Known Vulnerabilities for WP Private Content Plus by Nimeshrmr

Listed below are 10 of the newest known vulnerabilities associated with "WP Private Content Plus" by "Nimeshrmr".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-104960 json Plane is an open-source project management tool. Prior to 1.4.0, Plane exposes the workspace-scoped GET /api/assets/v2/worksp... Not Provided 2026-10-05 2026-10-05
CVE-2026-104469 json YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because... Not Provided 2026-10-02 2026-10-06
CVE-2026-103059 json When Gitea's built-in SSH server is enabled (`START_SSH_SERVER = true`), the presented public key was looked up with an SQL `... Not Provided 2026-10-06 2026-10-06
CVE-2026-100853 json In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allowing u... Not Provided 2026-09-27 2026-09-28
CVE-2026-100708 json Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in th... Not Provided 2026-09-26 2026-09-28
CVE-2026-100668 json Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its identical function form) is on t... Not Provided 2026-09-26 2026-09-28
CVE-2026-96526 json The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of it... Not Provided 2026-09-26 2026-09-26
CVE-2026-93507 json The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-clon... Not Provided 2026-09-23 2026-09-23
CVE-2026-93365 json Bludit CMS through 3.22.0 contains a missing authorization vulnerability that allows authenticated users holding the Author o... Not Provided 2026-09-25 2026-09-25
CVE-2026-92917 json Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and seria... Not Provided 2026-09-17 2026-09-19

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report