plugin

Wp Plugin Crazy Domains Vulnerabilities

1 known security issue reported for the Wp Plugin Crazy Domains WordPress plugin. Most recent disclosed Sep 8, 2026.

1 high

Running Wp Plugin Crazy Domains on your site? Check whether your installed version is affected.

Scan your site free

Various Newfold Plugins Various Versions - Unauthenticated Authentication Bypass via Bearer Token Validation with Empty Secret

high

Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the `authenticate()` method — registered on the `rest_authentication_errors` filter and therefore evaluated for every unauthenticated REST API request — performs...

CVSS:
8.8
(Wordfence)
Affected:
up to 2.5.2
Fixed in:
2.5.3
Disclosed:
Sep 8, 2026

CVE-2026-80099 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database