Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 8 April 2026
RSS673 vulnerabilities published on 8 April 2026
Severity:
Blackfyre: Malicious Requests Can Be Sent on Your Behalf
CVE-2026-39641
A security weakness in Blackfyre software allows an attacker to trick users into performing actions without their knowledge or consent. This issue affects Blackfyre versions from an unknown version up...
6.5
RPS Include Content: Unauthorized Access via Incorrect Security Settings
CVE-2026-39639
If not set properly, the RPS Include Content plugin can be accessed by unauthorized users, potentially allowing them to view sensitive information. This issue affects RPS Include Content versions 1.2....
6.5
Grand Car Rental: Unapproved Actions Can Be Tricked into Occurring
CVE-2026-39633
The Grand Car Rental website is vulnerable to a security issue known as Cross-Site Request Forgery. This means that an attacker could trick someone into doing something they didn't intend to do on the...
6.5
WP Blockade plugin on WordPress allows attackers to run malicious shortcodes
CVE-2026-3480
The WP Blockade plugin for WordPress is affected by a security issue that could let an attacker with a Subscriber-level account or above execute malicious shortcodes, potentially leading to informatio...
6.5
WWBN AVideo: Authenticated SSRF via Stored Callback URL
CVE-2026-39368
GHSA-q4x6-6mm2-crg9
An attacker-controlled URL is stored on the WWBN AVideo server, which can be used to make unauthorized requests to internal services. This affects authenticated streamers in versions 26.0 and prior. T...
6.5
AVideo PayPal Payment Handler Allows Malicious Transaction Replay
CVE-2026-39366
GHSA-mmw7-wq3c-wf9p
AVideo's outdated PayPal payment handler in versions 26.0 and prior can be exploited by attackers to inflate their wallet balance and renew subscriptions repeatedly. This is caused by a lack of transa...
6.5
WordPress Post Blocks & Tools plugin allows malicious scripts on pages
CVE-2026-5711
The Post Blocks & Tools plugin for WordPress has a security flaw that allows attackers to inject malicious scripts on pages. This means that if an attacker has permission to edit a page, they can add ...
6.4
WordPress Pagelayer Plugin Allows Hackers to Inject Malicious Code
CVE-2026-2509
A security flaw in the Pagelayer plugin for WordPress allows attackers with high-level access to inject malicious code into pages. This can happen when a user visits the affected page. To fix this iss...
6.4
Red Hat Process Automation Manager container allows non-root users to gain root access
CVE-2025-58713
Non-root users in certain Red Hat Process Automation Manager containers can gain full root access, allowing them to perform any action within the container. This happens when a user in the root group ...
6.4
OpenShift Update Service images allow non-root users to gain root access
CVE-2025-57854
Certain OpenShift Update Service images create a file with weak permissions, allowing a non-root user to gain full control of the container by adding themselves as a root user. To fix this, users shou...
6.4
Web Terminal images allow non-root users to gain full control
CVE-2025-57853
Non-root users in certain Web Terminal images can exploit a flaw to gain complete control over the container. This is because the /etc/passwd file was created with permissions that allow non-root user...
6.4
Multicluster Engine for Kubernetes: Unauthorized Access to Root Privileges
CVE-2025-57851
Certain Multicluster Engine for Kubernetes images have a security issue that allows an attacker to gain full control of a container. This occurs when an attacker can modify the /etc/passwd file, which...
6.4
Ansible Automation Platform images can be hijacked by non-root users
CVE-2025-57847
Certain Ansible images have a security flaw that allows a non-root user to gain full control of the container by manipulating the /etc/passwd file, potentially allowing unauthorized access to sensitiv...
6.4
Beaver Builder Plugin Allows Malicious Code Injection
CVE-2026-2481
The Beaver Builder plugin for WordPress has a security flaw that lets attackers inject malicious code into website pages. This could allow an attacker to take control of a website's content or steal u...
6.4
WordPress WP Visitor Statistics plugin allows attackers to inject malicious scripts
CVE-2026-4303
The WP Visitor Statistics plugin for WordPress has a security weakness that allows authorized users to inject malicious scripts into certain pages. This can happen if a contributor or higher-level use...
6.4
Malicious code can execute when using Robo Gallery plugin with WordPress
CVE-2026-4300
The Robo Gallery plugin for WordPress has a security flaw that allows attackers to inject malicious code into web pages. This can happen when an authenticated user with author-level access or above cr...
6.4
pdfl.io WordPress Plugin Allows Hackers to Inject Malicious Code
CVE-2026-4073
The pdfl.io plugin for WordPress has a security flaw that allows attackers to inject malicious code into web pages. This can happen if a website using the plugin allows users with certain access level...
6.4
PrivateContent Free plugin for WordPress allows attackers to inject malicious scripts
CVE-2026-4025
An attacker with Contributor-level access and above can inject malicious scripts into the PrivateContent Free plugin for WordPress, which can execute when a user accesses the affected page. This is du...
6.4
Magic Conversation For Gravity Forms Plugin Allows Malicious Code Injection
CVE-2026-1396
The Magic Conversation For Gravity Forms plugin for WordPress is vulnerable to a security flaw that allows attackers to inject malicious code into pages. This could happen if an authenticated user wit...
6.4
Element Pack Addons for Elementor plugin allows malicious SVG files to inject code
CVE-2026-4655
The Element Pack Addons for Elementor plugin has a security risk that allows attackers to inject malicious code into SVG files. This can happen if an attacker with contributor-level access uploads a m...
6.4
WowPress Plugin for WordPress: Malicious Code Injection via Shortcode
CVE-2026-5508
A security weakness in the WowPress plugin for WordPress allows attackers to inject malicious code into certain pages, which can harm users who visit those pages. This affects all versions of the plug...
6.4
Wavr plugin for WordPress allows attackers to inject malicious scripts
CVE-2026-5506
The Wavr plugin for WordPress is insecure, allowing attackers to inject malicious scripts into pages, which can execute when users access those pages. This affects all versions up to and including 0.2...
6.4
Sports Club Management plugin for WordPress: Stored Cross-Site Scripting
CVE-2026-4871
An attacker with contributor access can inject malicious scripts into pages that are accessed by other users, potentially allowing them to steal data or take control of user sessions. This affects all...
6.4
Columns by BestWebSoft plugin for WordPress allows attackers to inject malicious scripts
CVE-2026-3618
The Columns by BestWebSoft plugin for WordPress is at risk because an attacker with admin-level access can inject malicious code into pages that will be executed when visited. This can happen if an ad...
6.4
Pinterest Site Verification plugin for WordPress allows attackers to inject scripts
CVE-2026-3142
The Pinterest Site Verification plugin for WordPress, used in versions up to 1.8, has a security flaw that allows an attacker to inject malicious code into a website. This can harm users who visit the...
6.4