|
2801
|
8.8 |
HIGH
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in BoldGrid weForms weforms allows Object Injection.This issue affects weForms: from n/a through <= 1.6.26.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32484
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2802
|
8.8 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en BoldGrid weForms weforms permite la inyección de objetos. Este problema afecta a weForms: desde n/a hasta <= 1.6.26.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32484
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2803
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a t…
|
CWE-862
Missing Authorization
|
CVE-2026-32485
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2804
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad por ausencia de autorización en weDevs WP User Frontend wp-user-frontend permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a…
|
CWE-862
Missing Authorization
|
CVE-2026-32485
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2805
|
8.1 |
HIGH
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalation.This issue affects User Registration: from n/a through <= 4.4.9.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-32488
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2806
|
8.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Asignación Incorrecta de Privilegios en wpeverest User Registration user-registration permite la escalada de privilegios. Este problema afecta a User Registration: desde n/a hasta &…
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-32488
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2807
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in bPlugins B Blocks b-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects B Blocks: from n/a through < 2.0.30.
|
CWE-862
Missing Authorization
|
CVE-2026-32489
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2808
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de Autorización Faltante en bPlugins B Blocks b-blocks permite la Explotación de Niveles de Seguridad de Control de Acceso Incorrectamente Configurados. Este problema afecta a B Blocks…
|
CWE-862
Missing Authorization
|
CVE-2026-32489
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2809
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgwhite33 WP TripAdvisor Review Slider wp-tripadvisor-review-slider allows Stored XSS.This issue …
|
CWE-79
Cross-site Scripting
|
CVE-2026-32490
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2810
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en jgwhite33 WP TripAdvisor Review Slider wp-tripadvisor-review-slider permite XSS…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32490
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2811
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgwhite33 WP Review Slider wp-facebook-reviews allows Stored XSS.This issue affects WP Review Sli…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32491
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2812
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en jgwhite33 WP Review Slider wp-facebook-reviews permite XSS Almacenado. Este pro…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32491
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2813
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Authentication Bypass by Spoofing vulnerability in Joe Dolson My Tickets my-tickets allows Identity Spoofing.This issue affects My Tickets: from n/a through <= 2.1.1.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-32492
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2814
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de omisión de autenticación por suplantación en Joe Dolson My Tickets my-tickets permite la suplantación de identidad. Este problema afecta a My Tickets: desde n/a hasta <= 2.1.1.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-32492
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2815
|
- |
-
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Reflected XSS.This issue affects JobSearch: from n/a through…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32493
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2816
|
- |
-
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en eyecix JobSearch wp-jobsearch permite XSS Reflejado. Este problema afecta a Job…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32493
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2817
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Image Slider by Ays ays-slider allows Exploiting Incorrectly Configured Access Control Se…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32494
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2818
|
7.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('Cross-site Scripting') en Ays Pro Image Slider de Ays ays-slider permite la Explotación de Niveles de …
|
CWE-79
Cross-site Scripting
|
CVE-2026-32494
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2819
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in Link Software LLC WP Terms Popup wp-terms-popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Terms Popup: from …
|
CWE-862
Missing Authorization
|
CVE-2026-32495
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2820
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en Link Software LLC WP Terms Popup wp-terms-popup permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este probl…
|
CWE-862
Missing Authorization
|
CVE-2026-32495
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2821
|
6.7 |
MEDIUM
Network
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NYSL Spam Protect for Contact Form 7 wp-contact-form-7-spam-blocker allows Path Traversal.This issue af…
|
CWE-22
Path Traversal
|
CVE-2026-32496
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2822
|
6.7 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de limitación incorrecta de un nombre de ruta a un directorio restringido ('Salto de ruta') en NYSL Spam Protect para Contact Form 7 wp-contact-form-7-spam-blocker permite el salto de …
|
CWE-22
Path Traversal
|
CVE-2026-32496
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2823
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Weak Authentication vulnerability in PickPlugins User Verification user-verification allows Authentication Abuse.This issue affects User Verification: from n/a through <= 2.0.45.
|
CWE-1390
Weak Authentication
|
CVE-2026-32497
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2824
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de autenticación débil en PickPlugins User Verification user-verification permite el abuso de autenticación. Este problema afecta a User Verification: desde n/a hasta <= 2.0.45.
