Export limit exceeded: 15167 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15167 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-13692 | 2 Payu, Wordpress | 2 Payu Commercepro Plugin, Wordpress | 2026-08-10 | 5.3 Medium |
| The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders. | ||||
| CVE-2026-14223 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-08-10 | 4.3 Medium |
| The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier. | ||||
| CVE-2026-14222 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-08-10 | 3.8 Low |
| The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system. | ||||
| CVE-2026-48093 | 2 Davidartiss, Wordpress | 2 Code Embed, Wordpress | 2026-08-10 | 6.5 Medium |
| The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the external URL embed feature in post content. The vulnerable code scans rendered content for URL embed tokens, fetches the remote URL, and inserts the remote response body into the page without output sanitization or an `unfiltered_html` capability check. This allows a Contributor attacker to submit a pending post containing an inert-looking URL token that executes attacker-controlled JavaScript when an Administrator or Editor previews or reviews the post. This is distinct from CVE-2026-2512, which affected custom field meta values up to version 2.5.1. This vector affects version 2.6 and uses the documented external URL embed feature in post content. This particular issue is patched in version 2.6.1. | ||||
| CVE-2026-18933 | 2 Wordpress, Wpdownloadmanager | 2 Wordpress, Download Manager | 2026-08-10 | 7.2 High |
| The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no wp_check_filetype_and_ext, no validate_file, and no extension blocklist exist anywhere in the upload handler. | ||||
| CVE-2026-14226 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-08-10 | 4.3 Medium |
| The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookings on the site, including customer names, schedules, and statuses. | ||||
| CVE-2026-66470 | 2 Shabti, Wordpress | 2 Frontend Admin By Dynamapps, Wordpress | 2026-08-08 | 7.1 High |
| Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions. | ||||
| CVE-2026-66662 | 2 Shabti, Wordpress | 2 Frontend Admin By Dynamapps, Wordpress | 2026-08-08 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions. | ||||
| CVE-2026-66664 | 2 Squirrly, Wordpress | 2 Seo Plugin By Squirrly Seo, Wordpress | 2026-08-08 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions. | ||||
| CVE-2026-66694 | 2 Thrive Themes Coupon, Wordpress | 2 Thrive Architect, Wordpress | 2026-08-08 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions. | ||||
| CVE-2026-66705 | 2 Facebook, Wordpress | 2 Facebook For Wordpress, Wordpress | 2026-08-08 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions. | ||||
| CVE-2026-66707 | 2 Facebook, Wordpress | 2 Facebook For Woocommerce, Wordpress | 2026-08-08 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions. | ||||
| CVE-2026-11361 | 2 Formidableforms, Wordpress | 2 Formidable, Wordpress | 2026-08-08 | 5.9 Medium |
| The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without being charged. | ||||
| CVE-2026-13399 | 2 Payment Plugins, Wordpress | 2 Payment Plugins For Paypal Woocommerce, Wordpress | 2026-08-08 | 7.5 High |
| The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments | ||||
| CVE-2026-14936 | 2 Simple-membership-plugin, Wordpress | 2 Simple Membership, Wordpress | 2026-08-08 | 5.3 Medium |
| The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's own configured merchant account before activating a membership, allowing unauthenticated users to activate or extend a membership using a payment made to an arbitrary PayPal account they control. | ||||
| CVE-2026-12801 | 2 Themefic, Wordpress | 2 Ultimate Addons For Contact Form 7, Wordpress | 2026-08-08 | 6.4 Medium |
| The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slider 'data-label' and 'data-separator' attributes in all versions up to, and including, 3.5.43 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-14364 | 2 Themetechmount, Wordpress | 2 Truebooker-appointment-booking, Wordpress | 2026-08-08 | 9.8 Critical |
| The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity before resetting their password. This makes it possible for unauthenticated attackers to reset the password of arbitrary user accounts, including administrators, and gain access to those accounts. | ||||
| CVE-2026-14205 | 2 Wordpress, Wp-eventmanager | 2 Wordpress, Wp Event Manager | 2026-08-08 | 9.8 Critical |
| The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment. | ||||
| CVE-2026-14331 | 2 Subscribe2 Project, Wordpress | 2 Subscribe2, Wordpress | 2026-08-08 | 6.1 Medium |
| The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a public subscription form, leading to Reflected Cross-Site Scripting that executes in the browser of an unauthenticated visitor who interacts with the form through a crafted link. | ||||
| CVE-2026-15214 | 2 Wordpress, Wpswings | 2 Wordpress, Subscriptions For Woocommerce | 2026-08-08 | 4.3 Medium |
| The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that subscription's ID. | ||||