Export limit exceeded: 15167 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15167 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-12743 | 2 Cservit, Wordpress | 2 Affiliate-toolkit – Multi-network Affiliate & Amazon Product Display, Wordpress | 2026-08-14 | 4.9 Medium |
| The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.8.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-15213 | 2 Welcart, Wordpress | 2 Welcart E-commerce, Wordpress | 2026-08-14 | 5.3 Medium |
| The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback: an unauthenticated request can flip an order from unpaid to settled purely from an order number and a status flag, with no signature, amount, or origin check. Because these are pay-later methods, an attacker can mark their own unpaid order as settled and obtain fulfilment without paying. | ||||
| CVE-2026-18943 | 2 Admincolumns, Wordpress | 2 Admin Columns, Wordpress | 2026-08-14 | 6.5 Medium |
| The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as low as subscriber to read arbitrary user, post and term metadata, including data belonging to administrators. | ||||
| CVE-2026-18962 | 2 Wordpress, Wp Photo Album Plus Project | 2 Wordpress, Wp Photo Album Plus | 2026-08-14 | 4.3 Medium |
| The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload into the album they target when it processes a front-end upload, allowing any authenticated user, such as a Subscriber, to upload files into albums owned by other users or by the administrator. Exploitation requires the WP Photo Album Plus WordPress plugin before 9.2.09.002's front-end user upload feature to be enabled, which is not the default. | ||||
| CVE-2026-19050 | 2 Prosolution, Wordpress | 2 Prosolution Wp Client, Wordpress | 2026-08-14 | 6.4 Medium |
| The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requester, before performing a server-side HTTP request with it, allowing any authenticated user, such as a subscriber, to make the site issue arbitrary requests to internal hosts and services, including requests with an attacker-chosen method, headers and body. | ||||
| CVE-2026-19052 | 2 Prosolution, Wordpress | 2 Prosolution Wp Client, Wordpress | 2026-08-14 | 4.3 Medium |
| The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX actions, and the nonce they rely on is published on its public frontend, allowing any authenticated user, such as a subscriber, to trigger an administrative data synchronisation and to clear the ProSolution WP Client WordPress plugin before 2.0.9's activity records. | ||||
| CVE-2026-27345 | 2 Magepeople, Wordpress | 2 Taxi Booking Manager For Woocommerce, Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions. | ||||
| CVE-2026-27537 | 2 Supsysticcom, Wordpress | 2 Smart Popup By Supsystic, Wordpress | 2026-08-14 | 6.5 Medium |
| Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions. | ||||
| CVE-2026-28004 | 2 Strategy11team, Wordpress | 2 Business Directory Plugin, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions. | ||||
| CVE-2026-28008 | 2 Miniorange, Wordpress | 2 Oauth Single Sign On – Sso (oauth Client), Wordpress | 2026-08-14 | 9.8 Critical |
| Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions. | ||||
| CVE-2026-28148 | 2 Miniorange, Wordpress | 2 Headless Single Sign On, Wordpress | 2026-08-14 | 9.8 Critical |
| Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions. | ||||
| CVE-2026-28149 | 2 Miniorange, Wordpress | 2 Headless Single Sign On, Wordpress | 2026-08-14 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions. | ||||
| CVE-2026-28189 | 2 Rolandbarkerxnauwebdesign, Wordpress | 2 Participants Database, Wordpress | 2026-08-14 | 7.4 High |
| Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions. | ||||
| CVE-2026-61965 | 2 Ahmad, Wordpress | 2 Geekybot, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions. | ||||
| CVE-2026-61967 | 2 Miniorange, Wordpress | 2 Otp Verification, Wordpress | 2026-08-14 | 9.8 Critical |
| Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. | ||||
| CVE-2026-66424 | 2 Cozyvision, Wordpress | 2 Sms Alert Order Notifications, Wordpress | 2026-08-14 | 9.8 Critical |
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. | ||||
| CVE-2026-66426 | 2 Lesterchan, Wordpress | 2 Wp-stats, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions. | ||||
| CVE-2026-66429 | 2 Codepress It Solutions Llc, Wordpress | 2 Visitor Traffic Real Time Statistics Pro, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | ||||
| CVE-2026-66430 | 2 Codepress It Solutions Llc, Wordpress | 2 Visitor Traffic Real Time Statistics Pro, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | ||||
| CVE-2026-66444 | 2 Kendysond, Wordpress | 2 Payment Forms For Paystack, Wordpress | 2026-08-14 | 6.5 Medium |
| Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions. | ||||