39 CVEs published June 6, 2026: 0 critical, 7 high, 26 medium, 6 low; 0 in KEV; 0 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 14 in the results table.
Yesterday's Results
39 CVEs published. 25 box scores, 14 table rows — nothing truncated.
wpdevteam Essential Addons for Elementor – Popular Elementor Templates & Widgets — Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U L N N 5.3 .0724 93.8 —
AFFECTED
Product Versions Fixed
Essential Addons for Elementor – Popular Elementor Templates & Widgets unspecified —
TIMELINE
May 1 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
GL.iNet MT3000 OpenVPN Client Import Workflow ovpnclient.sh command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0123 66.4 —
AFFECTED
Product Versions Fixed
MT3000 4.4.0 – 4.9.0_beta3-1012-0513-1778656146
TIMELINE
Jun 5 Reserved by CNA
Jun 6 Published (CNA: VulDB)
vertex-app vertex Log Viewer Endpoint LogMod.js os command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0111 63.3 —
AFFECTED
Product Versions Fixed
vertex 2026.02.0 – —
TIMELINE
Jun 5 Reserved by CNA
Jun 6 Published (CNA: VulDB)
chrisvrichardson MapPress Maps for WordPress — MapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Reference via REST API Endpoints
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N L N 5.3 .0102 60.5 —
AFFECTED
Product Versions Fixed
MapPress Maps for WordPress unspecified —
TIMELINE
May 18 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H N U H H H 7.2 .0066 48.6 —
AFFECTED
Product Versions Fixed
MDJM Event Management unspecified —
TIMELINE
Apr 30 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
thimpress LearnPress – Backup & Migration Tool — LearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H N U H N N 4.9 .0065 48.0 —
AFFECTED
Product Versions Fixed
LearnPress – Backup & Migration Tool unspecified —
TIMELINE
Apr 30 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
nextendweb Smart Slider 3 — Smart Slider 3 <= 3.5.1.36 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'src'/'srcset' Attribute in HTML Export
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H N U H N N 4.9 .0060 45.9 —
AFFECTED
Product Versions Fixed
Smart Slider 3 unspecified —
TIMELINE
May 21 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
thimpress LearnPress – WordPress LMS Plugin for Create and Sell Online Courses — LearnPress <= 4.3.6 - Unauthenticated Sensitive Information Exposure via 'c_status' and 'return_type' Parameters
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U L N N 5.3 .0053 42.2 —
AFFECTED
Product Versions Fixed
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses unspecified —
TIMELINE
May 13 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
davidanderson All-In-One Security (AIOS) – Security and Firewall — All-In-One Security (AIOS) <= 5.4.7 - Unauthenticated Stored Cross-Site Scripting via REST API Request Path
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C L L N 7.2 .0049 39.7 —
AFFECTED
Product Versions Fixed
All-In-One Security (AIOS) – Security and Firewall unspecified —
TIMELINE
May 12 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
JingDong JD Cloud Box AX6600 jdcweb_rpc set_macfilter stack-based overflow
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 7.4 .0048 39.4 —
AFFECTED
Product Versions Fixed
JD Cloud Box AX6600 4.5.3.r4546 – —
TIMELINE
Jun 5 Reserved by CNA
Jun 6 Published (CNA: VulDB)
10web Photo Gallery by 10Web – Mobile-Friendly Image Gallery — Photo Gallery by 10Web <= 1.8.41 - Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H N N 6.5 .0047 38.6 —
AFFECTED
Product Versions Fixed
Photo Gallery by 10Web – Mobile-Friendly Image Gallery unspecified —
TIMELINE
May 28 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
thimpress LearnPress – Backup & Migration Tool — LearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File Upload
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H H N U H H H 6.6 .0045 37.4 —
AFFECTED
Product Versions Fixed
LearnPress – Backup & Migration Tool unspecified —
TIMELINE
Apr 30 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
CRUX Protocol::HTTP2 — Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N N H 7.5 .0041 34.5 —
AFFECTED
Product Versions Fixed
Protocol::HTTP2 unspecified —
TIMELINE
Jun 3 Reserved by CNA
Jun 6 Published (CNA: CPANSec)
perfree go-fastdfs-web Installation Endpoint checkServer server-side request forgery
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0041 34.0 —
AFFECTED
Product Versions Fixed
go-fastdfs-web 1.3.0 – —
TIMELINE
Jun 5 Reserved by CNA
Jun 6 Published (CNA: VulDB)
holithemes Click to Chat – HoliThemes — Click to Chat <= 4.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'num' Shortcode Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C L L N 6.4 .0041 33.9 —
AFFECTED
Product Versions Fixed
Click to Chat – HoliThemes unspecified —
TIMELINE
May 4 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
spacetime Ad Inserter – Ad Manager & AdSense Ads — Ad Inserter <= 2.8.15 - Reflected Cross-Site Scripting via URL Parameters in iframe Mode
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N R C L L N 6.1 .0036 29.1 —
AFFECTED
Product Versions Fixed
Ad Inserter – Ad Manager & AdSense Ads unspecified —
TIMELINE
May 22 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
