79 CVEs published July 11, 2026: 5 critical, 23 high, 48 medium, 3 low; 0 in KEV; 2 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 54 in the results table.
Yesterday's Results
79 CVEs published. 25 box scores, 54 table rows — nothing truncated.
boldgrid W3 Total Cache — W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H N N 7.5 .0277 85.1 —
AFFECTED
Product Versions Fixed
W3 Total Cache unspecified —
TIMELINE
May 22 Reserved by CNA
Jul 11 Published (CNA: Wordfence)
MervinPraison PraisonAI — PraisonAI before 1.6.78 Remote Code Execution via CodeAgent
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 10.0 .0223 81.2 —
AFFECTED
Product Versions Fixed
PraisonAI unspecified 1.6.78
TIMELINE
Jul 9 Reserved by CNA
Jul 11 Published (CNA: VulnCheck)
xtreeme Planyo online reservation system — Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C L L N 7.2 .0113 63.7 —
AFFECTED
Product Versions Fixed
Planyo online reservation system unspecified —
TIMELINE
Mar 4 Reserved by CNA
Jul 11 Published (CNA: Wordfence)
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H N R C H H H 8.3 .0070 50.3 —
AFFECTED
Product Versions Fixed
Microsoft Edge (Chromium-based) 1.0.0.0 – —
TIMELINE
Jun 29 Reserved by CNA
Jul 11 Published (CNA: microsoft)
smackcoders WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel — WP Ultimate CSV Importer <= 8.0.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'MappedFields' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H H H 8.8 .0062 47.0 —
AFFECTED
Product Versions Fixed
WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel unspecified —
TIMELINE
Jun 25 Reserved by CNA
Jul 11 Published (CNA: Wordfence)
choijun LA-Studio Element Kit for Elementor — LA-Studio Element Kit for Elementor <= 1.6.1 - Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H L N U H H H 7.5 .0055 43.4 —
AFFECTED
Product Versions Fixed
LA-Studio Element Kit for Elementor unspecified —
TIMELINE
Jul 9 Reserved by CNA
Jul 11 Published (CNA: Wordfence)
MervinPraison PraisonAI — PraisonAI before 4.6.78 Arbitrary File Write and Command Execution
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 9.4 .0054 42.8 —
AFFECTED
Product Versions Fixed
PraisonAI unspecified 4.6.78
TIMELINE
Jul 9 Reserved by CNA
Jul 11 Published (CNA: VulnCheck)
wpmessiah Swiss Toolkit For WP — Swiss Toolkit For WP <= 1.4.6 - Authenticated (Author+) Arbitrary File Upload via upload_extension_files()
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H H H 8.8 .0054 42.8 —
AFFECTED
Product Versions Fixed
Swiss Toolkit For WP unspecified —
TIMELINE
Feb 11 Reserved by CNA
Jul 11 Published (CNA: Wordfence)
masaakitanaka Booking Package — Booking Package <= 1.7.20 - Unauthenticated SQL Injection via 'email' Form Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H N N 7.5 .0048 39.4 —
AFFECTED
Product Versions Fixed
Booking Package unspecified —
TIMELINE
Jul 9 Reserved by CNA
Jul 11 Published (CNA: Wordfence)
tigroumeow Code Engine – PHP Snippets, AI Functions & Automation for WordPress — Code Engine <= 0.3.5 - Authenticated (Contributor+) Remote Code Execution
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H H H 8.8 .0047 38.6 —
AFFECTED
Product Versions Fixed
Code Engine – PHP Snippets, AI Functions & Automation for WordPress unspecified —
TIMELINE
Jun 27 Reserved by CNA
Jul 11 Published (CNA: Wordfence)
MervinPraison PraisonAI — PraisonAI before 4.6.78 SQL/CQL Injection via vector dimension
