Threats
CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.
| Score | CVE | Affected | EPSS | Published |
|---|---|---|---|---|
| 6.5 medium | CVE-2026-39798 | ThemetechMount TrueBooker Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions. | 0.25% | 6 Oct 2026 |
| 9.8 critical | CVE-2026-39797 | Data443 Risk Mitigation, Inc. GDPR Framework By Data443 Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions. | 0.34% | 6 Oct 2026 |
| 7.5 high | CVE-2026-39796 | Flipper Code – WordPress Development Company Advanced Posts Listing – Show Post List Easily Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions. | 0.30% | 6 Oct 2026 |
| 9.3 critical | CVE-2026-39795 | brewlabs SendPress Newsletters Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions. | 0.33% | 6 Oct 2026 |
| 7.5 high | CVE-2026-39794 | WC Lovers WooCommerce Multivendor Marketplace – REST API Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions. | 0.39% | 6 Oct 2026 |
| 8.8 high | CVE-2026-39793 | Nicu Micle Simple JWT Login Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions. | 0.42% | 6 Oct 2026 |
| 8.6 high | CVE-2026-39792 | Mitchell Bennis Simple File List Unauthenticated Arbitrary File Deletion in Simple File List <= 6.3.11 versions. | 0.36% | 6 Oct 2026 |
| 5.3 medium | CVE-2026-39791 | Mailjet Email Marketing Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions. | 0.25% | 6 Oct 2026 |
| 7.1 high | CVE-2026-39790 | e4jvikwp VikRentCar Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRentCar vikrentcar allows Reflected XSS.This issue affects VikRentCar: from n/a through 1.4.7. | 0.25% | 6 Oct 2026 |
| 6.5 medium | CVE-2026-39788 | Shamim Hasan Front End PM Subscriber Cross Site Scripting (XSS) in Front End PM <= 11.4.6 versions. | 0.22% | 6 Oct 2026 |
| 6.5 medium | CVE-2026-39787 | 10Web Social Photo Feed Unauthenticated Broken Access Control in 10Web Social Photo Feed <= 1.4.35 versions. | 0.29% | 6 Oct 2026 |
| 9.3 critical | CVE-2026-39785 | Serhii Pasyuk Gmedia Photo Gallery Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions. | 0.25% | 6 Oct 2026 |
| 7.1 high | CVE-2026-39784 | nicdark Hotel Booking Unauthenticated Cross Site Scripting (XSS) in Hotel Booking <= 3.8 versions. | 0.19% | 6 Oct 2026 |
| 7.1 high | CVE-2026-39781 | Dan Rossiter Document Gallery Unauthenticated Cross Site Scripting (XSS) in Document Gallery <= 5.1.1 versions. | 0.19% | 6 Oct 2026 |
| 7.1 high | CVE-2026-39780 | Youzify Unauthenticated Cross Site Scripting (XSS) in Youzify <= 1.3.7 versions. | 0.19% | 6 Oct 2026 |
| 7.1 high | CVE-2026-39778 | themeansar Ansar Import – One Click Starter Sites – for Elementor & Themes Unauthenticated Cross Site Scripting (XSS) in Ansar Import – One Click Starter Sites – for Elementor & Themes <= 2.1.2 versions. | 0.19% | 6 Oct 2026 |
| 8.0 high | CVE-2026-39776 | wpshopmart Tabs Editor Remote Code Execution (RCE) in Tabs <= 2.5 versions. | 0.38% | 6 Oct 2026 |
| 8.8 high | CVE-2026-39775 | DexignZone JobZilla - Job Board WordPress Theme Subscriber Privilege Escalation in JobZilla - Job Board WordPress Theme <= 2.2 versions. | 0.34% | 6 Oct 2026 |
| 8.8 high | CVE-2026-39774 | Tourfic AI Studio Tourfic Pro Unauthenticated Privilege Escalation in Tourfic Pro <= 1.17.3 versions. | 0.25% | 6 Oct 2026 |
| 10.0 critical | CVE-2026-39773 | AmentoTech Doctreat Core Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions. | 0.29% | 6 Oct 2026 |