The CVE-2024-31435 vulnerability is a Missing Authorization issue in the Social Media & Share Icons WordPress plugin, affecting versions up to 2.8.6. This vulnerability allows attackers to exploit incorrectly configured access control security levels. The CVSS score for this vulnerability is 4.3, indicating a Medium severity. The vulnerability was published on June 17, 2026, and last modified on the same day.
CVE-2026-39480 is a HIGH severity vulnerability (CVSS Score: 7.5) in the Backup Migration plugin for WordPress, affecting versions up to and including 2.1.1. This vulnerability allows unauthenticated attackers to access sensitive data. The vulnerability was published on [cve-org](https://www.cve.org/CVERecord?id=CVE-2026-39480) and additional details can be found on [nvd](https://nvd.nist.gov/vuln/detail/ [truncated]
CVE-2026-53738 is a HIGH severity vulnerability in the Copy & Delete Posts plugin for WordPress. The plugin's cdp_action_handling AJAX handler allows any plugin-enabled non-admin role to invoke every operation, including deleting posts and overwriting plugin settings. This is possible due to a lack of per-function capability checks. The vulnerability has a CVSS score of 7.2 and was published on [cvePublis [truncated]