masaakitanaka Booking Package — Booking Package <= 1.7.16 - Authenticated (Editor+) Privilege Escalation via Account Takeover to updateUser AJAX Action
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H N U H H H 7.2 .0036 28.9 —
AFFECTED
Product Versions Fixed
Booking Package unspecified —
TIMELINE
May 28 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
wpdevteam EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more — EmbedPress <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block 'url' Attribute
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C L L N 6.4 .0033 26.0 —
AFFECTED
Product Versions Fixed
EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more unspecified —
TIMELINE
May 4 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
davidfcarr Quick Playground — Quick Playground <= 1.3.4 - Authenticated (Administrator+) Arbitrary File Read via 'filename' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H H N U H N N 4.4 .0032 24.3 —
AFFECTED
Product Versions Fixed
Quick Playground unspecified —
TIMELINE
Feb 13 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
plugcrux Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More — Integration for Freshsales <= 1.0.15 - Unauthenticated Stored Cross-Site Scripting via Form Submission Data
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C L L N 7.2 .0031 24.1 —
AFFECTED
Product Versions Fixed
Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More unspecified —
TIMELINE
May 18 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
glenwpcoder Drag and Drop Multiple File Upload for Contact Form 7 — Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H H N C L L N 4.4 .0031 23.9 —
AFFECTED
Product Versions Fixed
Drag and Drop Multiple File Upload for Contact Form 7 unspecified —
TIMELINE
May 19 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
smub WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More — WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N L N 5.3 .0030 22.7 —
AFFECTED
Product Versions Fixed
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More unspecified —
TIMELINE
May 4 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
cifi SEO Plugin by Squirrly SEO — SEO Plugin by Squirrly SEO <= 12.4.16 - Missing Authorization to Authenticated (Contributor+) Privileged Cloud API Operations
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U N L N 4.3 .0030 22.2 —
AFFECTED
Product Versions Fixed
SEO Plugin by Squirrly SEO unspecified —
TIMELINE
May 1 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
flippercode WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters — WP Maps <= 4.9.4 - Authenticated (Admin+) Stored Cross-Site Scripting via 'location_messages' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H H N C L L N 4.4 .0029 21.9 —
AFFECTED
Product Versions Fixed
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters unspecified —
TIMELINE
May 26 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
n/a FluentCMS — FluentCMS Blocks Plugin blocks cross site scripting
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N H P N L N 1.9 .0027 19.9 —
AFFECTED
Product Versions Fixed
FluentCMS 0.0.5 – —
TIMELINE
Jun 5 Reserved by CNA
Jun 6 Published (CNA: VulDB)
Remainder (ranked, continued)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
| CVE-2026-11436 | 2.1 | 18.3 | n/a | Mage AI | CWE-79 | Mage AI Sign-in Flow index.tsx useMutation cross site scripting |
| CVE-2026-9016 | 5.3 | 18.0 | qriouslad | Debug Log Manager – Conveniently Monitor and Inspect Errors | CWE-117 | Debug Log Manager <= 2.5.0 - Unauthenticated Improper Output Neutralization f… |
| CVE-2026-11435 | 5.5 | 17.8 | Jinher | OA | CWE-74 | Jinher OA nextselectplan.aspx sql injection |
| CVE-2026-8978 | 4.9 | 17.7 | crafium | OptinCraft – Drag & Drop Optins & Popup Builder for WordPress | CWE-89 | OptinCraft <= 1.2.0 - Authenticated (Administrator+) SQL Injection via 'order… |
| CVE-2026-8611 | 4.3 | 14.5 | klamra22 | Klamra Paycal for Aspaclaria | CWE-639 | Klamra Paycal for Aspaclaria <= 1.1.4 - Insecure Direct Object Reference to A… |
| CVE-2026-9008 | 4.3 | 13.2 | webvitaly | Page-list | CWE-862 | Page-list <= 6.2 - Missing Authorization to Authenticated (Contributor+) Sens… |
| CVE-2026-9281 | 6.4 | 12.1 | litonice13 | Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits | CWE-79 | Master Addons For Elementor <= 3.1.0 - Authenticated (Author+) Stored Cross-S… |
| CVE-2026-11438 | 5.3 | 12.0 | theonedev | onedev | CWE-266 | theonedev projects improper authorization |
| CVE-2026-11439 | 5.3 | 12.0 | theonedev | onedev | CWE-266 | theonedev Parent Project projects improper authorization |
| CVE-2026-11440 | 5.3 | 12.0 | theonedev | onedev | CWE-266 | theonedev REST API default-branch improper authorization |
| CVE-2026-11441 | 5.3 | 12.0 | theonedev | onedev | CWE-266 | theonedev Pull Request issues canAccessIssue improper authorization |
| CVE-2026-11412 | 2.1 | 9.7 | Jinher | OA | CWE-74 | Jinher OA GetFormSn.aspx sql injection |
| CVE-2026-11411 | 1.9 | 6.8 | iAI Lab | PDF AI App | CWE-22 | iAI Lab PDF AI App chatpdf.pro getExternalCacheDir path traversal |
| CVE-2026-26422 | 8.4 | 6.0 | Clash Verge Rev | clash-verge-service-ipc | CWE-732 | clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, lead… |