[vulnfeed] 3 critical CVEs — 2026-07-08 04:00 UTC
vulnfeed
Critical alert — 2026-07-08 06:43 UTC
3 new critical CVEs
in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-9701CRITICAL
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to,
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of the password reset key in the
CVSS 9.8
CVE-2026-12153CRITICAL
The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inc
The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugin not properly verifying that a user is authorized
CVSS 9.8
CVE-2026-14487CRITICAL
The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fil
The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the removeUploadDir function in all versions up to, and including, 2.
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: