CVE-2026-27085Low· 2.7▾ SunlitShop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 14.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions.
astra >= n/a <= 4.13.12Update the WordPress Astra WordPress Theme theme to the latest available version (at least 4.14.0).
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-96837High· 8.8WordPress CartFlows plugin <= 3.2.0 - Remote Code Execution (RCE) vulnerability
CVE-2026-87741High· 8.8The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action
CVE-2026-62134Medium· 4.3WordPress Starter Templates plugin <= 4.7.5 - Insecure Direct Object References (IDOR) vulnerability
CVE-2026-102279Low· 3.1Laravel is a web application framework
CVE-2026-63216Medium· 5.3Zammad is a web based open source helpdesk/customer support system
CVE-2026-57440High· 7.5The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services