|
491
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49105
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
492
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49106
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
493
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49109
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
494
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.
New
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-49110
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
495
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.
New
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2026-49112
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
496
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49763
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
497
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.
New
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-49764
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
498
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49765
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
499
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.
New
|
CWE-22
Path Traversal
|
CVE-2026-49766
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
500
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49768
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|