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 9.3 .0041 34.2 —
AFFECTED
Product Versions Fixed
PraisonAI unspecified 4.6.78
TIMELINE
Jul 8 Reserved by CNA
Jul 11 Published (CNA: VulnCheck)
rsjoomla.com rsjoomla.com RSFiles extension for Joomla — Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 10.0 .0040 33.7 —
AFFECTED
Product Versions Fixed
rsjoomla.com RSFiles extension for Joomla 1.0-1.17.11 – —
TIMELINE
Jun 25 Reserved by CNA
Jul 11 Public exploit reference published
Jul 11 Published (CNA: Joomla)
nicu_m Simple JWT Login – Allows you to use JWT on REST endpoints. — Simple JWT Login <= 3.6.6 - Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation via 'payload' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H H H 8.8 .0038 31.4 —
AFFECTED
Product Versions Fixed
Simple JWT Login – Allows you to use JWT on REST endpoints. unspecified —
TIMELINE
Jun 30 Reserved by CNA
Jul 11 Published (CNA: Wordfence)
phoca.cz phoca.cz Phoca Download extension for Joomla — Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L P L N H H H 9.0 .0037 30.3 —
AFFECTED
Product Versions Fixed
phoca.cz Phoca Download extension for Joomla 1.0-6.1.2 – —
TIMELINE
Jun 25 Reserved by CNA
Jul 11 Public exploit reference published
Jul 11 Published (CNA: Joomla)
stylemix Cost Calculator Builder — Cost Calculator Builder <= 4.0.11 - Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U L N N 5.3 .0037 30.1 —
AFFECTED
Product Versions Fixed
Cost Calculator Builder unspecified —
TIMELINE
Jun 4 Reserved by CNA
Jul 11 Published (CNA: Wordfence)
wclovers WCFM – Frontend Manager for WooCommerce — WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manage Controller
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N L N 5.3 .0036 29.2 —
AFFECTED
Product Versions Fixed
WCFM – Frontend Manager for WooCommerce unspecified —
TIMELINE
Jun 23 Reserved by CNA
Jul 11 Published (CNA: Wordfence)
wpdevteam Essential Addons for Elementor – Popular Elementor Templates & Widgets — Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H H H 8.8 .0036 28.7 —
AFFECTED
Product Versions Fixed
Essential Addons for Elementor – Popular Elementor Templates & Widgets unspecified —
TIMELINE
Jul 8 Reserved by CNA
Jul 11 Published (CNA: Wordfence)
wupsales AI Copilot – Content Generator — AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Modification via 'publishTasks' and 'unpublishTasks' AJAX Actions
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N L N 5.3 .0035 28.5 —
AFFECTED
Product Versions Fixed
AI Copilot – Content Generator unspecified —
TIMELINE
Apr 21 Reserved by CNA
Jul 11 Published (CNA: Wordfence)
ahmadmj Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin — Majestic Support <= 1.1.9 - Authenticated (Subscriber+) SQL Injection via 'val' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H N N 6.5 .0035 28.3 —
AFFECTED
Product Versions Fixed
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin unspecified —
TIMELINE
Jun 24 Reserved by CNA
Jul 11 Published (CNA: Wordfence)
wpswings Points and Rewards for WooCommerce — Points and Rewards for WooCommerce <= 2.10.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U N L N 4.3 .0035 28.0 —
AFFECTED
Product Versions Fixed
Points and Rewards for WooCommerce unspecified —
TIMELINE
Jun 2 Reserved by CNA
Jul 11 Published (CNA: Wordfence)
