Export limit exceeded: 16120 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (16120 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-62113 | 2 Anh Tran, Wordpress | 2 Slim Seo, Wordpress | 2026-09-13 | 4.3 Medium |
| Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4.10.0 versions. | ||||
| CVE-2026-62136 | 2 Wordpress, Wpdesk | 2 Wordpress, Flexible Quantity – Measurement Price Calculator For Woocommerce | 2026-09-13 | 5.3 Medium |
| Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 versions. | ||||
| CVE-2026-62089 | 2 Pixar Labs, Wordpress | 2 Master Addons For Elementor, Wordpress | 2026-09-13 | 7.1 High |
| Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2. | ||||
| CVE-2026-15398 | 2 Arraytics, Wordpress | 2 Eventin – Event Calendar, Event Registration, Tickets & Booking (ai Powered), Wordpress | 2026-09-13 | 4.3 Medium |
| The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.22. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to bypass payment for paid events, fraudulently mark orders as completed, deplete ticket inventory, and trigger confirmation emails for tickets never purchased. This is exploitable by unauthenticated attackers because the wp_rest nonce is publicly emitted on every frontend page, and the order creation endpoint mints and returns an order_access_token to any caller possessing that nonce — giving unauthenticated users all credentials required to reach the privileged update_booking_status branch. | ||||
| CVE-2026-66632 | 2 Replywp, Wordpress | 2 Simple Cloudfare Turnstile, Wordpress | 2026-09-13 | 6.5 Medium |
| Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions. | ||||
| CVE-2026-66674 | 2 Replywp, Wordpress | 2 Simple Cloudfare Turnstile, Wordpress | 2026-09-13 | 5.6 Medium |
| Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions. | ||||
| CVE-2026-81789 | 2 Maartenbelmans, Wordpress | 2 Advanced Product Fields Product Addons For Woocommerce, Wordpress | 2026-09-13 | 8.6 High |
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6. | ||||
| CVE-2026-11446 | 2 Arraytics, Wordpress | 2 Booktics – Booking Calendar For Appointments And Service Businesses, Wordpress | 2026-09-13 | 5.3 Medium |
| The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.0.23. This is due to the create_order_permission() permission callback on the POST /wp-json/booktics/v1/orders REST route unconditionally returning true, combined with find_and_update_guest() overwriting an existing customer record's stored name, phone, and wp_user_id whenever the caller-supplied email matches, with no proof of ownership. This makes it possible for unauthenticated attackers to overwrite the contact details (name and phone) of any existing customer whose email address they know, poisoning downstream reminder emails, SMS, calendar invites, and CRM data. | ||||
| CVE-2026-78172 | 2 Themify, Wordpress | 2 Woocommerce Product Filter, Wordpress | 2026-09-13 | 6.1 Medium |
| The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query Parameter Name in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. | ||||
| CVE-2026-6641 | 2 Davidlingren, Wordpress | 2 Media Library Assistant, Wordpress | 2026-09-13 | 6.4 Medium |
| The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35. This is due to insufficient input sanitization and output escaping on the mla_link_href parameter when mla_output is set to 'paginate_links', where the _paginate_links() function processes the value through mla_process_shortcode_parameter() and _replace_query_parameter() without proper URL escaping, then outputs it directly in href attributes without applying esc_url(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-6642 | 2 Davidlingren, Wordpress | 2 Media Library Assistant, Wordpress | 2026-09-13 | 6.4 Medium |
| The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset field values when they are rendered in HTML attribute contexts in the mla_generate_bulk_edit_form_fieldsets() function and mla-bulk-edit-fieldsets.tpl template. While wp_kses() filtering is applied during preset export for users without unfiltered_html capability, this does not prevent attribute injection attacks since the malicious payload consists of quotes and HTML attributes rather than HTML tags. When preset values are retrieved and rendered, they are directly assigned to template variables without esc_attr() escaping and then inserted into input element value attributes via simple string replacement. This makes it possible for authenticated attackers, with Author-level access and above (upload_files capability), to inject arbitrary web scripts that execute when an administrator imports the poisoned preset and the targeted input field receives focus. | ||||
| CVE-2026-6640 | 2 Davidlingren, Wordpress | 2 Media Library Assistant, Wordpress | 2026-09-13 | 6.4 Medium |
| The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-15439 | 2 Rubengc, Wordpress | 2 Gamipress – Gamification Plugin To Reward Points, Achievements, Badges & Ranks In Wordpress, Wordpress | 2026-09-13 | 6.5 Medium |
| The GamiPress plugin for WordPress is vulnerable to authenticated (Subscriber+) SQL Injection via the 'q' parameter of the wpForo integration AJAX selector (action gamipress_wpforo_get_posts) in versions up to, and including, 7.9.7. The value is passed only through $wpdb->esc_like() and interpolated directly into a single-quoted LIKE clause with no %s placeholder. Because esc_like() runs after WordPress core magic quotes, it doubles the injected backslash (\' -> \\'), which MySQL reads as one literal backslash followed by a live closing quote, allowing the attacker to break out of the string and inject boolean-based SQL. The wpForo plugin only needs to be active to register the callback; no wpForo vulnerability is used. Requires a Subscriber account, which can read the gamipress_admin nonce (exposed on every admin page, e.g. /wp-admin/profile.php). Note: the researcher's Simple:Press vectors (PoC 2 & 3) do not reproduce in current code, which uses $wpdb->prepare() with %s placeholders; only the wpForo selector is confirmed. | ||||
| CVE-2026-62140 | 2 Expresstech, Wordpress | 2 Quiz And Survey Master, Wordpress | 2026-09-13 | 5.3 Medium |
| Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions. | ||||
| CVE-2026-62107 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-09-13 | 8.8 High |
| Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions. | ||||
| CVE-2026-62114 | 2 Wordpress, Wpchill | 2 Wordpress, Passster | 2026-09-13 | 5.3 Medium |
| Unauthenticated Broken Access Control in Passster <= 4.3.13 versions. | ||||
| CVE-2026-62132 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-09-13 | 5.3 Medium |
| Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions. | ||||
| CVE-2026-87918 | 2 Wordpress, Wpbot | 2 Wordpress, Wpot | 2026-09-13 | 5.3 Medium |
| The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls, and consume the associated cost, using the site's own configured API keys. | ||||
| CVE-2026-89080 | 2 Really-simple-plugins, Wordpress | 2 Really Simple Security, Wordpress | 2026-09-13 | 7.5 High |
| The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator. | ||||
| CVE-2026-62105 | 2 Themerex, Wordpress | 2 Themerex Addons, Wordpress | 2026-09-13 | 9.8 Critical |
| Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions. | ||||