Log inSign up
Log inSign up
CVE
252K posts
CVE profile banner
@CVEnew

CVE

@CVEnew
Official account maintained by the CVE™ Program to notify the community of new CVE IDs. Posts contain abbreviated details. Full CVE Records on cve.org
cveform.mitre.org
Joined January 2017
3 Following
58.1K Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @CVEnew
    CVE
    @CVEnew
    4h
    CVE-2026-105195 The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers… cve.org/CVERecord?id=C…
  • @CVEnew
    CVE
    @CVEnew
    4h
    CVE-2026-105196 The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, allowing an auth… cve.org/CVERecord?id=C…
  • @CVEnew
    CVE
    @CVEnew
    4h
    CVE-2026-105197 The Appointment Booking Plugin WordPress plugin before 5.6.5 does not verify that a backend staff user is authorized to act on the specific record targeted for del… cve.org/CVERecord?id=C…
  • @CVEnew
    CVE
    @CVEnew
    4h
    CVE-2026-105198 The Appointment Booking Plugin WordPress plugin before 5.7.3 does not verify that the caller owns the order referenced by an order-item identifier before rendering… cve.org/CVERecord?id=C…
  • @CVEnew
    CVE
    @CVEnew
    4h
    CVE-2026-105260 The Database Addon For WPForms ( wpforms entries ) WordPress plugin before 1.1.1 does not verify the CSRF nonce when the field is omitted and performs no capabilit… cve.org/CVERecord?id=C…