|
CWE-1390
Weak Authentication
|
CVE-2026-32497
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2825
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorrectly Configured Access Control Security Levels.Thi…
|
CWE-862
Missing Authorization
|
CVE-2026-32498
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2826
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Falta de Autorización en Metagauss RegistrationMagic constructor de formularios de registro personalizados con gestor de envíos permite Explotar Niveles de Seguridad de Control de A…
|
CWE-862
Missing Authorization
|
CVE-2026-32498
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2827
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatBot chatbot allows Blind SQL Injection.This issue affects ChatBot: from n/a thro…
|
CWE-89
SQL Injection
|
CVE-2026-32499
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2828
|
9.3 |
CRITICAL
Network
|
-
|
-
|
La vulnerabilidad de Neutralización Inadecuada de Elementos Especiales utilizados en un Comando SQL ('Inyección SQL') en el chatbot QuantumCloud ChatBot permite Inyección SQL Ciega. Este problema afe…
|
CWE-89
SQL Injection
|
CVE-2026-32499
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2829
|
8.1 |
HIGH
Network
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS MetaMax metamax allows PHP Local File Inclusion.This issue affects …
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32500
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2830
|
8.1 |
HIGH
Network
|
-
|
-
|
Control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP ('Inclusión Remota de Ficheros PHP') vulnerabilidad en CreativeWS MetaMax metamax permite la Inclusión …
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32500
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2831
|
7.1 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in wp-configurator WP Configurator Pro wp-configurator-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Configurat…
|
CWE-862
Missing Authorization
|
CVE-2026-32501
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2832
|
7.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en wp-configurator WP Configurator Pro wp-configurator-pro permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este proble…
|
CWE-862
Missing Authorization
|
CVE-2026-32501
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2833
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object Injection.This issue affects Borgholm: from n/a through < 1.6.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32502
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2834
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Select-Themes Borgholm borgholm-marketing-agency-theme permite la inyección de objetos. Este problema afecta a Borgholm: desde n/a hasta &l…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32502
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2835
|
8.1 |
HIGH
Network
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS Trendustry trendustry allows PHP Local File Inclusion.This issue af…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32503
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2836
|
8.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de control inadecuado del nombre de fichero para la declaración include/require en el programa PHP ('inclusión remota de ficheros PHP') en CreativeWS Trendustry trendustry permite la i…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32503
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2837
|
8.1 |
HIGH
Network
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS VintWood vintwood allows PHP Local File Inclusion.This issue affect…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32504
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2838
|
8.1 |
HIGH
Network
|
-
|
-
|
Control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP (vulnerabilidad de 'Inclusión remota de ficheros PHP') en CreativeWS VintWood vintwood permite la Inclu…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32504
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2839
|
8.1 |
HIGH
Network
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS Kiddy kiddy allows PHP Local File Inclusion.This issue affects Kidd…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32505
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2840
|
8.1 |
HIGH
Network
|
-
|
-
|
Control inadecuado del nombre de fichero para la declaración include/require en un programa PHP (vulnerabilidad de 'inclusión remota de ficheros PHP') en CreativeWS Kiddy kiddy permite la inclusión l…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32505
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2841
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Edge-Themes Archicon archicon allows Object Injection.This issue affects Archicon: from n/a through < 1.7.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32506
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2842
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Edge-Themes Archicon archicon permite la inyección de objetos. Este problema afecta a Archicon: desde n/a hasta < 1.7.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32506
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2843
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Elated-Themes Leroux leroux allows Object Injection.This issue affects Leroux: from n/a through < 1.4.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32507
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2844
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Elated-Themes Leroux leroux permite la inyección de objetos. Este problema afecta a Leroux: desde n/a hasta < 1.4.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32507
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2845
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Mikado-Themes Halstein halstein allows Object Injection.This issue affects Halstein: from n/a through < 1.8.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32508
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2846
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Mikado-Themes Halstein halstein permite la inyección de objetos. Este problema afecta a Halstein: desde n/a hasta < 1.8.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32508
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2847
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Edge-Themes Gracey gracey allows Object Injection.This issue affects Gracey: from n/a through < 1.4.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32509
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2848
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Edge-Themes Gracey gracey permite la inyección de objetos. Este problema afecta a Gracey: desde n/a hasta < 1.4.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32509
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2849
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Edge-Themes Kamperen kamperen allows Object Injection.This issue affects Kamperen: from n/a through < 1.3.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32510
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2850
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Edge-Themes Kamperen kamperen permite la inyección de objetos. Este problema afecta a Kamperen: desde n/d hasta < 1.3.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32510
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|