AJAX

Privilege Escalation in User Registration & Membership

Versions of User Registration & Membership up to 5.1.2 let unauthenticated attackers create administrator accounts via an unguarded AJAX endpoint.

27 June 2026

Read more

Booking Manipulation in WP Travel Engine

CVE-2026-49078: WP Travel Engine ≤6.7.10 lets unauthenticated attackers create fraudulent bookings and access customer data via AJAX endpoints with non-fatal nonce validation.

22 June 2026

Read more

Information Disclosure in Advanced Custom Fields

CVE-2026-4812: ACF 6.7.0 and earlier let unauthenticated attackers leak internal post, user, and relationship data by manipulating AJAX query parameters.

16 June 2026

Read more

Vendor IDOR in WCFM Frontend Manager for WooCommerce

WCFM Frontend Manager for WooCommerce is the dashboard lots of multi-vendor marketplaces sit on top of. It gives each vendor a front-end area to manage their own products, orders and content without ever touching wp-admin. Versions up to and including 6.7.25 had a set of matching authorisation bugs in that dashboard that let any logged-in vendor reach well beyond their own shop. CVE-2026-4896 covers the lot.

6 April 2026

Read more

Missing Authorisation in Product Filter for WooCommerce Lets Anyone Delete Your Filter Data

Product Filter for WooCommerce: unauthorised attackers can delete all filter configurations. Learn about CVE-2026-3138 and protect your store now.

2 April 2026

Read more

Unauthenticated Privilege Escalation in User Registration plugin

There's a critical unauthenticated privilege escalation vulnerability in the User Registration & Membership WordPress plugin.

31 March 2026

Read more