Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 21 March 2026
RSS131 vulnerabilities published on 21 March 2026
Severity:
WebCTRL sends unencrypted sensitive data over the network
CVE-2026-24060
The WebCTRL system sends sensitive information, such as file position and data, without encryption when transmitting updates over the network. This means an unauthorized person with access to the netw...
9.1
Expire Users plugin for WordPress allows attackers to gain admin access
CVE-2026-4261
The Expire Users plugin for WordPress is not secure for users with Subscriber-level access and above. This means that attackers can gain full admin access to the website. To stay safe, update to a sec...
8.8
WordPress CMS Commander Plugin Exposes Sensitive Data
CVE-2026-3334
The CMS Commander plugin for WordPress has a security flaw that allows an attacker with a special key to access sensitive information from your database. This could happen if you're running a version ...
8.8
Linksy Search and Replace plugin for WordPress: Data Modification Risk
CVE-2026-2941
The Linksy Search and Replace plugin for WordPress, used in websites, can be exploited by attackers with subscriber-level access to modify any database table, including changing their own role to admi...
8.8
OpenClaw version 2026.3.1 and earlier: Authorized users can access sensitive settings
CVE-2026-32051
Authenticated users with certain permissions can access and control sensitive features in OpenClaw. This means that an attacker with the wrong level of access can still make changes they shouldn't be ...
8.7
OpenClaw Devices Can Access More Features Without Approval
CVE-2026-32042
OpenClaw devices running versions 2026.2.22 to 2026.2.24 are vulnerable to a security issue that allows unpaired devices to access more features than they should. This can happen if an attacker uses a...
8.7
MimeTypes Link Icons Plugin Leaks Internal Network Information
CVE-2026-1313
The MimeTypes Link Icons plugin for WordPress makes unauthorized requests to websites controlled by users with contributor-level access. This could allow hackers to access internal information and pot...
8.3
Invelity Product Feeds plugin for WordPress allows malicious file deletion
CVE-2025-14037
The Invelity Product Feeds plugin for WordPress is at risk of file deletion by hackers. If an administrator clicks on a malicious link, a hacker could delete any file on the server. To protect your si...
8.1
OpenClaw Sandbox Browser Allows Unauthenticated Access to VNC Interface
CVE-2026-32064
OpenClaw versions prior to 2026.2.21 have a security flaw that lets hackers access the browser without a password. This can happen when a hacker is on the same network as the computer running OpenClaw...
8.5
WebCTRL service impersonation risk from unauthorized port sharing
CVE-2026-25086
An attacker can impersonate the WebCTRL service if they can bind to the same port, potentially allowing them to send malicious packets. This could happen if the port is not properly secured. To protec...
7.7
OpenClaw versions prior to 2026.2.26 allow attackers to write files outside the workspace
CVE-2026-32055
Old versions of OpenClaw can be tricked into saving files in the wrong place, outside of the workspace, if an attacker creates a special kind of shortcut. This could allow an attacker to write sensiti...
7.2
Quentn WP Plugin Allows Hackers to Access WordPress Database
CVE-2026-2468
The Quentn WP plugin for WordPress has a security flaw that lets hackers access sensitive information from the database using a cookie. This means that even people who don't have an account can get ac...
7.5
Fonts Manager Custom Fonts Plugin Leaks Database Data
CVE-2026-1800
The Fonts Manager Custom Fonts plugin for WordPress allows hackers to steal sensitive information from the database without a password. This is because the plugin doesn't properly check user input, al...
7.5
OpenClaw versions fail to sanitize environment variables, allowing command bypass
CVE-2026-32056
Old versions of OpenClaw don't properly clean up environment variables, which could let attackers sneak in malicious code before security checks. This means an attacker could run unauthorized commands...
7.7
OpenClaw Media Buffer Overflow Vulnerability
CVE-2026-32049
Versions of OpenClaw prior to 2026.2.22 can be exploited by an attacker to cause memory issues and possible crashes. This is a concern for organizations using OpenClaw, as it could lead to system inst...
8.7
OpenClaw Sandbox Bypass in Pre-2026.3.1 Versions
CVE-2026-32048
Versions of OpenClaw before 2026.3.1 have a security flaw that allows a malicious user to bypass security restrictions when creating new processes. This could lead to unauthorized access and potential...
7.7
WebCTRL Systems Can Be Tricked by Fake BACnet Messages
CVE-2026-32666
WebCTRL systems can be vulnerable to fake messages sent over the network, potentially allowing an attacker to control certain devices or disrupt the system. This is because WebCTRL does not verify the...
7.5
WordPress Content Syndication Toolkit plugin allows attackers to make unauthorized web requests
CVE-2026-3478
The Content Syndication Toolkit plugin for WordPress has a security weakness that allows attackers to make unauthorized web requests to any website. This could be used to access sensitive information ...
7.2
Vagaro Booking Widget plugin for WordPress allows malicious scripts to run
CVE-2026-3003
The Vagaro Booking Widget plugin for WordPress has a security issue that allows hackers to inject malicious code into pages, which can be triggered when a user visits those pages. This can lead to una...
7.2
SurveyJS plugin for WordPress allows hackers to inject malicious code into admin panels
CVE-2026-2440
The SurveyJS plugin for WordPress is vulnerable to a security risk where hackers can inject malicious code into the admin panel when survey results are viewed. This can happen when an attacker submits...
7.2
WordPress myLinksDump Plugin Exposes Sensitive Data to Attackers
CVE-2026-2279
The myLinksDump WordPress plugin, used to manage links, is vulnerable to a security weakness that could allow attackers with administrator access to access sensitive information. This means that if an...
7.2
Performance Monitor plugin for WordPress allows attackers to target internal services
CVE-2026-1648
The Performance Monitor plugin for WordPress has a security flaw that lets attackers make requests to internal services. This could lead to sensitive data being accessed or systems being compromised. ...
7.2
WowOptin WordPress Plugin Allows Hackers to Control Server Actions
CVE-2026-4302
The WowOptin WordPress plugin exposes a security risk that allows hackers to make unauthorized requests to any website or server connected to the plugin, potentially stealing or modifying sensitive in...
7.2
Injection Guard Plugin for WordPress allows malicious scripts in admin logs
CVE-2026-3368
A security issue in the Injection Guard plugin for WordPress allows hackers to inject malicious scripts into the admin log page, which can be executed when an administrator views the log. This affects...
7.2
Discourse: Unauthenticated users can guess membership in private groups
CVE-2026-33425
Unauthenticated users can determine if a private group member exists, potentially compromising group confidentiality. This affects Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2...
6.9