A critical SQL injection vulnerability, known as CVE-2026-54819, has been identified in the Listdom plugin, affecting versions from n/a through 5.4.0. This vulnerability, with a CVSS score of 9.3, allows attackers to perform blind SQL injection attacks. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the Listdom plugin are urged to take immediate action to mit [truncated]
CVE-2026-49063 is a HIGH severity vulnerability (CVSS Score: 7.3) affecting Listdom plugin versions <= 5.5.0. This vulnerability allows unauthenticated privilege escalation. The CVE was published on 2026-06-15T21:17:19.187Z and last modified on 2026-06-15T21:24:32.790Z.