blendmedia WP CTA – Call Now Button, Sticky Button & Call to Action Builder — WP CTA <= 2.2.2 - Unauthenticated Time-Based Blind SQL Injection via 'fildname' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H N N 7.5 .0033 25.5 —
AFFECTED
Product Versions Fixed
WP CTA – Call Now Button, Sticky Button & Call to Action Builder unspecified —
TIMELINE
Mar 23 Reserved by CNA
Jul 11 Published (CNA: Wordfence)
wupsales AI Copilot – Content Generator — AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via AJAX Actions 'removeGroup' and 'clear'
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N L N 5.3 .0032 25.3 —
AFFECTED
Product Versions Fixed
AI Copilot – Content Generator unspecified —
TIMELINE
Apr 21 Reserved by CNA
Jul 11 Published (CNA: Wordfence)
corvusinfo CorvusPay WooCommerce Payment Gateway — CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Stored Cross-Site Scripting via 'approval_code' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C L L N 7.2 .0032 25.2 —
AFFECTED
Product Versions Fixed
CorvusPay WooCommerce Payment Gateway unspecified —
TIMELINE
Apr 23 Reserved by CNA
Jul 11 Published (CNA: Wordfence)
ImageMagick before 7.1.2-26 Use-After-Free in FormatMagickCaption
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N H P N N N N L 6.3 .0032 25.1 —
AFFECTED
Product Versions Fixed
ImageMagick unspecified 7.1.2-26
ImageMagick unspecified 6.9.13-51
TIMELINE
Jul 10 Reserved by CNA
Jul 11 Published (CNA: VulnCheck)
MervinPraison PraisonAI — PraisonAI before 1.7.3 Unauthenticated Agent Access via Insecure Defaults
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H L L 8.8 .0032 25.0 —
AFFECTED
Product Versions Fixed
PraisonAI unspecified 1.7.3
TIMELINE
Jul 9 Reserved by CNA
Jul 11 Published (CNA: VulnCheck)
Remainder (ranked, continued)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
| CVE-2026-7655 | 8.1 | 24.8 | surecart | SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments | CWE-640 | SureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via For… |
| CVE-2026-1359 | 8.8 | 23.1 | genolve | Genolve – Genolve AI Business Graphics, AI Images | CWE-863 | Genolve – AI image AI video generation <= 5.0.5 - Authenticated (Contributor+… |
| CVE-2026-7559 | 4.3 | 23.0 | redefiningtheweb | Affiliate Program & Referral Tracking for WooCommerce & WordPress – Affilia | CWE-862 | Affilia <= 3.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbit… |
| CVE-2026-56303 | 8.7 | 22.8 | Capgo | Capgo | CWE-200 | Capgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC … |
| CVE-2026-13756 | 8.8 | 22.6 | WP Grid Builder | WP Grid Builder | CWE-269 | WP Grid Builder <= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation v… |
| CVE-2026-11426 | 6.5 | 22.5 | WebFactory | Under Construction Page (Pro) | CWE-22 | UnderConstructionPage PRO <= 5.76 - Authenticated (Subscriber+) Arbitrary Fil… |
| CVE-2026-13250 | 5.3 | 22.4 | solacewp | Solace Extra | CWE-862 | Solace Extra <= 1.5.3 - Missing Authorization to Unauthenticated Arbitrary Co… |
| CVE-2026-12103 | 4.3 | 21.2 | subratamal | Wallet for WooCommerce | CWE-862 | Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Sub… |
| CVE-2026-12426 | 5.3 | 19.8 | supercleanse | Members – Membership & User Role Editor Plugin | CWE-200 | Members <= 3.2.22 - Unauthenticated Sensitive Information Disclosure via REST… |
