Export limit exceeded: 385542 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (385542 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-105194 | 1 Wordpress-extensions | 1 Easy Digital Downloads | 2026-10-09 | 4.3 Medium |
| The Easy Digital Downloads WordPress plugin before 3.7.1 does not restrict a block's order data to the current user, allowing users with subscriber-level access to view other customers' recent order products and obtain signed download links that grant access to paid digital files without purchase. | ||||
| CVE-2026-105195 | 1 Wordpress-extensions | 1 Booking Calendar | 2026-10-09 | 2.7 Low |
| The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration. | ||||
| CVE-2026-105196 | 1 Wordpress-extensions | 1 Latepoint | 2026-10-09 | 3.3 Low |
| The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, allowing an authenticated user holding the LatePoint Agent role, normally restricted to their own records, to read and modify other agents' profile data and read other agents' bookings and associated customer details when the Abilities API feature is enabled. | ||||
| CVE-2026-105197 | 1 Wordpress-extensions | 1 Latepoint | 2026-10-09 | 2.7 Low |
| The Appointment Booking Plugin WordPress plugin before 5.6.5 does not verify that a backend staff user is authorized to act on the specific record targeted for deletion, allowing an authenticated user with a record-scoped staff role to irreversibly delete any order, customer, or transaction on the site, including records belonging to other staff and outside their assigned scope. | ||||
| CVE-2026-105198 | 1 Wordpress-extensions | 1 Latepoint | 2026-10-09 | 5.3 Medium |
| The Appointment Booking Plugin WordPress plugin before 5.7.3 does not verify that the caller owns the order referenced by an order-item identifier before rendering that order's confirmation summary, letting an unauthenticated visitor retrieve any customer's name, contact details and order confirmation code by supplying a sequential order-item id. | ||||
| CVE-2026-105260 | 1 Wordpress-extensions | 1 Database Addon For Wpforms | 2026-10-09 | 4.3 Medium |
| The Database Addon For WPForms ( wpforms entries ) WordPress plugin before 1.1.1 does not verify the CSRF nonce when the field is omitted and performs no capability check of its own, allowing attackers to delete arbitrary stored form entries by tricking a logged-in administrator into loading a crafted page. | ||||
| CVE-2026-86826 | 1 Wordpress-extensions | 1 Backwpup | 2026-10-09 | 5.9 Medium |
| The BackWPup WordPress plugin before 5.7.7 does not properly restrict web access to the working directory it uses during backup restores, allowing unauthenticated attackers, on webservers that do not honour .htaccess rules such as NGINX, to download the full backup archive (database dump and site files, including credentials and secret keys) left behind by an interrupted restore. | ||||
| CVE-2026-86827 | 1 Wordpress-extensions | 1 Backwpup | 2026-10-09 | 5.3 Medium |
| The BackWPup WordPress plugin before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress's internal scheduled-event dispatch, allowing unauthenticated attackers to force any existing backup job to run immediately, independent of its configured trigger type or schedule. | ||||
| CVE-2026-86828 | 1 Wordpress-extensions | 1 Backwpup | 2026-10-09 | 6.6 Medium |
| The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code execution. | ||||
| CVE-2026-94244 | 1 Wordpress-extensions | 1 Wallet System For Woocommerce | 2026-10-09 | 4.3 Medium |
| The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not perform any capability check, and relies on a token any authenticated user can obtain from a front-end page, before generating a report containing every customer's wallet transaction history, allowing any authenticated user, such as a subscriber, to disclose all users' names, email addresses, roles, transaction amounts, payment methods and dates. | ||||
| CVE-2026-94245 | 1 Wordpress-extensions | 1 Wallet System For Woocommerce | 2026-10-09 | 6.5 Medium |
| The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the user submitting a wallet transfer owns the wallet being debited, allowing any authenticated user, including one with only the Subscriber role, to move an arbitrary user's wallet balance, including an administrator's, into an account they control. | ||||
| CVE-2026-94246 | 1 Wordpress-extensions | 1 Wallet System For Woocommerce | 2026-10-09 | 6.3 Medium |
| The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the wallet account named in a withdrawal submission belongs to the user making it, allowing any authenticated user, such as a subscriber, to file a withdrawal request against another user's wallet for an amount and a payout destination of their choosing, and to indefinitely prevent that user from submitting withdrawals of their own. | ||||
| CVE-2026-94258 | 1 Wordpress-extensions | 1 Sms Alert | 2026-10-09 | 2.7 Low |
| The SMS Alert WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning their stored billing phone numbers, allowing an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network. This affects multisite only, and requires the SMS Alert WordPress plugin before 4.0.1's gateway credentials to be stored on the acting administrator's own site. | ||||
| CVE-2026-94275 | 1 Wordpress-extensions | 1 Track Orders For Woocommerce | 2026-10-09 | 5.3 Medium |
| The Track Orders for WooCommerce WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing unauthenticated attackers to obtain a customer's name, email address, phone number, postal address and order history by supplying that customer's email address. | ||||
| CVE-2026-85097 | 2 Bricksforge, Wordpress-extensions | 2 Bricksforge, Bricksforge | 2026-10-09 | 9.8 Critical |
| The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to insufficient validation of the attacker-controlled URL field in the 'temporaryFileUploads' parameter during form submission. An unauthenticated attacker can first obtain a valid nonce via the bricksforge_regenerate_nonce AJAX endpoint, then upload a GIF/PHP polyglot file to the temporary upload directory where MIME type validation is correctly performed. Subsequently, the attacker can submit a form with a crafted 'temporaryFileUploads' parameter where the server-side file path points to the validated GIF file, but the attacker-controlled url field ends with a .php extension. This makes it possible for unauthenticated attackers to upload and execute arbitrary PHP code on the server. | ||||
| CVE-2026-93699 | 2 Webpros, Wordpress-extensions | 2 Wordpress-toolkit, Wp Toolkit | 2026-10-09 | N/A |
| Argument injection in WP Toolkit for cPanel allows local users to execute arbitrary code as other accounts on the same server. | ||||
| CVE-2026-84224 | 2026-10-09 | 4.1 Medium | ||
| The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetching it, allowing users with editor-level access and above to make the site issue requests to internal services that are not otherwise reachable, and to tell which of those are live from the response. | ||||
| CVE-2026-84220 | 2026-10-09 | 4.8 Medium | ||
| The Kirki WordPress plugin before 6.3.2 does not prevent shortcodes held in comments from being executed when it renders them, and displays comments regardless of their moderation status, allowing unauthenticated visitors to run shortcodes registered on the site and to read private custom fields of the page being viewed. | ||||
| CVE-2026-89191 | 1 Sqlview | 1 Sqlview Kris | 2026-10-09 | 6.8 Medium |
| Unsanitised input in the "template name" field of SQLView KRIS's Workflow Template feature is rendered in "onclick" attributes on the main dashboard without proper server-side sanitisation, allowing an attacker with administrative access to inject and store malicious scripts that execute in the browsers of affected users. | ||||
| CVE-2026-71183 | 1 Apache | 1 Dolphinscheduler | 2026-10-09 | 7.1 High |
| An authorization vulnerability in Apache DolphinScheduler allows authenticated users to obtain information about data sources they are not authorized to access through the /unauth-datasource and /authed-datasource endpoints. These endpoints fail to enforce the required data source access controls and return sensitive connection information, including data source passwords. As a result, an authenticated user without permission to access a data source can retrieve its connection details and credentials. Successful exploitation exposes sensitive data source information and may enable unauthorized access to the underlying databases using the disclosed credentials. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue. | ||||