Vulnfeed

Archives
Log in
Subscribe
July 8, 2026

[vulnfeed] 3 critical CVEs — 2026-07-08 04:00 UTC

vulnfeed Critical alert — 2026-07-08 06:43 UTC
3 new critical CVEs in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-9701CRITICAL
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to,
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of the password reset key in the
CVSS 9.8
CVE-2026-12153CRITICAL
The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inc
The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugin not properly verifying that a user is authorized
CVSS 9.8
CVE-2026-14487CRITICAL
The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fil
The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the removeUploadDir function in all versions up to, and including, 2.
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 3 critical CVEs — 2026-07-08 08:00 UTC Older → [vulnfeed] 3 critical CVEs — 2026-07-08 00:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.