| CVE-2026-15072 | 6.5 | 19.7 | iqonicdesign | KiviCare – Clinic & Patient Management System (EHR) | CWE-89 | KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Param… |
| CVE-2026-9017 | 5.3 | 19.7 | webaways | NEX-Forms – Ultimate Forms Plugin for WordPress | CWE-862 | NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Arbitrary Form … |
| CVE-2026-7620 | 4.3 | 19.6 | rainafarai | Notification for Telegram | CWE-862 | Notification for Telegram <= 3.5.1 - Missing Authorization to Authenticated (… |
| CVE-2026-61857 | 6.3 | 18.5 | ImageMagick | ImageMagick | CWE-252 | ImageMagick before 7.1.2-26 Heap Use-After-Free via XMP |
| CVE-2026-61439 | 8.7 | 17.8 | MervinPraison | PraisonAI | CWE-1188 | PraisonAI before 4.6.78 Prompt Injection Defense Bypass |
| CVE-2026-13378 | 7.2 | 17.7 | wpvibes | Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database | CWE-79 | Form Vibes <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting via Contact… |
| CVE-2025-5017 | 4.9 | 17.6 | catalyst2020 | Catalyst Connect Zoho CRM Client Portal | CWE-89 | Catalyst Connect Zoho CRM Client Portal <= 2.2.0 - Authenticated (Administrat… |
| CVE-2026-61442 | 7.1 | 17.4 | MervinPraison | PraisonAI | CWE-862 | PraisonAI Platform before 0.1.9 Authorization Bypass via PATCH |
| CVE-2026-3367 | 4.4 | 17.4 | lustmored | Lockme calendars integration | CWE-79 | Lockme OAuth2 calendars integration <= 2.11.0 - Authenticated (Administrator+… |
| CVE-2026-5743 | 6.4 | 16.8 | gallerycreator | SimpLy Gallery | CWE-79 | Mixed Media Gallery Blocks <= 3.3.3.1 - Authenticated (Author+) Stored Cross-… |
| CVE-2026-11591 | 4.4 | 16.8 | trustindex | Widgets for Google Reviews | CWE-79 | Widgets for Google Reviews <= 13.3 - Authenticated (Editor+) Stored Cross-Sit… |
| CVE-2026-10041 | 4.3 | 16.7 | wclovers | WCFM – Frontend Manager for WooCommerce | CWE-639 | WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber… |
| CVE-2026-13114 | 7.2 | 16.2 | stylemix | Motors – Car Dealership & Classified Listings Plugin | CWE-79 | Motors <= 1.4.112 - Unauthenticated Stored Cross-Site Scripting via Comment C… |
| CVE-2026-61428 | 6.9 | 16.1 | MervinPraison | PraisonAI | CWE-290 | PraisonAI AgentMail before 4.6.78 Message Injection via Webhook |
| CVE-2026-61858 | 4.8 | 16.2 | ImageMagick | ImageMagick | CWE-59 | ImageMagick before 7.1.2-26 Policy Bypass via APNG encoder |
| CVE-2026-11898 | 4.4 | 16.2 | videousermanuals | White Label CMS | CWE-79 | White Label CMS <= 2.7.12 - Authenticated (Administrator+) Stored Cross-Site … |
| CVE-2026-61448 | 2.1 | 15.9 | parse-community | parse-server | CWE-434 | Parse Server 9.0.0 Stored XSS via malformed Content-Type |
| CVE-2026-15073 | 6.5 | 15.6 | iqonicdesign | KiviCare – Clinic & Patient Management System (EHR) | CWE-89 | KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Param… |
| CVE-2026-61454 | 8.7 | 15.2 | getgrav | grav | CWE-200 | Grav before 2.0.4 Information Disclosure via __GRAV_CONFIG__ |
| CVE-2026-56296 | 6.9 | 15.2 | Cap-go | capgo | CWE-203 | Cap-go - App Existence Oracle via Unauthenticated transfer_app RPC |
| CVE-2026-6801 | 5.3 | 15.2 | postmagthemes | Context Blog | CWE-200 | Context Blog <= 1.3.5 - Unauthenticated Sensitive Information Exposure via 'p… |
| CVE-2026-7544 | 4.3 | 15.0 | 2coders | Mux Video Uploader | CWE-200 | Mux Video Uploader <= 1.1.4 - Authenticated (Subscriber+) Information Exposure |
