33 CVEs published June 27, 2026: 1 critical, 10 high, 22 medium, 0 low; 0 in KEV; 0 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 8 in the results table.
Yesterday's Results
33 CVEs published. 25 box scores, 8 table rows — nothing truncated.
pravel Invoice Generator — Invoice Generator <= 1.0.0 - Unauthenticated Privilege Escalation via Account Takeover via 'user_id' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .0066 48.7 —
AFFECTED
Product Versions Fixed
Invoice Generator unspecified —
TIMELINE
Jun 16 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
themeisle Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions — Stripe Payment Forms by WP Full Pay <= 8.4.3 - Missing Authorization to Unauthenticated Payment Record Manipulation via 'paymentIntentId' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N L N 5.3 .0054 42.9 —
AFFECTED
Product Versions Fixed
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions unspecified —
TIMELINE
Jun 16 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
nmedia Frontend File Manager Plugin — Frontend File Manager Plugin <= 23.6 - Authenticated (Subscriber+) Arbitrary File Deletion
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U N H H 8.1 .0040 33.7 —
AFFECTED
Product Versions Fixed
Frontend File Manager Plugin unspecified —
TIMELINE
May 7 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
vinod-dalvi Ivory Search – WordPress Search Plugin — Ivory Search <= 5.5.15 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H H N C L L N 4.4 .0034 27.4 —
AFFECTED
Product Versions Fixed
Ivory Search – WordPress Search Plugin unspecified —
TIMELINE
Jun 5 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
gpriday Page Builder by SiteOrigin — Page Builder by SiteOrigin <= 2.34.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via panels_data Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C L L N 6.4 .0034 27.3 —
AFFECTED
Product Versions Fixed
Page Builder by SiteOrigin unspecified —
TIMELINE
Jun 24 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation — Groundhogg <= 4.5.5 - Authenticated (Sales Rep+) SQL Injection via 'query[select]' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H N N 6.5 .0033 26.3 —
AFFECTED
Product Versions Fixed
Groundhogg — CRM, Newsletters, and Marketing Automation unspecified —
TIMELINE
Jun 25 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
maxfoundry MaxButtons – Create buttons — MaxButtons <= 9.8.5 - Reflected Cross-Site Scripting via 'view' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N R C L L N 6.1 .0033 26.2 —
AFFECTED
Product Versions Fixed
MaxButtons – Create buttons unspecified —
TIMELINE
Jun 24 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
webaways NEX-Forms – Ultimate Forms Plugin for WordPress — NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via CSVExport Class
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U L N N 5.3 .0031 24.1 —
AFFECTED
Product Versions Fixed
NEX-Forms – Ultimate Forms Plugin for WordPress unspecified —
TIMELINE
Jun 16 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
reepaydenmark Frisbii Pay — Frisbii Pay <= 1.8.9 - Missing Authorization to Authenticated (Subscriber+) Payment Token Modification
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U N H N 6.5 .0027 19.8 —
AFFECTED
Product Versions Fixed
Frisbii Pay unspecified —
TIMELINE
Mar 3 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation — Groundhogg <= 4.5.5 - Authenticated (Marketer+) SQL Injection via 'search' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H N N 6.5 .0027 19.6 —
AFFECTED
Product Versions Fixed
Groundhogg — CRM, Newsletters, and Marketing Automation unspecified —
TIMELINE
Jun 25 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
expresstech Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker — Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U N L N 4.3 .0027 19.2 —
AFFECTED
Product Versions Fixed
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker unspecified —
TIMELINE
May 21 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
dokaninc Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U L N N 4.3 .0027 19.1 —
AFFECTED
Product Versions Fixed
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy unspecified —
TIMELINE
Jun 11 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
jegstudio Gutenverse – WordPress Blocks, Page Builder & Site Editor — Gutenverse <= 3.8.0 - Authenticated (Editor+) Stored Cross-Site Scripting via 'fonts[].font.font.value' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H H N C L L N 4.4 .0024 15.8 —
AFFECTED
Product Versions Fixed
Gutenverse – WordPress Blocks, Page Builder & Site Editor unspecified —
TIMELINE
Jun 16 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
dokaninc Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C L L N 6.4 .0024 15.5 —
AFFECTED
Product Versions Fixed
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy unspecified —
