Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 19 February 2026
RSS391 vulnerabilities published on 19 February 2026
Severity:
Shopwell: Incorrect Access Control Exposes Sensitive Data
CVE-2026-25333
Shopwell's access control settings are not properly configured, allowing unauthorized access to sensitive data. This means that users may be able to view or modify data they shouldn't have access to. ...
5.3
Endless Posts Navigation Software Lacks Proper Access Control
CVE-2026-25332
The Endless Posts Navigation software has a flaw that could allow unauthorized access to certain features. This means someone might be able to do things they shouldn't be able to do, like accessing se...
5.3
Sensitive data exposed in rtMedia plugin for WordPress and BuddyPress
CVE-2026-25325
An issue in the rtMedia plugin for WordPress and BuddyPress allows unauthorized access to sensitive data. This affects versions up to 4.7.8. To stay secure, update the rtMedia plugin to the latest ver...
5.3
Quiz And Survey Master quiz-master-next Allows Unintended Access to Quiz Data
CVE-2026-25324
A security flaw in Quiz And Survey Master allows an attacker to access quiz data they shouldn't be able to see. This is a problem because it could allow someone to view sensitive information they shou...
5.3
SupportCandy: Unauthorized Access to Sensitive Data
CVE-2026-25321
A weakness in SupportCandy's access control allows attackers to access sensitive areas without permission. This affects SupportCandy versions up to 3.4.4. To protect your data, update to the latest ve...
5.3
Elementor Contact Form DB Missing Authorization Allows Unauthorized Access
CVE-2026-25320
An issue with Elementor Contact Form DB allows attackers to access and potentially steal sensitive data. If not addressed, this could lead to unauthorized access and data breaches. Update to version 2...
5.3
hCaptcha for WP: Unsecured Access to Sensitive Features
CVE-2026-25315
A security issue in hCaptcha for WordPress allows attackers to exploit weak access controls. This affects versions of hCaptcha for WordPress from version 1 to 4.22.0. To protect your site, update to t...
5.3
XStore Shopping Cart Software Allows Harmful Code Injection
CVE-2026-25006
A security issue in XStore shopping cart software allows hackers to inject malicious code into a website, potentially stealing or manipulating customer data. This affects XStore versions up to 9.6.4, ...
5.3
Incorrect Access Control in N-Media File Manager can let users access files they shouldn't
CVE-2026-25005
A security issue in the N-Media Frontend File Manager could allow users to access files they shouldn't have access to if access controls are not set up correctly. This affects a version of the N-Media...
5.3
Kraft Plugins Wheel of Life: Insecure Access Control
CVE-2026-25000
The Kraft Plugins Wheel of Life software does not properly control access to its features, which could allow an attacker to access data or perform actions they shouldn't. This is a serious issue becau...
5.3
Alma Gateway for WooCommerce: Incorrect Access Control Exposes Customer Data
CVE-2026-24999
A security issue in Alma Gateway for WooCommerce allows unauthorized users to access customer data if access control settings are not properly configured. This can lead to sensitive information being ...
5.3
Ultimate Gift Cards For WooCommerce: Unauthorized Access to Gift Cards
CVE-2026-24375
A security flaw in Ultimate Gift Cards For WooCommerce allows unauthorized users to access gift cards if access control settings are misconfigured. This can lead to users being able to redeem or modif...
5.3
DirectoryPress Security: Unauthorized Access to Configured Directories
CVE-2026-23548
A security weakness in DirectoryPress allows attackers to access sensitive areas of your website if access controls are not set up correctly. This affects versions of DirectoryPress up to 3.6.25. To s...
5.3
WPDeveloper Essential Addons for Elementor allows unauthorized access to sensitive settings
CVE-2026-23543
A security flaw in WPDeveloper's Essential Addons for Elementor plugin allows attackers to access sensitive settings if access control is not properly configured. This issue affects older versions of ...
5.3
Everest Forms: Malicious Code Can Be Injected into Web Pages
CVE-2026-22422
A security issue in Everest Forms allows attackers to inject malicious code into web pages, potentially allowing them to steal user data or take control of the site. This issue affects all versions of...
5.3
blst Library: Zero-Length Salt Triggers Crash
CVE-2026-2681
The blst library has a vulnerability that can cause a critical error if a program using it is given a special kind of input. This could potentially lead to a program crash, which would make the system...
5.3
Mega Store Woocommerce theme allows unauthorized site changes
CVE-2025-14357
The Mega Store Woocommerce theme has a security flaw that lets authorized users with limited access create or modify site pages and settings. This is a concern because it could be exploited by attacke...
5.3
Razorpay for WooCommerce lets unauthorized users change order details
CVE-2025-14294
The Razorpay for WooCommerce plugin on WordPress has a security flaw that allows anyone to change the email and phone number on any order without permission. This is a risk because attackers could use...
5.3
WooCommerce Checkout Field Manager plugin allows attackers to delete attachments
CVE-2025-13930
An attacker can delete attachments associated with guest orders without being authorized. This is a concern for online stores using the WooCommerce plugin. To fix, update to version 7.8.6 or later, or...
5.3
The Breeze WordPress Plugin Allows Unapproved Cache Clearing
CVE-2025-13864
The Breeze WordPress plugin has a security flaw that lets anyone clear your website's cache without permission. This means that an attacker could make your website seem broken or show incorrect inform...
5.3
WordPress Breadcrumb NavXT plugin exposes draft and private post information
CVE-2025-13842
The Breadcrumb NavXT plugin for WordPress allows unauthorized access to sensitive post information. This can happen if an attacker manipulates a specific parameter in the URL. To protect your site, up...
5.3
Sensitive data exposed by WordPress accessiBe plugin in all versions up to 2.11
CVE-2025-13113
The accessiBe plugin for WordPress exposes sensitive information, such as email addresses and license details, to anyone who views the website's browser console. This could lead to unauthorized access...
5.3
WordPress Popup Builder Plugin Allows Unauthorized Email Unsubscribes
CVE-2025-13079
A security flaw in the WordPress Popup Builder plugin allows hackers to remove people from email lists without permission. This can happen if the attacker knows the person's email address. To protect ...
5.3
WooCommerce Checkout Manager plugin allows attackers to upload files without login
CVE-2025-12500
The WooCommerce Checkout Manager plugin, used with WordPress, has a security flaw that lets attackers upload files to the server without needing a login. This means an attacker could potentially uploa...
5.3
QEMU: Sensitive data exposed or service crashes when processing VMDK files
CVE-2026-2243
A bug in QEMU can cause sensitive data to be leaked or the program to crash if it's given a specially crafted virtual disk image. This could potentially expose confidential information. Update QEMU to...
5.1