Search

Search Results (402870 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-97300 2026-10-06 6.5 Medium
Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.
CVE-2026-97275 2026-10-06 5.3 Medium
Improper Validation of Specified Quantity in Input vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Input Data Manipulation.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28.
CVE-2026-97257 2026-10-06 8.8 High
Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.
CVE-2026-97071 2026-10-06 5.3 Medium
Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17.
CVE-2026-94299 2026-10-06 6.5 Medium
The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers to forge payment confirmations and change the status of arbitrary orders on any installation where that secret has been left at its default empty value.
CVE-2026-94278 2026-10-06 5.5 Medium
The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belonging to other users, including administrators, and to corrupt unrelated stored site data that referenced the old file path.
CVE-2026-93617 2026-10-06 7.2 High
Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1.
CVE-2026-41563 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions.
CVE-2026-41558 2026-10-06 7.5 High
Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.
CVE-2026-39791 2026-10-06 5.3 Medium
Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions.
CVE-2026-39789 2026-10-06 7.5 High
Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.
CVE-2026-39760 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.
CVE-2026-39757 2026-10-06 9.9 Critical
Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions.
CVE-2026-39756 2026-10-06 6.5 Medium
Unauthenticated Insecure Direct Object References (IDOR) in Wappointment <= 2.7.7 versions.
CVE-2026-39755 2026-10-06 9.9 Critical
Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions.
CVE-2026-39754 2026-10-06 6.5 Medium
Contributor Arbitrary File Download in Piotnet Addons For Elementor <= 7.1.71 versions.
CVE-2026-39753 2026-10-06 9.8 Critical
Unauthenticated Privilege Escalation in Taskbot <= 6.6 versions.
CVE-2026-39752 2026-10-06 7.7 High
Contributor Arbitrary File Deletion in Jobs for WordPress <= 2.8.2 versions.
CVE-2026-39751 2026-10-06 7.5 High
Unauthenticated Broken Access Control in PayPlug for WooCommerce (Official) <= 3.1.0 versions.
CVE-2026-39750 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.0.6 versions.