Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

230 changes refused · newest first · grouped by dayCSVJSONRSS

SinceClear all
ChangedSourceRows

Showing changes seen on 2026-04-08. Every day

These rows are not counted anywhere on this site. Checked and refused means we compared this change and then rejected it: the false positive filter for this kind of change judged it to be a false positive rather than a real change. The row is shown so you can check the filter and disagree with us, and it is counted in no figure on this site. No advisory change is here: the advisory engine counts the 2,291 version pairs its filters refused by class rather than writing them out one by one, so this view holds CVE and KEV changes only.

Rows we checked and refused, counted nowhere changed on 2026-04-08, newest first, one line per change to a CVE record, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord, Which record was edited, by its CVE id, or how many records one collapsed line stands on.Vendor · product, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Wed 8 Apr 2026· 58 record changes
2026-04-08Product addedCVE-2024-1294Wordfencenot named as affected at publication, now names sunshine photo cart – client photo gallery & photo proofing for photographersNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed sunshinephotocart/sunshine photo cart: free client galleries for photographers; a new product identity is not establishedDays to revision 778
2026-04-08Product addedWordfencenot named as affected at publication, now names jeg kit for elementor – powerful addons for elementor, widgets & templates for wordpressnot counted: Product identity rewritten with unchanged scopeDays to revision 663 to 757
2026-04-08same kind of change as the line aboveCVE-2024-1326same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed jegtheme/jeg elementor kit; a new product identity is not establishedDays to revision 757
2026-04-08same kind of change as the line aboveCVE-2024-3162same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed jegtheme/jeg elementor kit; a new product identity is not establishedDays to revision 736
2026-04-08same kind of change as the line aboveCVE-2024-4479same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed jegtheme/jeg elementor kit; a new product identity is not establishedDays to revision 663
2026-04-08Product addedWordfencenot named as affected at publication, now names classified listing – ai-powered classified ads & business directory pluginnot counted: Product identity rewritten with unchanged scopeDays to revision 713 to 729
2026-04-08same kind of change as the line aboveCVE-2024-1352same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed techlabpro1/classified listing – classified ads & business directory plugin; a new product identity is not establishedDays to revision 729
2026-04-08same kind of change as the line aboveCVE-2024-3893same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed techlabpro1/classified listing – classified ads & business directory plugin; a new product identity is not establishedDays to revision 713
2026-04-08Product addedWordfencenot named as affected at publication, now names lead form builder & contact formnot counted: Product identity rewritten with unchanged scopeDays to revision 706
2026-04-08same kind of change as the line aboveCVE-2024-1415same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed themehunk/responsive contact form builder & lead generation plugin; a new product identity is not establishedDays to revision 706
2026-04-08same kind of change as the line aboveCVE-2024-1416same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed themehunk/responsive contact form builder & lead generation plugin; a new product identity is not establishedDays to revision 706
2026-04-08Product addedWordfencenot named as affected at publication, now names ht mega addons for elementor – elementor widgets & template buildernot counted: Product identity rewritten with unchanged scopeDays to revision 652 to 757
2026-04-08same kind of change as the line aboveCVE-2024-1421same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed devitemsllc/ht mega – absolute addons for elementor; a new product identity is not establishedDays to revision 757
2026-04-08same kind of change as the line aboveCVE-2024-3307same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed devitemsllc/ht mega – absolute addons for elementor; a new product identity is not establishedDays to revision 706
2026-04-08same kind of change as the line aboveCVE-2024-4875same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed devitemsllc/ht mega – absolute addons for elementor; a new product identity is not establishedDays to revision 687
2026-04-08same kind of change as the line aboveCVE-2024-5173same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed devitemsllc/ht mega – absolute addons for elementor; a new product identity is not establishedDays to revision 652
2026-04-08Product addedWordfencenot named as affected at publication, now names livemesh addons by elementornot counted: Product identity rewritten with unchanged scopeDays to revision 729
2026-04-08same kind of change as the line aboveCVE-2024-1458same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed livemesh/elementor addons by livemesh; a new product identity is not establishedDays to revision 729
