Search

Search Results (386439 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-42705 2026-10-11 7.5 High
Unauthenticated Broken Access Control in Grand News <= 3.4 versions.
CVE-2026-42696 2026-10-11 10 Critical
Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1.5.19 versions.
CVE-2026-40808 2026-10-11 6.5 Medium
Subscriber Broken Access Control in Jetpack VideoPress <= 3.6 versions.
CVE-2026-40805 2026-10-11 7.7 High
Subscriber Arbitrary File Deletion in PeepSo <= 9.0.5.4 versions.
CVE-2026-40802 2026-10-11 7.6 High
Subscriber Settings Change in Pubjet | پاب‌جت <= 5.4.8 versions.
CVE-2026-40801 2026-10-11 8.1 High
Subscriber Broken Access Control in Wordable <= 8.2.10 versions.
CVE-2026-40777 2026-10-11 8.1 High
Subscriber Broken Access Control in WPSection <= 1.5.1 versions.
CVE-2026-39802 2026-10-11 8.1 High
Unauthenticated Remote Code Execution (RCE) in Everest Backup <= 2.3.13 versions.
CVE-2026-39801 2026-10-11 9.8 Critical
Subscriber Privilege Escalation in AIWU <= 1.5.9 versions.
CVE-2026-18558 2026-10-11 6.4 Medium
The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embeddoc' shortcode in all versions up to, and including, 2.7.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-17025 2026-10-11 6.4 Medium
The Graphene theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'Current location' and 'Author profile image URL' Profile Fields in all versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-16776 2026-10-11 6.4 Medium
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.14.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress's save-time wp_kses_post does not neutralize the payload because the attack is delivered via shortcode attributes rather than raw HTML in post content, allowing the unescaped values to survive to render time.
CVE-2026-14882 2026-10-11 6.4 Medium
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'brizy-compiled-sections' parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-14877 2026-10-11 6.4 Medium
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id attribute in all versions up to, and including, 1.12.03 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-14379 2026-10-11 6.4 Medium
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_id' parameter in all versions up to, and including, 7.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-14335 2 Smub, Wordpress-extensions 3 Easy Digital Downloads, Easy Digital Downloads – Ecommerce Payments And Subscriptions Made Easy, Easy Digital Downloads 2026-10-11 7.2 High
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PayPal IPN Parameters in all versions up to, and including, 3.6.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-12054 2026-10-11 6.1 Medium
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'REFERRER' parameter in all versions up to, and including, 3.3.57 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
CVE-2026-107742 2026-10-11 7.2 High
The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 2.34.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable because a comment author Name value containing ' src=' and an event-handler payload contains no HTML tags or quote characters, allowing it to survive WordPress core's sanitize_text_field and land verbatim inside the alt attribute, where the plugin's own str_replace subsequently injects the single quote that breaks out of the attribute context.
CVE-2026-107657 2026-10-11 7.2 High
The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<custom user attribute field name, e.g. profile_test>' parameter in all versions up to, and including, 1.7.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires an administrator to have configured a text-type custom user attribute whose display format places %value% inside an HTML attribute context (e.g., the documented pattern &lt;a href="%value%"&gt;Custom link&lt;/a&gt;), and for front-end user profiles to be enabled — both of which reflect the plugin's standard, documented configuration.
CVE-2026-107434 2026-10-11 5.4 Medium
Subscriber Bypass Vulnerability in MicroPayments <= 3.2.9 versions.