Export limit exceeded: 16287 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (16287 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-87965 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-09-18 | 4.8 Medium |
| The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointment cancellation and confirmation action, deriving the token from a hardcoded source-embedded salt and the appointment's creation timestamp, so unauthenticated attackers who know or guess that timestamp can cancel or confirm arbitrary appointments. | ||||
| CVE-2026-84905 | 2 Eventin, Wordpress | 2 Eventin, Wordpress | 2026-09-18 | 2.7 Low |
| The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker, allowing users with contributor-level access and above to create new WordPress user accounts that carry capabilities beyond their own, including publishing content and uploading files, and, by supplying an email address they control, to obtain a working login to the created account. | ||||
| CVE-2026-86447 | 2 Learnpress, Wordpress | 2 Learnpress, Wordpress | 2026-09-18 | 5.3 Medium |
| The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative course tools, allowing unauthenticated attackers to list every enrolled student's display name and user identifier against the course they are enrolled on, and to recover their email addresses through the same handler's search filter. | ||||
| CVE-2026-84906 | 2 Eventin, Wordpress | 2 Eventin, Wordpress | 2026-09-18 | 5.3 Medium |
| The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or which order it belongs to, allowing unauthenticated visitors to mark unpaid orders of any value as paid by replaying the transaction of a single genuine low-value payment. | ||||
| CVE-2026-90923 | 2 Autopay, Wordpress | 2 Autopay, Wordpress | 2026-09-18 | 6.5 Medium |
| The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders. | ||||
| CVE-2026-91016 | 2 Motors, Wordpress | 2 Motors, Wordpress | 2026-09-18 | 5.3 Medium |
| The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private car listings - including titles, prices, media URLs and seller notes - by supplying only the target's numeric user id. | ||||
| CVE-2026-86824 | 2 Newsletter, Wordpress | 2 Newsletter, Wordpress | 2026-09-18 | 4.8 Medium |
| The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed hash, allowing an unauthenticated attacker who recovers that key offline to forge tracking links, obtain any subscriber's session token, and read and modify that subscriber's stored personal data. | ||||
| CVE-2026-86446 | 2 Learnpress, Wordpress | 2 Learnpress, Wordpress | 2026-09-18 | 3.7 Low |
| The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is checked, allowing unauthenticated attackers to obtain the correct answer to every option of a question, along with the instructor's explanation, on courses configured to be taken without enrolling. | ||||
| CVE-2026-86311 | 2 10web, Wordpress | 2 Photo Gallery By 10web – Mobile-friendly Image Gallery, Wordpress | 2026-09-17 | 6.4 Medium |
| The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-66580 | 2 Rextheme, Wordpress | 2 Product Feed Manager, Wordpress | 2026-09-17 | 8.5 High |
| Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions. | ||||
| CVE-2026-74005 | 2 Publishpress, Wordpress | 2 Publishpress Series, Wordpress | 2026-09-17 | 5.4 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions. | ||||
| CVE-2026-90887 | 2 Wordpress, Wpinventory | 2 Wordpress, Wp Inventory Manager | 2026-09-17 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions. | ||||
| CVE-2026-62108 | 2 Miniorange, Wordpress | 2 Headless Single Sign On, Wordpress | 2026-09-17 | 9.8 Critical |
| Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions. | ||||
| CVE-2026-66625 | 2 Wcvendors, Wordpress | 2 Wc Vendors Marketplace, Wordpress | 2026-09-17 | 7.6 High |
| Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions. | ||||
| CVE-2026-66676 | 2 Matrixaddons, Wordpress | 2 Easy Invoice, Wordpress | 2026-09-17 | 5.3 Medium |
| Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions. | ||||
| CVE-2026-66573 | 2 Crocoblock. Jetimpex Inc., Wordpress | 2 Jettabs, Wordpress | 2026-09-17 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions. | ||||
| CVE-2026-66576 | 2 Crocoblock, Wordpress | 2 Jetblocks For Elementor, Wordpress | 2026-09-17 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions. | ||||
| CVE-2026-92465 | 2 Themehunk, Wordpress | 2 Mega Menu, Wordpress | 2026-09-17 | 7.6 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects WP Mega Menu: from n/a through 1.4.2. | ||||
| CVE-2026-90986 | 2 Codepress It Solutions Llc, Wordpress | 2 Visitor Traffic Real Time Statistics Pro, Wordpress | 2026-09-17 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions. | ||||
| CVE-2026-66628 | 2 Wordpress, Wplab | 2 Wordpress, Wp-lister Lite For Ebay | 2026-09-17 | 7.6 High |
| Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions. | ||||