CVE-2026-28140 is an unauthenticated broken access control vulnerability in JetFormBuilder plugin versions up to 3.6.4.1. This vulnerability has a CVSS score of 7.5 and is considered HIGH severity. The CVE record was published on 2026-08-06T15:16:52.707Z and has not been modified since then. Affected users should prioritize patching to prevent potential unauthorized access. The vulnerability allows attack [truncated]
CVE-2026-54196 is a medium-severity vulnerability (CVSS Score: 6.8) affecting JetFormBuilder versions <= 3.6.1. This issue allows subscribers to escalate their privileges. The vulnerability was published on 2026-06-17T13:20:50.960Z and last modified on 2026-06-17T14:44:26.397Z. Users of affected versions should take immediate action to mitigate potential risks. The CVE record and NVD detail provide furthe [truncated]
CVE-2026-54195 is a HIGH severity vulnerability in JetFormBuilder versions <= 3.6.0.1. It allows unauthenticated Cross Site Scripting (XSS) attacks. The CVSS score is 7.1. The vulnerability was published on 2026-06-17T13:20:50.820Z and last modified on 2026-06-17T17:17:26.393Z. Users of affected versions should take immediate action to mitigate the risk.
The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference (IDOR) in all versions up to and including 2.4.16. The vulnerability exists in the `action_get_event_data` functionality, which fails to validate user-controlled keys. Authenticated attackers with contributor-level access or higher can enumerate timeslot IDs and retrieve complete WP_Post ob [truncated]
The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite or delete the internal notes (_mphb_booking_internal_notes) of any booking by supplying an arbitrary booking ID. [truncated]