Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 19 February 2026
RSS391 vulnerabilities published on 19 February 2026
Severity:
UpsellWP: Insecure Access Control in Checkout Allows Unauthorized Actions
CVE-2026-25419
The UpsellWP plugin's checkout feature has a security issue that allows unauthorized access to certain areas. This could potentially allow an attacker to make changes to orders or access sensitive inf...
4.3
Blazethemes News Kit Elementor Addons: Unauthorized Access to Content
CVE-2026-25416
A security issue in News Kit Elementor Addons could allow unauthorized users to access content they shouldn't. This affects versions of the software up to 1.4.2. Users should update to a fixed version...
4.3
Revision Manager TMC allows unauthorized changes by attackers
CVE-2026-25411
A security weakness in Revision Manager TMC allows hackers to trick users into making unintended changes to the system. This can happen when a user clicks on a malicious link or submits a form on a we...
4.3
WP-CORS Plugin Missing Authorization, Unsecured Data Exposure
CVE-2026-25410
The WP-CORS plugin has a security bug that could allow unauthorized access to sensitive data. This affects WP-CORS plugin versions up to 0.2.2. To protect your site, update your plugin to the latest v...
4.3
Incorrect Access Control in JAMstack Deployments for WordPress
CVE-2026-25409
A security issue in JAMstack deployments for WordPress, including crgeary's wp-jamstack-deployments, allows attackers to access data they shouldn't. This affects sites using this plugin. To fix, updat...
4.3
Cookiebot Cookiebot: Unauthorized Access to Sensitive Data
CVE-2026-25407
Cookiebot Cookiebot has a security issue that allows unauthorized access to sensitive data. This affects Cookiebot versions 4.6.4 and earlier. To fix this, update to the latest version of Cookiebot.
4.3
echo-knowledge-base: Unauthorized Access to Sensitive Data
CVE-2026-25402
The echo-knowledge-base software has a security issue that allows unauthorized users to access sensitive information. This affects the Knowledge Base for Documentation, FAQs with AI Assistance. If not...
4.3
Serious Slider Security: Unauthorized Access to Configured Settings
CVE-2026-25399
The Serious Slider plugin has a security problem that allows unauthorized users to access and change settings. This means that someone might be able to make changes without permission, potentially cau...
4.3
Business Roy Configuration Error Lets Unapproved Users Access
CVE-2026-25395
A configuration mistake in Business Roy allows unauthorized users to access areas they shouldn't. This is a serious issue because it lets people who shouldn't have permission do things they shouldn't ...
4.3
Fitness FSE: Unauthorized Access to Sensitive Pages
CVE-2026-25394
The Fitness FSE plugin has a security flaw that could allow unauthorized users to access sensitive pages. This means that users who shouldn't have access might be able to view or edit information they...
4.3
Hello FSE Themes: Unprotected Access with Incorrect Security Settings
CVE-2026-25393
A security issue in Hello FSE themes allows unauthorized access to certain features. This affects versions of Hello FSE up to 1.0.6. To stay secure, update to the latest version of Hello FSE.
4.3
Elementor Image Optimizer on WordPress: Incorrect Access Control
CVE-2026-25387
A security weakness in Elementor's Image Optimizer plugin for WordPress allows unauthorized users to access and potentially exploit it if access controls are not properly set. This affects versions of...
4.3
Insecure Access Control in WP Chill Image Gallery
CVE-2026-25375
An issue in WP Chill Image Photo Gallery Final Tiles Grid allows attackers to access parts of the website they shouldn't. This affects the way access is controlled, potentially letting unauthorized us...
4.3
FooGallery: Unsecured Access to Sensitive Features
CVE-2026-25363
A security weakness in FooGallery allows attackers to access features they shouldn't, potentially leading to data exposure or unauthorized actions. This affects all versions of FooGallery up to 3.1.11...
4.3
Ays Pro Secure Copy Content Protection Has Weak Access Controls
CVE-2026-25335
Ays Pro Secure Copy Content Protection and Content Locking has a serious security weakness. If not set up correctly, attackers can access and alter protected content. Update to the latest version to f...
4.3
PublishPress Authors Security Flaw Allows Unauthorized Access
CVE-2026-25330
A security flaw in PublishPress Authors allows users to access restricted content without permission. This affects PublishPress Authors versions up to 4.10.1. To fix this, update to the latest version...
4.3
Quiz And Survey Master Quiz-master-next: Unauthorized Access to Quiz Data
CVE-2026-25329
A configuration error in Quiz And Survey Master's security settings allows unauthorized access to quiz data. This affects versions 1 through 10.3.4. To fix, update to a patched version of the software...
4.3
MiKa OSM osm: Insecure Access Control Allows Unauthorized Access
CVE-2026-25323
A security weakness in MiKa OSM osm allows attackers to access sensitive information or perform unauthorized actions if access control settings are not properly configured. This affects versions of Mi...
4.3
Unauthorized Actions on Zita Elementor Site Library Websites
CVE-2026-25319
A security issue affects Zita Elementor Site Library, a popular plugin for WordPress websites. If exploited, an attacker could trick a website owner into performing unintended actions, such as deletin...
4.3
WiserReview for WooCommerce: Unauthorized Access to Product Reviews
CVE-2026-25318
An issue with WiserReview for WooCommerce allows attackers to view or edit product reviews they shouldn't be able to access. This is a security risk because it means that unauthorized people can see o...
4.3
WP Messiah TOP Table Of Contents: Access Control Settings Error
CVE-2026-25314
A security issue in WP Messiah TOP Table Of Contents allows attackers to access restricted content. If not configured correctly, users with normal access levels can view content meant for admins or ot...
4.3
FluentForm Missing Authorization: Unauthorized Access to Configured Content
CVE-2026-25313
FluentForm has a security issue that allows an attacker to access content that should be restricted. If not configured properly, an attacker can gain access to sensitive information. Update to the lat...
4.3
Simple Membership: Exploiting Incorrect Security Settings Can Grant Unauthorized Access
CVE-2026-25308
A security flaw in Simple Membership software can allow users to access levels of the site they shouldn't be able to. This affects versions of Simple Membership up to 4.6.9. To protect your site, upda...
4.3
Ninja Tables: Sensitive Data Exposure through User Input
CVE-2026-25008
A security issue in Ninja Tables allows attackers to retrieve sensitive data that was embedded in user input. This means that if a user enters malicious data, it can be extracted and potentially used ...
4.3
Client Portal: Unauthorized Access to Restricted Data
CVE-2026-25003
The Client Portal software may allow unauthorized users to access sensitive data or perform actions they shouldn't be able to. This is because the access control settings are not properly configured. ...
4.3