Search Results (16111 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-86446 2 Learnpress, Wordpress 2 Learnpress, Wordpress 2026-09-18 3.7 Low
The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is checked, allowing unauthenticated attackers to obtain the correct answer to every option of a question, along with the instructor's explanation, on courses configured to be taken without enrolling.
CVE-2026-86311 2 10web, Wordpress 2 Photo Gallery By 10web – Mobile-friendly Image Gallery, Wordpress 2026-09-17 6.4 Medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-66580 2 Rextheme, Wordpress 2 Product Feed Manager, Wordpress 2026-09-17 8.5 High
Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.
CVE-2026-74005 2 Publishpress, Wordpress 2 Publishpress Series, Wordpress 2026-09-17 5.4 Medium
Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.
CVE-2026-90887 2 Wordpress, Wpinventory 2 Wordpress, Wp Inventory Manager 2026-09-17 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.
CVE-2026-62108 2 Miniorange, Wordpress 2 Headless Single Sign On, Wordpress 2026-09-17 9.8 Critical
Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.
CVE-2026-66625 2 Wcvendors, Wordpress 2 Wc Vendors Marketplace, Wordpress 2026-09-17 7.6 High
Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.
CVE-2026-66676 2 Matrixaddons, Wordpress 2 Easy Invoice, Wordpress 2026-09-17 5.3 Medium
Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.
CVE-2026-66573 2 Crocoblock. Jetimpex Inc., Wordpress 2 Jettabs, Wordpress 2026-09-17 6.5 Medium
Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.
CVE-2026-66576 2 Crocoblock, Wordpress 2 Jetblocks For Elementor, Wordpress 2026-09-17 6.5 Medium
Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.
CVE-2026-92465 2 Themehunk, Wordpress 2 Mega Menu, Wordpress 2026-09-17 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects WP Mega Menu: from n/a through 1.4.2.
CVE-2026-90986 2 Codepress It Solutions Llc, Wordpress 2 Visitor Traffic Real Time Statistics Pro, Wordpress 2026-09-17 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions.
CVE-2026-66628 2 Wordpress, Wplab 2 Wordpress, Wp-lister Lite For Ebay 2026-09-17 7.6 High
Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.
CVE-2026-74017 2 Wordpress, Wpeverest 2 Wordpress, User Registration 2026-09-17 5.3 Medium
Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.
CVE-2026-78295 2 Wordpress, Xagio 2 Wordpress, Xagio Seo 2026-09-17 8.8 High
Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.
CVE-2026-89029 2 Adenion, Wordpress 2 Blog2social, Wordpress 2026-09-17 4.3 Medium
Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. The b2s_get_select_mandant_user AJAX handler in includes/Ajax/Get.php resolves arbitrary user IDs supplied in the owner parameter to display names without verifying that the caller is authorized to read user account data, allowing any user with the edit_posts capability to map WordPress user IDs to display names and confirm account existence for arbitrary IDs.
CVE-2026-66578 2 Propertyhive, Wordpress 2 Propertyhive, Wordpress 2026-09-17 6.5 Medium
Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.
CVE-2026-66608 2 Unlimited-elements, Wordpress 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Wordpress 2026-09-17 6.4 Medium
Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.
CVE-2026-74000 2 Wordpress, Wp.insider 2 Wordpress, Simple Membership 2026-09-17 5.3 Medium
Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.
CVE-2026-89023 2 Themeatelier, Wordpress 2 Domain For Sale, Wordpress 2026-09-17 8.6 High
ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can retrieve stored offer records, delete arbitrary offers by numeric identifier, and access dashboard statistics to disclose bidder contact information, offer details, messages, verification tokens, and business data.