Export limit exceeded: 383093 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (383093 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-91022 1 Wordpress-extensions 1 Motors 2026-10-02 6.8 Medium
The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator.
CVE-2026-91023 1 Wordpress-extensions 1 Motors 2026-10-02 3.1 Low
The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.
CVE-2026-94298 1 Wordpress-extensions 1 Buildkit 2026-10-02 6.2 Medium
The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.
CVE-2026-97317 2 Rafflepress, Wordpress-extensions 2 Giveaways And Contests By Rafflepress, Giveaways And Contests By Rafflepress 2026-10-02 5.3 Medium
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured.
CVE-2026-97318 2 Rafflepress, Wordpress-extensions 2 Giveaways And Contests By Rafflepress, Giveaways And Contests By Rafflepress 2026-10-02 6.1 Medium
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary external site.
CVE-2026-102565 2 Booking Algorithms, Wordpress-extensions 2 Ba Book Everything, Ba Book Everything 2026-10-02 7.2 High
The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_service_qty' parameter in all versions up to, and including, 1.8.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that an administrator or other privileged user opens the injected order record in the plugin's wp-admin order management area, which is the plugin's ordinary order-review workflow.
CVE-2026-16000 1 Legion Of The Bouncy Castle Inc. 1 Bc-csharp 2026-10-02 N/A
Missing cryptographic step in the DSTU 7624 CCM mode implementation (KCcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can observe encrypted messages of known or chosen content to forge ciphertexts with valid authentication tags, via messages encrypted without associated data. The cause is that the G1 block, which binds the nonce, the message length and the parameter flags into the CBC-MAC, was processed only when associated data was present. Without associated data the tag was a CBC-MAC of the plaintext alone, independent of the nonce. Only applications that use KCcmBlockCipher directly and supply no associated data are affected.
CVE-2026-97641 2 Comesio, Wordpress-extensions 2 Relevanssi – A Better Search, Relevanssi 2026-10-02 7.2 High
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 4.28.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the administrator has configured a non-empty value for the "Allowable tags in excerpts" setting, such as the default example value of <p><a><strong>, as the prefix-matching regex must have an allowable tag whose name is a prefix of the injected tag name.
CVE-2026-12951 2 Wcmp, Wordpress-extensions 2 Multivendorx – Woocommerce Multivendor Marketplace Ai Powered Solutions, Multivendorx 2026-10-02 6.5 Medium
The Dc Woocommerce Multi Vendor plugin for WordPress is vulnerable to SQL Injection via the 'order_by' parameter of the /multivendorx/v1/compliance/report-abuse REST endpoint in versions up to and including 5.0.18. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query — the value is concatenated directly into an ORDER BY clause where esc_sql() (which only neutralizes characters needed to break out of quoted string literals) provides no protection. This makes it possible for authenticated attackers, with vendor-level access and above (users granted the 'edit_stores' capability), to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-102002 2 Themeisle, Wordpress-extensions 2 Otter Blocks – Gutenberg Blocks, Page Builder For Gutenberg Editor & Fse, Otter Blocks 2026-10-02 3.1 Low
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.6 via the 'otter_form_widget_filter' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the email addresses of the five most recent form submitters, their submission dates, and the site's total form submission count. The widget is registered whenever the themeisle_blocks_form_emails option is non-empty — the normal state after any Form block has been saved — meaning the exposure is active on any standard site using the plugin's form feature.
CVE-2026-96566 2 Satollo, Wordpress-extensions 2 Newsletter – Send Awesome Emails From Wordpress, Newsletter 2026-10-02 7.2 High
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'np1' Custom Field Parameter in all versions up to, and including, 9.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The subscription endpoint (na=sa) requires no nonce, no capability check, and no CAPTCHA, and the payload can be smuggled past email-address validation by embedding the {profile_1} placeholder in the local part of the submitted address, since WordPress's is_email() permits curly braces there.