2026-04-08same kind of change as the line aboveCVE-2024-1461same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed livemesh/elementor addons by livemesh; a new product identity is not establishedDays to revision 729
2026-04-08Product addedCVE-2024-1467Wordfencenot named as affected at publication, now names starter templates – ai-powered templates for elementor & gutenbergNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed brainstormforce/starter templates — elementor, wordpress & beaver builder templates; a new product identity is not establishedDays to revision 699
2026-04-08Product addedCVE-2024-1562Wordfencenot named as affected at publication, now names gsheetconnector for woocommerce – send your orders and products to google sheet in real-timeNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed westerndeal/woocommerce google sheet connector; a new product identity is not establishedDays to revision 778
2026-04-08Product addedCVE-2024-1698Wordfencenot named as affected at publication, now names notificationx – fomo, live sales notification, woocommerce sales popup, gdpr, social proof, announcement banner & floating notification barNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/notificationx – best fomo, social proof, woocommerce sales popup & notification bar plugin with elementor; a new product identity is not establishedDays to revision 772
2026-04-08Product addedCVE-2024-1716Wordfencenot named as affected at publication, now names admin bar editor – toolbar customization with user role based access & custom menusNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed litonice13/admin bar editor – hide toolbar by user roles; a new product identity is not establishedDays to revision 706
2026-04-08Product addedWordfencenot named as affected at publication, now names wp ulike – like & dislike buttons for engagement and feedbacknot counted: Product identity rewritten with unchanged scopeDays to revision 706
2026-04-08same kind of change as the line aboveCVE-2024-1759same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed alimir/wp ulike – most advanced wordpress marketing toolkit; a new product identity is not establishedDays to revision 706
2026-04-08same kind of change as the line aboveCVE-2024-1797same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed alimir/wp ulike – most advanced wordpress marketing toolkit; a new product identity is not establishedDays to revision 706
2026-04-08Product addedCVE-2024-1812Wordfencenot named as affected at publication, now names everest forms – contact form, payment form, quiz, survey & custom form builderNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpeverest/everest forms – build contact forms, surveys, polls, quizzes, newsletter & application forms, and many more with ease!; a new product identity is not establishedDays to revision 729
2026-04-08Product addedCVE-2024-2086Wordfencenot named as affected at publication, now names file manager for google drive – integrate google driveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed princeahmed/integrate google drive – browse, upload, download, embed, play, share, gallery, and manage your google drive files into your wordpress site; a new product identity is not establishedDays to revision 740
2026-04-08Product addedCVE-2024-2124Wordfencenot named as affected at publication, now names translate wordpress with weglot – multilingual ai translationNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed remyb92/translate wordpress and go multilingual – weglot; a new product identity is not establishedDays to revision 750
2026-04-08Product addedCVE-2024-2324Wordfencenot named as affected at publication, now names fileorganizer – wordpress file managerNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed softaculous/fileorganizer – manage wordpress and website files; a new product identity is not establishedDays to revision 706
2026-04-08Product addedCVE-2024-2348Wordfencenot named as affected at publication, now names gum addon for elementorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed celomitan/gum elementor addon; a new product identity is not establishedDays to revision 729
2026-04-08Product addedCVE-2024-2381Wordfencenot named as affected at publication, now names aliexpress dropshipping plugin for woocommerce & wordpressNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed ali2woo/aliexpress dropshipping with alinext lite; a new product identity is not establishedDays to revision 659
2026-04-08Product addedCVE-2024-2384Wordfencenot named as affected at publication, now names wcpos – point of sale (pos) plugin for woocommerceNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed kilbot/woocommerce pos; a new product identity is not establishedDays to revision 750
2026-04-08Product addedCVE-2024-2456Wordfencenot named as affected at publication, now names ecwid by lightspeed ecommerce shopping cartNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed ecwid/ecwid ecommerce shopping cart; a new product identity is not establishedDays to revision 729