TIMELINE
Jun 9 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
metagauss RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login — RegistrationMagic <= 6.0.8.6 - Authenticated (Subscriber+) Authentication Bypass via Forged PayPal IPN Request
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N L N 5.3 .0024 14.9 —
AFFECTED
Product Versions Fixed
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login unspecified —
TIMELINE
May 21 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
Unknown Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content — ProfilePress < 4.16.17 - Subscriber+ Subscription Cancellation via IDOR
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U N H H 8.1 .0022 13.0 —
AFFECTED
Product Versions Fixed
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content unspecified —
TIMELINE
Jun 4 Reserved by CNA
Jun 27 Published (CNA: WPScan)
dornaweb Product Specifications for Woocommerce — Product Specifications for Woocommerce <= 0.8.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attribute/Group Creation, Modification, and Deletion via 'dwps_modify_groups' and 'dwps_modify_attributes' AJAX Actions
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U N L N 4.3 .0021 11.7 —
AFFECTED
Product Versions Fixed
Product Specifications for Woocommerce unspecified —
TIMELINE
Jun 5 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
CodePeople Post Map for Google Maps <= 1.2.6 - Authenticated (Contributor +) Stored Cross-Site Scripting via 'cpm_point' Post Meta
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C L L N 6.4 .0020 10.7 —
AFFECTED
Product Versions Fixed
CodePeople Post Map for Google Maps unspecified —
TIMELINE
Jun 25 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
templatescoderthemes Spexo — Spexo <= 2.0.11 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Activation
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U N L N 4.3 .0019 9.5 —
AFFECTED
Product Versions Fixed
Spexo unspecified —
TIMELINE
Jun 16 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
Surbma | Infusionsoft Shortcode <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C L L N 6.4 .0019 9.1 —
AFFECTED
Product Versions Fixed
Surbma | Infusionsoft Shortcode unspecified —
TIMELINE
Jun 8 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
harmonic_design HD Quiz — HD Quiz 2.2.0 - 2.2.1 - Cross-Site Request Forgery via Multiple AJAX Handlers
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N R U N L N 4.3 .0018 7.7 —
AFFECTED
Product Versions Fixed
HD Quiz 2.2.0 – —
TIMELINE
Jun 26 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
FreeBSD FreeBSD — Multiple vulnerabilities in the sound(4) mmap path
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U H H H 7.8 .0015 4.8 —
AFFECTED
Product Versions Fixed
FreeBSD 15.0-RELEASE – —
TIMELINE
May 11 Reserved by CNA
Jun 27 Published (CNA: freebsd)
FreeBSD FreeBSD — Flaw in Linuxulator execution of setugid binaries
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U N H H 7.1 .0015 4.7 —
AFFECTED
Product Versions Fixed
FreeBSD 15.0-RELEASE – —
TIMELINE
May 29 Reserved by CNA
Jun 27 Published (CNA: freebsd)
Masteriyo LMS <= 2.2.1 - Missing Authorization to Authenticated (Student+) Arbitrary Course Announcement Modification
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U N L N 4.3 .0015 4.6 —
AFFECTED
Product Versions Fixed
Masteriyo LMS – LMS Course Builder, Quizzes & Certificates unspecified —
TIMELINE
Jun 9 Reserved by CNA
Jun 27 Published (CNA: Wordfence)
Unknown Shariff for WordPress — Shariff for WordPress <= 1.0.11 - Admin+ Stored Cross-Site Scripting
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H R C L L N 4.8 .0014 4.3 —
AFFECTED
Product Versions Fixed
Shariff for WordPress unspecified —
TIMELINE
May 27 Reserved by CNA
Jun 27 Published (CNA: WPScan)
Remainder (ranked, continued)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
| CVE-2026-49417 | 7.0 | 2.9 | FreeBSD | FreeBSD | CWE-416 | Multiple vulnerabilities in the sound(4) mmap path |
| CVE-2026-10643 | 7.8 | 2.6 | zephyrproject | zephyr | CWE-787 | Out-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_p… |
| CVE-2025-59868 | 5.5 | 1.4 | HCLSoftware | Traveler for Microsoft Outlook | CWE-532 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to sensitive data ex… |
| CVE-2026-49416 | 7.8 | 1.3 | FreeBSD | FreeBSD | CWE-190 | Integer overflow in vt(4) CONS_HISTORY ioctl |
| CVE-2026-49414 | 7.8 | 1.3 | FreeBSD | FreeBSD | CWE-179 | ASLR bypass for setuid executables via procctl(2) |
| CVE-2026-49412 | 7.8 | 1.2 | FreeBSD | FreeBSD | CWE-416 | Use-after-free bug in the IPV6_MSFILTER socket option handler |
| CVE-2023-37524 | 7.8 | 1.0 | HCLSoftware | Traveler for Microsoft Outlook | CWE-1104 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities d… |
| CVE-2026-45259 | 6.5 | 0.7 | FreeBSD | FreeBSD | CWE-266 | sigqueue(2) missing capability mode restriction |