| CVE-2026-13116 | 4.3 | 14.8 | wpovernight | PDF Invoices & Packing Slips for WooCommerce | CWE-639 | PDF Invoices & Packing Slips for WooCommerce <= 5.14.0 - Insecure Direct Obje… |
| CVE-2026-8678 | 4.3 | 14.3 | richardperdaan | MyParcel | CWE-862 | MyParcel <= 4.25.1 - Missing Authorization to Authenticated (Subscriber+) Arb… |
| CVE-2026-61429 | 8.4 | 12.9 | MervinPraison | PraisonAI | CWE-918 | PraisonAI before 1.6.78 SSRF via Crawl4AI Chromium backend |
| CVE-2026-3552 | 4.3 | 11.9 | surflabtech | SurfLink – Link Manager & Backup Restore | CWE-862 | SurfLink < 2.6.0 - Missing Authorization to Authenticated (Subscriber+) 410 G… |
| CVE-2026-12738 | 4.3 | 11.9 | saadiqbal | WP Easy Pay – Payment and Donation form Builder for Square | CWE-862 | WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) A… |
| CVE-2026-9738 | 4.4 | 11.2 | printfriendly | Print, PDF & Email by PrintFriendly | CWE-79 | Print, PDF, Email by PrintFriendly <= 5.5.10 - Authenticated (Administrator+)… |
| CVE-2026-15470 | 2.1 | 11.1 | Eleveo | Call Recording Software | CWE-266 | Eleveo Call Recording Software group.jsp improper authorization |
| CVE-2026-12126 | 6.4 | 10.7 | wclovers | WCFM Marketplace – Multivendor Marketplace for WooCommerce | CWE-79 | WCFM Marketplace <= 3.7.3 - Authenticated (Vendor+) Stored Cross-Site Scripti… |
| CVE-2026-1832 | 4.3 | 10.7 | thrivedesk | Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk | CWE-862 | ThriveDesk <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Ca… |
| CVE-2026-15010 | 6.4 | 10.5 | robin-w | bbp style pack | CWE-79 | bbp style pack <= 6.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scrip… |
| CVE-2026-56372 | 4.8 | 9.9 | ImageMagick | ImageMagick | CWE-122 | ImageMagick - Heap Buffer Overflow Read via Unrecognized Magnify Method |
| CVE-2025-13968 | 6.4 | 9.6 | starboardsuite | Starboard Suite Reservation Calendars | CWE-79 | Starboard Suite Reservation Calendars <= 3.1.4 - Authenticated (Contributor+)… |
| CVE-2026-15097 | 6.4 | 9.6 | themifyme | Themify Builder | CWE-79 | Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scr… |
| CVE-2026-12141 | 4.9 | 9.3 | leap13 | Premium Addons for Elementor – Powerful Elementor Templates & Widgets | CWE-79 | Premium Addons for Elementor <= 4.11.84 - Authenticated (Contributor+) Stored… |
| CVE-2026-61870 | 2.1 | 9.1 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak via VIFF Encoder |
| CVE-2026-1382 | 6.4 | 8.7 | freshlabs | fresh Podcaster | CWE-79 | fresh Podcaster <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scr… |
| CVE-2026-15096 | 6.4 | 8.7 | themifyme | Themify Builder | CWE-79 | Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scr… |
| CVE-2026-56240 | 5.3 | 8.1 | Capgo | Capgo | CWE-285 | Capgo - Billing Authorization Bypass via Exhausted Usage Credits |
| CVE-2026-11901 | 5.3 | 7.6 | thimpress | WP Hotel Booking | CWE-345 | WP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data… |
| CVE-2026-56763 | 6.3 | 7.5 | Hono | Hono | CWE-1321 | Hono - Prototype Pollution via __proto__ Key in parseBody with dot Option |
| CVE-2026-61465 | 4.8 | 7.0 | ImageMagick | ImageMagick | CWE-770 | ImageMagick before 7.1.2-26 Memory Allocation Policy Bypass |
| CVE-2026-10660 | 6.4 | 5.6 | zephyrproject | zephyr | CWE-787 | Shared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-c… |
| CVE-2026-60088 | 6.8 | 4.4 | MervinPraison | PraisonAI | CWE-22 | PraisonAI before 4.6.78 Path Traversal via Custom Commands |