2026-04-08Product addedCVE-2024-2501Wordfencenot named as affected at publication, now names hubbub lite – fast, free social sharing and follow buttonsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed nerdpressteam/hubbub lite – fast, reliable social sharing buttons; a new product identity is not establishedDays to revision 729
2026-04-08Product addedWordfencenot named as affected at publication, now names email subscribers & newsletters – email marketing, post notifications & newsletter plugin for wordpressnot counted: Product identity rewritten with unchanged scopeDays to revision 657 to 706
2026-04-08same kind of change as the line aboveCVE-2024-2876same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed icegram/email subscribers by icegram express – email marketing, newsletters, automation for wordpress & woocommerce; a new product identity is not establishedDays to revision 706
2026-04-08same kind of change as the line aboveCVE-2024-5756same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed icegram/email subscribers by icegram express – email marketing, newsletters, automation for wordpress & woocommerce; a new product identity is not establishedDays to revision 657
2026-04-08Product addedWordfencenot named as affected at publication, now names carousel, slider, photo gallery with lightbox, video slider, by wp carouselnot counted: Product identity rewritten with unchanged scopeDays to revision 490 to 729
2026-04-08same kind of change as the line aboveCVE-2024-3020same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed shapedplugin/carousel, slider, gallery by wp carousel – image carousel & photo gallery, post carousel & post grid, product carousel & product grid for woocommerce; a new product identity is not establishedDays to revision 729
2026-04-08same kind of change as the line aboveCVE-2024-5020same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed shapedplugin/carousel, slider, gallery by wp carousel – image carousel with lightbox & photo gallery, video slider, post carousel & post grid, product carousel & product grid; a new product identity is not establishedDays to revision 490
2026-04-08Product addedWordfencenot named as affected at publication, now names poll maker – versus polls, anonymous polls, image pollsnot counted: Product identity rewritten with unchanged scopeDays to revision 706 to 720
2026-04-08same kind of change as the line aboveCVE-2024-3600same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed ays-pro/poll maker – best wordpress poll plugin; a new product identity is not establishedDays to revision 720
2026-04-08same kind of change as the line aboveCVE-2024-3601same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed ays-pro/poll maker – best wordpress poll plugin; a new product identity is not establishedDays to revision 706
2026-04-08Product addedCVE-2024-3609Wordfencenot named as affected at publication, now names reviewx – multi-criteria reviews for woocommerce with google reviews & schemaNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed reviewx/reviewx – multi-criteria rating & reviews for woocommerce; a new product identity is not establishedDays to revision 692
2026-04-08Product addedCVE-2024-3897Wordfencenot named as affected at publication, now names popup box – create countdown, coupon, video, contact form popupsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed ays-pro/popup box – best wordpress popup plugin; a new product identity is not establishedDays to revision 706
2026-04-08Product addedWordfencenot named as affected at publication, now names pearl – header buildernot counted: Product identity rewritten with unchanged scopeDays to revision 665 to 706
2026-04-08same kind of change as the line aboveCVE-2024-4000same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed stylemix/wordpress header builder plugin – pearl; a new product identity is not establishedDays to revision 706
2026-04-08same kind of change as the line aboveCVE-2024-5468same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed stylemix/wordpress header builder plugin – pearl; a new product identity is not establishedDays to revision 665
2026-04-08Product addedWordfencenot named as affected at publication, now names master addons for elementor – widgets, extensions, theme builder, popup builder & template kitsnot counted: Product identity rewritten with unchanged scopeDays to revision 670 to 706
2026-04-08same kind of change as the line aboveCVE-2024-4265same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed litonice13/master addons – free widgets, hover effects, toggle, conditions, animations for elementor; a new product identity is not establishedDays to revision 706
2026-04-08same kind of change as the line aboveCVE-2024-4580same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed litonice13/master addons – free widgets, hover effects, toggle, conditions, animations for elementor; a new product identity is not establishedDays to revision 692
2026-04-08same kind of change as the line aboveCVE-2024-5382same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed litonice13/master addons – free widgets, hover effects, toggle, conditions, animations for elementor; a new product identity is not establishedDays to revision 670
2026-04-08Product addedWordfencenot named as affected at publication, now names wpzoom addons for elementor – starter templates & widgetsnot counted: Product identity rewritten with unchanged scopeDays to revision 658 to 694
