Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 11 April 2026
RSS42 vulnerabilities published on 11 April 2026
Severity:
BlockArt Blocks plugin for WordPress allows malicious script injection
CVE-2026-3498
The BlockArt Blocks plugin for WordPress is not properly filtering user input, which can allow attackers to inject malicious scripts into pages. This means that authorized users with administrative ac...
6.4
Optimole Plugin for WordPress Allows Attackers to Execute Malicious Code
CVE-2026-5226
The Optimole plugin for WordPress, used to optimize images, has a security flaw that could allow attackers to execute malicious code on your website. If a user clicks on a link that contains malicious...
6.1
Tutor LMS Plugin for WordPress: Unauthorized Course Enrollment in Private Courses
CVE-2026-3358
An attacker with Subscriber-level access or above can enroll in private courses without permission. This can be done by sending a specific request to the plugin. To fix this, update to a version of Tu...
5.4
OpenClaw Client Credentials Exposed Through OAuth Authorization
CVE-2026-3691
An attacker can obtain stored credentials for OpenClaw installations by manipulating an OAuth authorization flow. This can happen when a user initiates the flow on their own, allowing an attacker to a...
5.3
UsersWP Plugin Allows Attackers to Hijack WordPress Server Requests
CVE-2026-4979
A weakness in the UsersWP plugin for WordPress lets attackers trick the server into making unauthorized requests to other websites or internal systems, potentially exposing sensitive data. This affect...
5.0
Tutor LMS Plugin for WordPress Allows Unauthorized Access to Course Content
CVE-2026-3371
An attacker with a basic user account can reorder course content and reassign lessons for any course, including those owned by administrators. This can occur through a specific type of malicious reque...
4.3
Flatpak allows malicious apps to delete any file on the computer
CVE-2026-40354
A security issue in Flatpak's file management system allows malicious apps to delete any file on the host computer. This could allow hackers to delete important system or user files, potentially causi...
2.9
CGA-3wh4-q833-xff6
CGA-3wh4-q833-xff6
CGA-8qgr-x76h-39pw
CGA-8qgr-x76h-39pw
CGA-2fmw-fc3p-8vp3
CGA-2fmw-fc3p-8vp3
CGA-96ph-rhp8-7jgh
CGA-96ph-rhp8-7jgh
CGA-96ph-rhp8-7jgh
CGA-9v96-6p33-r65p
CGA-9v96-6p33-r65p
CGA-9v96-6p33-r65p
CGA-5gcx-5c97-r5wr
CGA-5gcx-5c97-r5wr
CGA-5gcx-5c97-r5wr
Apache HTTP Server Remote Code Execution Vulnerability
CGA-hjr7-vxf9-rgpc
A security weakness in Apache's HTTP Server software allows hackers to inject and execute malicious code on a server. This could allow an attacker to take control of a server or steal sensitive inform...