
    redefiningtheweb/Affiliate Program & Referral Tracking for WooCommerce & WordPress – Affiliageneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  26. CVE-2026-15096Medium
    Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Module 'b_width_map' Field
    CVSS 6.4
    themifyme/Themify Buildergeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  27. CVE-2025-13968Medium
    Starboard Suite Reservation Calendars <= 3.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
    CVSS 6.4
    starboardsuite/Starboard Suite Reservation Calendarsgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 15, 2026View HOL analysis
  28. CVE-2026-13116Medium
    PDF Invoices & Packing Slips for WooCommerce <= 5.14.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'order_id' Shortcode Attribute
    CVSS 4.3
    wpovernight/PDF Invoices & Packing Slips for WooCommercegeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  29. CVE-2026-3576High
    Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter
    CVSS 7.2
    xtreeme/Planyo online reservation systemgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  30. CVE-2026-9738Medium
    Print, PDF, Email by PrintFriendly <= 5.5.10 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'content_position_css' Parameter
    CVSS 4.4
    printfriendly/Print, PDF & Email by PrintFriendlygeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  31. CVE-2026-3552Medium
    SurfLink < 2.6.0 - Missing Authorization to Authenticated (Subscriber+) 410 Gone URL Import via 'surfl_import_410' AJAX Action
    CVSS 4.3
    surflabtech/SurfLink – Link Manager & Backup Restoregeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  32. CVE-2026-2354High
    Swiss Toolkit For WP <= 1.4.6 - Authenticated (Author+) Arbitrary File Upload via upload_extension_files()
    CVSS 8.8
    wpmessiah/Swiss Toolkit For WPgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  33. CVE-2026-15097Medium
    Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'height_slider' Slider Module Field
    CVSS 6.4
    themifyme/Themify Buildergeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 15, 2026View HOL analysis
  34. CVE-2026-7620Medium
    Notification for Telegram <= 3.5.1 - Missing Authorization to Authenticated (Subscriber+) Cron Modification via nftb_cron_action_set AJAX Action
    CVSS 4.3
    rainafarai/Notification for Telegramgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  35. CVE-2026-13114High
    Motors <= 1.4.112 - Unauthenticated Stored Cross-Site Scripting via Comment Content and User Biographical Info
    CVSS 7.2
    stylemix/Motors – Car Dealership & Classified Listings Plugingeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  36. CVE-2026-13353High
    WP Ultimate CSV Importer <= 8.0.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'MappedFields' Parameter
    CVSS 8.8
    smackcoders/WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excelgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  37. CVE-2026-7544Medium
    Mux Video Uploader <= 1.1.4 - Authenticated (Subscriber+) Information Exposure
    CVSS 4.3
    2coders/Mux Video Uploadergeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  38. CVE-2026-15072Medium
    KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in KCQueryBuilder
    CVSS 6.5
    iqonicdesign/KiviCare – Clinic & Patient Management System (EHR)generic
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  39. CVE-2026-15338High
    LA-Studio Element Kit for Elementor <= 1.6.1 - Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting
    CVSS 7.5
    choijun/LA-Studio Element Kit for Elementorgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 14, 2026View HOL analysis
  40. CVE-2026-12426Medium
    Members <= 3.2.22 - Unauthenticated Sensitive Information Disclosure via REST API Pagination Side Channel
    CVSS 5.3
    supercleanse/Members – Membership & User Role Editor Plugingeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 14, 2026View HOL analysis
  41. CVE-2026-3367Medium
    Lockme OAuth2 calendars integration <= 2.11.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'App ID' Setting
    CVSS 4.4
    lustmored/Lockme calendars integrationgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  42. CVE-2026-10628Medium
    Points and Rewards for WooCommerce <= 2.10.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions
    CVSS 4.3
    wpswings/Points and Rewards for WooCommercegeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 15, 2026View HOL analysis
  43. CVE-2026-13262Medium
    Majestic Support <= 1.1.9 - Authenticated (Subscriber+) SQL Injection via 'val' Parameter
    CVSS 6.5
    ahmadmj/Majestic Support – The Leading-Edge Help Desk & Customer Support Plugingeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  44. CVE-2026-15073Medium
    KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in DoctorSessionController
    CVSS 6.5
    iqonicdesign/KiviCare – Clinic & Patient Management System (EHR)generic
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2026-5743Medium
    Mixed Media Gallery Blocks <= 3.3.3.1 - Authenticated (Author+) Stored Cross-Site Scripting via sliderMaxHeight Block Attribute
    CVSS 6.4
    gallerycreator/SimpLy Gallerygeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  46. CVE-2026-8678Medium
    MyParcel <= 4.25.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Data Disclosure and Modification via wcmp_get_shipment_options and wcmp_save_shipment_options AJAX Actions
    CVSS 4.3
    richardperdaan/MyParcelgeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  47. CVE-2026-13756High
    WP Grid Builder <= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation via 'key' Parameter
    CVSS 8.8
    WP Grid Builder/WP Grid Buildergeneric
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  48. CVE-2026-11426Medium
    UnderConstructionPage PRO <= 5.76 - Authenticated (Subscriber+) Arbitrary File Read via template_thumbnail Parameter
    CVSS 6.5
    WebFactory/Under Construction Page (Pro)generic
    PublishedJul 11, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  49. CVE-2026-14480Critical
    OpenPLC v3 External Control of File Name or Path
    CVSS 9.9
    OpenPLC/OpenPLCgeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026View HOL analysis
  50. CVE-2026-44383High
    Hydro-Québec Le Circuit Electrique charging station backend Insufficient Session Expiration
    CVSS 7.5
    Hydro-Québec/Le Circuit Electrique charging station backendgeneric
    PublishedJul 10, 2026First seen at HOL Jul 11, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
Page 73 of 327
Previous7172737475Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard