SQL injection flaw in Ally WordPress plugin exposes 200,000+ sites to data theft. Patch released, but most installations remain unpatched and vulnerable.
A vulnerability was found in wppochipp Pochipp Plugin up to 1.18.9 on WordPress and classified as critical. This vulnerability affects unknown code. Executing a manipulation can lead to missing authorization.
The identification of this vulnerability is CVE-2026-32417. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability has been found in Maciej Bis Permalink Manager Lite Plugin up to 2.5.3 on WordPress and classified as critical. This affects an unknown part. Performing a manipulation results in missing authorization.
This vulnerability was named CVE-2026-32413. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
A vulnerability, which was classified as critical, was found in vowelweb VW Education Lite Plugin up to 2.2.0 on WordPress. Affected by this issue is some unknown functionality. Such manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2026-32427. The attack can be launched remotely. No exploit exists.
A vulnerability, which was classified as critical, has been found in linknacional Payment Gateway Pix for GiveWP Plugin up to 2.2.3 on WordPress. Affected by this vulnerability is an unknown functionality. This manipulation causes missing authorization.
This vulnerability is handled as CVE-2026-32425. The attack can be initiated remotely. There is not any exploit available.
A vulnerability classified as critical was found in Bowo Admin and Site Enhancements Plugin up to 8.4.0 on WordPress. Affected is an unknown function. The manipulation results in missing authorization.
This vulnerability is known as CVE-2026-32423. It is possible to launch the attack remotely. No exploit is available.
A vulnerability classified as critical has been found in Agile Logix Post Timeline Plugin up to 2.4.1 on WordPress. This impacts an unknown function. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2026-32421. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability described as critical has been identified in themefusecom Brizy Plugin up to 2.7.23 on WordPress. This affects an unknown function. Executing a manipulation can lead to missing authorization.
This vulnerability appears as CVE-2026-32408. The attack may be performed from remote. There is no available exploit.
A vulnerability marked as critical has been reported in Ays Pro Image Slider Plugin up to 2.7.1 on WordPress. The impacted element is an unknown function. Performing a manipulation results in missing authorization.
This vulnerability is reported as CVE-2026-32402. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability labeled as problematic has been found in xtemos WoodMart Plugin up to 8.3.9 on WordPress. The affected element is an unknown function. Such manipulation leads to exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is documented as CVE-2026-32405. The attack can be executed remotely. There is not any exploit available.
A vulnerability identified as critical has been detected in RadiusTheme Team Plugin up to 5.0.13 on WordPress. Impacted is an unknown function. This manipulation causes missing authorization.
This vulnerability is registered as CVE-2026-32396. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability categorized as critical has been discovered in Studio99 WP Monitor Plugin up to 1.0.3 on WordPress. This issue affects some unknown processing. The manipulation results in missing authorization.
This vulnerability is cataloged as CVE-2026-32404. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in David Lingren Media LIbrary Assistant Plugin up to 3.32 on WordPress. It has been rated as critical. This vulnerability affects unknown code. The manipulation leads to sql injection.
This vulnerability is listed as CVE-2026-32399. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in YMC Filter & Grids Plugin up to 3.5.1 on WordPress. It has been declared as critical. This affects an unknown part. Executing a manipulation can lead to missing authorization.
This vulnerability is tracked as CVE-2026-32397. The attack can be launched remotely. No exploit exists.
A vulnerability was found in Xpro Addons for Beaver Builder Plugin up to 1.5.6 on WordPress. It has been classified as critical. Affected by this issue is some unknown functionality. Performing a manipulation results in missing authorization.
This vulnerability is identified as CVE-2026-32395. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in linethemes SmartFix Plugin up to 1.2.4 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality. Such manipulation leads to missing authorization.
This vulnerability is referenced as CVE-2026-32391. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability has been found in linethemes Nanosoft Plugin up to 1.3.2 on WordPress and classified as critical. Affected is an unknown function. This manipulation causes missing authorization.
The identification of this vulnerability is CVE-2026-32390. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability, which was classified as critical, was found in Noor Alam Checkout for PayPal Plugin up to 1.0.46 on WordPress. This impacts an unknown function. The manipulation results in missing authorization.
This vulnerability was named CVE-2026-32387. The attack may be performed from remote. There is no available exploit.
A vulnerability, which was classified as critical, has been found in raratheme Kalon Plugin up to 1.2.9 on WordPress. This affects an unknown function. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2026-32376. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability classified as critical was found in raratheme Travel Diaries Plugin up to 1.2.4 on WordPress. The impacted element is an unknown function. Executing a manipulation can lead to missing authorization.
This vulnerability is handled as CVE-2026-32375. The attack can be executed remotely. There is not any exploit available.