Export limit exceeded: 15167 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (15167 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-12743 2 Cservit, Wordpress 2 Affiliate-toolkit – Multi-network Affiliate & Amazon Product Display, Wordpress 2026-08-14 4.9 Medium
The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.8.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-15213 2 Welcart, Wordpress 2 Welcart E-commerce, Wordpress 2026-08-14 5.3 Medium
The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback: an unauthenticated request can flip an order from unpaid to settled purely from an order number and a status flag, with no signature, amount, or origin check. Because these are pay-later methods, an attacker can mark their own unpaid order as settled and obtain fulfilment without paying.
CVE-2026-18943 2 Admincolumns, Wordpress 2 Admin Columns, Wordpress 2026-08-14 6.5 Medium
The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as low as subscriber to read arbitrary user, post and term metadata, including data belonging to administrators.
CVE-2026-18962 2 Wordpress, Wp Photo Album Plus Project 2 Wordpress, Wp Photo Album Plus 2026-08-14 4.3 Medium
The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload into the album they target when it processes a front-end upload, allowing any authenticated user, such as a Subscriber, to upload files into albums owned by other users or by the administrator. Exploitation requires the WP Photo Album Plus WordPress plugin before 9.2.09.002's front-end user upload feature to be enabled, which is not the default.
CVE-2026-19050 2 Prosolution, Wordpress 2 Prosolution Wp Client, Wordpress 2026-08-14 6.4 Medium
The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requester, before performing a server-side HTTP request with it, allowing any authenticated user, such as a subscriber, to make the site issue arbitrary requests to internal hosts and services, including requests with an attacker-chosen method, headers and body.
CVE-2026-19052 2 Prosolution, Wordpress 2 Prosolution Wp Client, Wordpress 2026-08-14 4.3 Medium
The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX actions, and the nonce they rely on is published on its public frontend, allowing any authenticated user, such as a subscriber, to trigger an administrative data synchronisation and to clear the ProSolution WP Client WordPress plugin before 2.0.9's activity records.
CVE-2026-27345 2 Magepeople, Wordpress 2 Taxi Booking Manager For Woocommerce, Wordpress 2026-08-14 7.5 High
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
CVE-2026-27537 2 Supsysticcom, Wordpress 2 Smart Popup By Supsystic, Wordpress 2026-08-14 6.5 Medium
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions.
CVE-2026-28004 2 Strategy11team, Wordpress 2 Business Directory Plugin, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions.
CVE-2026-28008 2 Miniorange, Wordpress 2 Oauth Single Sign On – Sso (oauth Client), Wordpress 2026-08-14 9.8 Critical
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
CVE-2026-28148 2 Miniorange, Wordpress 2 Headless Single Sign On, Wordpress 2026-08-14 9.8 Critical
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
CVE-2026-28149 2 Miniorange, Wordpress 2 Headless Single Sign On, Wordpress 2026-08-14 9.8 Critical
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
CVE-2026-28189 2 Rolandbarkerxnauwebdesign, Wordpress 2 Participants Database, Wordpress 2026-08-14 7.4 High
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions.
CVE-2026-61965 2 Ahmad, Wordpress 2 Geekybot, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions.
CVE-2026-61967 2 Miniorange, Wordpress 2 Otp Verification, Wordpress 2026-08-14 9.8 Critical
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
CVE-2026-66424 2 Cozyvision, Wordpress 2 Sms Alert Order Notifications, Wordpress 2026-08-14 9.8 Critical
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
CVE-2026-66426 2 Lesterchan, Wordpress 2 Wp-stats, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions.
CVE-2026-66429 2 Codepress It Solutions Llc, Wordpress 2 Visitor Traffic Real Time Statistics Pro, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
CVE-2026-66430 2 Codepress It Solutions Llc, Wordpress 2 Visitor Traffic Real Time Statistics Pro, Wordpress 2026-08-14 8.5 High
Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
CVE-2026-66444 2 Kendysond, Wordpress 2 Payment Forms For Paystack, Wordpress 2026-08-14 6.5 Medium
Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.