A vulnerability marked as critical has been reported in wickedplugins Wicked Folders Plugin up to 4.1.0 on WordPress. Impacted is the function delete_folders. This manipulation causes authorization bypass.
This vulnerability appears as CVE-2026-1883. The attack may be initiated remotely. There is no available exploit.
A vulnerability labeled as critical has been found in wedevs User Frontend Plugin up to 4.2.8 on WordPress. This issue affects the function draft_post. The manipulation of the argument post_id results in missing authorization.
This vulnerability is reported as CVE-2026-2233. The attack can be launched remotely. No exploit exists.
A vulnerability identified as critical has been detected in webaways NEX-Forms Plugin up to 9.1.9 on WordPress. This vulnerability affects the function submit_nex_form. The manipulation of the argument nf_set_entry_update_id leads to authorization bypass.
This vulnerability is documented as CVE-2026-1947. The attack can be initiated remotely. There is not any exploit available.
A vulnerability categorized as problematic has been discovered in GNU Binutils. This affects an unknown part of the component XCOFF Object File Handler. Executing a manipulation can lead to out-of-bounds read.
This vulnerability is registered as CVE-2026-3442. The attack needs to be launched locally. No exploit is available.
A vulnerability was found in GNU Binutils. It has been rated as problematic. Affected by this issue is some unknown functionality of the component XCOFF Object File Handler. Performing a manipulation results in out-of-bounds read.
This vulnerability is cataloged as CVE-2026-3441. The attack must be initiated from a local position. There is no exploit available.
A vulnerability was found in Linux Kernel up to 6.12.23/6.13.11/6.14.2. It has been rated as problematic. Affected by this vulnerability is the function io_req_post_cqe. The manipulation leads to state issue.
This vulnerability is referenced as CVE-2025-23154. The attack needs to be initiated within the local network. No exploit is available.
Upgrading the affected component is advised.