A vulnerability was found in Easy Digital Downloads version 3.6.9 and earlier. The vulnerability allows an administrator to delete arbitrary files, potentially leading to data loss or other security issues. This issue has a CVSS score of 4.9, indicating a medium severity level. The vulnerability is caused by a lack of proper validation in the Easy Digital Downloads plugin. Users of Easy Digital Downloads [truncated]
CVE-2026-52698 is a HIGH-severity vulnerability (CVSS Score: 7.4) in the PushEngage – Web Push Notifications, eCommerce Automation & Chat Widget plugin versions <= 4.2.3. This vulnerability exposes sensitive subscriber data. The issue was published on 2026-06-17 and last modified on 2026-06-17. Users of affected versions should take immediate action to mitigate potential risks. The vulnerability allows at [truncated]
A Missing Authorization vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects User Feedback: from n/a through <= 1.10.1. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. Users of Syed Balkhi User Feedback plugin for WordPress, especially those with version 1.10.1 or earlier, sh [truncated]
A SQL injection vulnerability was discovered in the User Feedback plugin for WordPress, affecting versions from n/a through 1.10.1. The vulnerability, tracked as CVE-2026-39475, allows for blind SQL injection attacks. This issue arises from improper neutralization of special elements used in an SQL command. The CVSS score for this vulnerability is 7.6, indicating a high severity. Users of the User Feedbac [truncated]