|
341
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-39435
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-39441
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-39447
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in Contact Form to Any API <= 3.0.3 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-39449
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345
|
7.1 |
HIGH
Network
|
-
|
-
|
Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions.
New
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-39450
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider <= 18.0 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-39451
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <= 4.9.31 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-39463
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.
New
|
CWE-94
Code Injection
|
CVE-2026-39465
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versions.
New
|
CWE-22
Path Traversal
|
CVE-2026-39468
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350
|
7.2 |
HIGH
Network
|
-
|
-
|
Shop manager Privilege Escalation in WooCommerce Cart Abandonment Recovery < 2.1.0 versions.
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-39470
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|