2026-04-08same kind of change as the line aboveCVE-2024-4370same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpzoom/wpzoom addons for elementor (templates, widgets); a new product identity is not establishedDays to revision 694
2026-04-08same kind of change as the line aboveCVE-2024-5147same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpzoom/wpzoom addons for elementor (templates, widgets); a new product identity is not establishedDays to revision 686
2026-04-08same kind of change as the line aboveCVE-2024-5686same vendor as the line abovesame change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpzoom/wpzoom addons for elementor (templates, widgets); a new product identity is not establishedDays to revision 658
2026-04-08Product addedCVE-2024-4371Wordfencenot named as affected at publication, now names codesigner – all in one elementor woocommerce builderNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed codexpert/codesigner – the most compact and user-friendly elementor woocommerce builder; a new product identity is not establishedDays to revision 664
2026-04-08Product addedCVE-2024-4666Wordfencenot named as affected at publication, now names borderless – addons and templates for elementorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed visualmodo/borderless – widgets, elements, templates and toolkit for elementor & gutenberg; a new product identity is not establishedDays to revision 694
2026-04-08Product addedCVE-2024-5020Wordfencenot named as affected at publication, now names envira gallery – image photo gallery, albums, video gallery, slideshows & moreNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed smub/gallery plugin for wordpress – envira photo gallery; a new product identity is not establishedDays to revision 490
2026-04-08Product addedCVE-2024-5449Wordfencenot named as affected at publication, now names wp dark mode – improve accessibility with ai powered dark themeNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wppool/wp dark mode – wordpress dark mode plugin for improved accessibility, dark theme, night mode, and social sharing; a new product identity is not establishedDays to revision 672
2026-04-08Product addedCVE-2024-5647Wordfencenot named as affected at publication, now names robo gallery – photo & image sliderNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed robosoft/photo gallery, images, slider in rbs image gallery; a new product identity is not establishedDays to revision 279
2026-04-08Product addedCVE-2024-5879Wordfencenot named as affected at publication, now names hubspot all-in-one marketing – forms, popups, live chatNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed hubspotdev/hubspot – crm, email marketing, live chat, forms & analytics; a new product identity is not establishedDays to revision 587
2026-04-08Product addedCVE-2024-6069Wordfencenot named as affected at publication, now names pie register – user registration, profiles & content restrictionNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed genetechproducts/registration forms – user registration forms, invitation-based registrations, front-end user profile, login form & content restriction; a new product identity is not establishedDays to revision 638
2026-04-08Product addedCVE-2024-6210Wordfencenot named as affected at publication, now names duplicator – backups & migration plugin – cloud backups, scheduled backups, & moreNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed smub/duplicator – migration & backup plugin; a new product identity is not establishedDays to revision 637
2026-04-08Product addedCVE-2024-6262Wordfencenot named as affected at publication, now names portfolio filter galleryNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed awordpresslife/portfolio gallery – image gallery plugin; a new product identity is not establishedDays to revision 650
2026-04-08Product addedCVE-2024-6365Wordfencenot named as affected at publication, now names product table for woocommerce by wbwNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed woobewoo/product table by wbw; a new product identity is not establishedDays to revision 639
2026-04-08Product addedCVE-2024-6467Wordfencenot named as affected at publication, now names appointment booking calendar plugin and scheduling plugin – bookingpressNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed reputeinfosystems/appointment booking calendar plugin and online scheduling plugin – bookingpress; a new product identity is not establishedDays to revision 631
2026-04-08Product addedCVE-2026-26477mitrenot named as affected at publication, now names dokuwikiNot counted: No products named at publication. record named no affected product at publication — there was nothing to conclude 'not affected' fromDays to revision 5
2026-04-08CVSS base score changedCVE-2026-40035
whole record
VulnCheck
stated at publication 9.8, now states 9.3Assessments not comparable · base scoreCriticalCriticalNot counted: CVSS assessments are not comparable. the displayed maximum pair is not established on the same CVSS v3/v4 version, CNA and assessment context; changed scenarios, competing metrics and v2 bands are not comparableDays to revision 0

Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →