CVE-2026-57786 is a Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core. The issue affects WorkScout-Core from n/a through <= 1.7.08. The vulnerability has a CVSS score of 8.8 and a severity of HIGH. This type of vulnerability could allow an attacker to perform actions on behalf of a user without their consent, potentially leading to unauthorized changes or data bre [truncated]
CVE-2026-52716 is a medium-severity vulnerability (CVSS Score: 6.5) affecting WorkScout-Core versions <= 1.7.11. The vulnerability allows unauthenticated attackers to delete arbitrary files. Published on June 17, 2026, by the CVE Program, this vulnerability has not been associated with any ransomware campaigns. Users of affected versions should take immediate action to mitigate the risk.
The Listeo Core plugin for WordPress has a vulnerability that allows unauthenticated arbitrary media uploads. This issue affects all versions up to and including 2.0.27 and is caused by missing authorization and capability checks on the AJAX endpoint handling file uploads. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Administrators of WordPress sites using the Listeo Cor [truncated]