HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-5219 — Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology...

·Source: NIST NVD

Updated:

Executive Summary

Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows Cross Site Request Forgery. This issue affects E-Commerce Pack: through 30072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Analysis

Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows Cross Site Request Forgery. This issue affects E-Commerce Pack: through 30072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. CVSS Score: 8.3. Published: 2026-07-30T14:17:01.747.

Indicators of Compromise (1)

CVE (1)
CVE-2026-5219
Source Attribution

Originally published by NIST NVD on Jul 30, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-3141 — The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file d...

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the REST API route being registered without any authentication middleware in routes/rest/api.php. This makes it possible for unauthenticated attackers to

CVE-2026-3141
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-15414 — The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privileg...

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that excludes privileged roles — the only validations applied, `sanitize_key()` and `wp_roles()->is_role()`, both accept `'ad

CVE-2026-15414
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-15006 — The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email...

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2026-15006
NIST NVD