Export limit exceeded: 14785 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14785 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65514 | 2 Codepeople, Wordpress | 2 Appointment Hour Booking, Wordpress | 2026-08-02 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions. | ||||
| CVE-2026-65518 | 2 Scott Paterson, Wordpress | 2 Accept Donations With Paypal & Stripe, Wordpress | 2026-08-02 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions. | ||||
| CVE-2026-12981 | 2 Cafehaus, Wordpress | 2 Cafehaus Api, Wordpress | 2026-08-02 | 7.5 High |
| The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts. | ||||
| CVE-2026-14603 | 2 Wordpress, Wowoptin | 2 Wordpress, Next-gen Popup Maker | 2026-08-02 | 7.5 High |
| The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database. | ||||
| CVE-2026-15665 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluent Support – Helpdesk & Customer Support Ticket System | 2026-08-02 | 6.4 Medium |
| The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The XSS payload is in a hidden attribute so it only fires in specific browsers when specific access keys are used making exploitation unlikely. | ||||
| CVE-2026-12654 | 2 Payment Plugins, Wordpress | 2 Payment Plugins For Stripe Woocommerce, Wordpress | 2026-08-02 | 5.3 Medium |
| The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary pending asynchronous WooCommerce orders as paid by forging a charge.pending event with attacker-controlled metadata.order_id, metadata.gateway_id, and a charge object carrying status=succeeded and captured=true, triggering payment_complete() and downstream fulfillment flows with an attacker-supplied transaction ID. Exploitation requires the merchant to have left the webhook_secret_test or webhook_secret_live option blank, which is the plugin's default state until a Stripe-issued whsec_ value is manually configured; once a non-empty secret is set, the signature verification cannot be bypassed. | ||||
| CVE-2026-15739 | 2 Widgetpack, Wordpress | 2 Rich Showcase For Google Reviews, Wordpress | 2026-08-02 | 6.4 Medium |
| The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and including, 6.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-13605 | 2 Photoswipe, Wordpress | 2 Photoswipe, Wordpress | 2026-08-02 | 6.8 Medium |
| The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping. Because the title attribute survives the post-content sanitization applied to users who lack the unfiltered_html capability, an authenticated user with Author-level access can store a JavaScript payload that executes in the browser of any visitor, including an administrator, who clicks the link. | ||||
| CVE-2026-13690 | 2 Userswp, Wordpress | 2 Userswp, Wordpress | 2026-08-02 | 7.4 High |
| The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user. | ||||
| CVE-2026-13692 | 2 Payu, Wordpress | 2 Payu Commercepro Plugin, Wordpress | 2026-08-02 | 5.3 Medium |
| The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders. | ||||
| CVE-2026-14234 | 2 Wolf, Wordpress | 2 Wolf, Wordpress | 2026-08-02 | 7.1 High |
| The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker to trick a logged-in administrator into writing arbitrary content, including a malicious script, into a post via a cross-site request, resulting in stored Cross-Site Scripting. | ||||
| CVE-2026-18437 | 2 Mailerpress, Wordpress | 2 Mailerpress – Newsletter, Email Marketing & Ai Automation, Wordpress | 2026-08-02 | 5.3 Medium |
| The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details. | ||||
| CVE-2026-18436 | 2 Mailerpress, Wordpress | 2 Mailerpress – Newsletter, Email Marketing & Ai Automation, Wordpress | 2026-08-02 | 5.3 Medium |
| The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<id>/restore-revision/<revision_id>). The route in the vulnerable range was registered without a permissionCallback, allowing the restoreRevision() handler to run for unauthenticated requests and overwrite a campaign's content_html with any prior revision. This makes it possible for unauthenticated attackers to modify campaign content by restoring an arbitrary revision. | ||||
| CVE-2026-11961 | 2 Wordpress, Wpuserregistration | 2 Wordpress, User Registration \& Membership | 2026-08-02 | 8.1 High |
| The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user role, allowing unauthenticated users to register into an arbitrary published membership tier and obtain its role — up to administrator when such a tier exists. | ||||
| CVE-2026-11966 | 2 Wordpress, Wpuserregistration | 2 Wordpress, User Registration \& Membership | 2026-08-02 | 5.3 Medium |
| The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membership payment actions and acts on a caller-supplied user identifier, allowing unauthenticated attackers to delete recently-registered, payment-pending user accounts. | ||||
| CVE-2026-8825 | 2 Elementor, Wordpress | 2 Elementor Website Builder, Wordpress | 2026-08-02 | 4.9 Medium |
| The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators). | ||||
| CVE-2026-7232 | 2 Formcrafts, Wordpress | 2 Formcraft, Wordpress | 2026-08-02 | 7.2 High |
| The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit chain combines a server-side gap — where composite matrix sub-field keys such as field2_0 and field2_1 are never passed through the sanitization loop and are stored raw via $wpdb->insert() — with a client-side gap where DOMPurify is only invoked when typeof field.value === 'string', but matrix values arrive from the server as arrays, bypassing the check before being mapped to strings and injected into the DOM. Additionally, the same sink is reachable via a second attack vector: array-typed field values are passed through htmlentities() on submission but later reversed by html_entity_decode() at formcraft-main.php:2608 and :2122, restoring the malicious payload before storage and rendering. | ||||
| CVE-2026-24537 | 2 Alex Volkov, Wordpress | 2 Wp Accessibility Helper, Wordpress | 2026-08-02 | 4.3 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions. | ||||
| CVE-2026-27372 | 2 Peprodev, Wordpress | 2 Peprodev Ultimate Invoice, Wordpress | 2026-08-02 | 6.5 Medium |
| Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions. | ||||
| CVE-2026-27391 | 2 Stylemixthemes, Wordpress | 2 Ulisting, Wordpress | 2026-08-02 | 5.4 Medium |
| Subscriber Broken Access Control in uListing <= 2.2.0 versions. | ||||