CVE-2026-97342 2 Jetmonsters, Wordpress-extensions 2 Jetformbuilder, Jetformbuilder 2026-10-02 7.2 High
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action in all versions up to, and including, 3.6.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is submitted via the unauthenticated wp_ajax_nopriv_jet_form_builder_submit endpoint, stored verbatim into post meta through the Insert/Update Post action, and later rendered unescaped by the Select Field block template when the get_from_db option generator copies raw meta values into option value attributes and label content.
CVE-2026-96871 2 Kitae-park, Wordpress-extensions 2 Mang Board Wp, Mang Board 2026-10-02 7.2 High
The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable on any board configured with the default write_level=0 (guest posting) and editor_type=N settings, which are the out-of-the-box defaults for newly created boards.
CVE-2026-100107 2 Extendthemes, Wordpress-extensions 2 Kubio Ai Page Builder, Kubio Ai Page Builder 2026-10-02 7.2 High
The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 2.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-93756 2 Smashballoon, Wordpress-extensions 2 Smash Balloon Social Post Feed, Smash Balloon Social Post Feed 2026-10-02 7.2 High
The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Facebook Comment Message via v-html in Admin Builder Preview in all versions up to, and including, 4.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute whenever an administrator accesses the feed builder preview page. This attack requires only a Facebook account to post a comment on the connected Facebook Page, with no WordPress credentials needed; additionally, the use of v-show rather than v-if means injected HTML — including onerror handlers — is evaluated in the DOM even when the comment section is not visually displayed. When combined with the lack of URL validation in the cff_install_addon AJAX handler (admin/addon-functions.php), an injected script running in an administrator's session can trigger arbitrary plugin installation from an attacker-controlled URL, which may result in server-side code execution.
CVE-2026-95670 2 Mihdan, Wordpress-extensions 2 No External Links Project, No External Links 2026-10-02 7.2 High
The No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the administrator has enabled the 'Link Encoding: Base64' option in the plugin settings.
CVE-2026-96647 2 Webilia, Wordpress-extensions 2 Listdom: Ai-powered Business Directory With Classifieds Ads Listings, Listdom: Ai-powered Business Directory With Classifieds Ads Listings 2026-10-02 6.4 Medium
The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[remark]' Parameter in all versions up to, and including, 6.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users because the listing-creation branch of the AJAX handler omits a capability check, and the required nonce is publicly emitted on any page containing the [listdom-dashboard] shortcode.
CVE-2026-97634 2 Stellarwp, Wordpress-extensions 2 Event Tickets And Registration, Event Tickets And Registration 2026-10-02 6.5 Medium
The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.29.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. A Contributor-level user can reach the vulnerable code path by supplying a post_id they authored, as the can_access_page() gate requires only post authorship rather than the edit_others_posts capability for post owners.
CVE-2026-97338 2 Codename065, Wordpress-extensions 2 Download Manager Plugin, Download Manager 2026-10-02 6.4 Medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the [wpdm_edit_profile] shortcode to be present on a front-end page accessible to Subscriber-level users, who can then submit a multiply entity-encoded payload via the display name field to bypass sanitization.
CVE-2026-94432 2 Latepoint, Wordpress-extensions 2 Appointment Booking Plugin – Latepoint | Calendar & Scheduling For Wordpress, Appointment Booking Plugin 2026-10-02 5.3 Medium
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.7.1 via the OsPaypalConnectController::create_order_for_transaction() action registered as a public (unauthenticated) route through wp_ajax_nopriv_latepoint_route_call. The handler loads an OsInvoiceModel by a sequential integer 'invoice_id' with no access-key/UUID or ownership check (the sibling Stripe and Razorpay handlers require a 128-bit access-key UUID via OsInvoicesHelper::get_invoice_by_key), and then calls OsTransactionIntentHelper::create_or_update_transaction_intent() which persists a transaction intent tied to the target invoice's customer_id, order_id and charge_amount and regenerates its intent_key before the PayPal-configured guard is reached. This makes it possible for unauthenticated attackers to enumerate invoices belonging to arbitrary customers, create unauthorized transaction-intent rows linked to another customer's data, and overwrite the intent_key of any in-flight NEW-status transaction intent — invalidating the intent_key that legitimate Stripe/Razorpay flows are waiting on and breaking payment webhooks for those customers.