Export limit exceeded: 15080 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15080 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-15215 | 2 Wordpress, Wpswings | 2 Wordpress, Subscriptions For Woocommerce | 2026-08-08 | 8.8 High |
| The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin before 2.0.1, resulting in remote code execution. | ||||
| CVE-2026-15361 | 2 Contentviewspro, Wordpress | 2 Content Views, Wordpress | 2026-08-08 | 8.1 High |
| The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks. | ||||
| CVE-2026-16030 | 2 Mstore, Wordpress | 2 Mstore Api, Wordpress | 2026-08-08 | 8.1 High |
| The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts. | ||||
| CVE-2026-16038 | 2 Mstore, Wordpress | 2 Mstore Api, Wordpress | 2026-08-08 | 9.1 Critical |
| The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free. | ||||
| CVE-2026-16039 | 2 Mstore, Wordpress | 2 Mstore Api, Wordpress | 2026-08-08 | 6.5 Medium |
| The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each customer's personal information. | ||||
| CVE-2026-16041 | 2 Mstore, Wordpress | 2 Mstore Api, Wordpress | 2026-08-08 | 7.5 High |
| The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners. | ||||
| CVE-2026-15239 | 2 Simple Captcha, Wordpress | 2 Simple Captcha With Cloudflare Turnstile, Wordpress | 2026-08-08 | 5.3 Medium |
| The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated attackers to solve one challenge and then replay token-less form submissions for a short window, defeating the anti-abuse protection the plugin provides. | ||||
| CVE-2026-48094 | 2 Dartiss, Wordpress | 2 Shareopenly, Wordpress | 2026-08-08 | N/A |
| The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability caused by the absence of WordPress's `esc_url()` escaping function on the `$url` variable before it is rendered into HTML content. This variable is constructed from `home_url( add_query_arg( array(), $wp->request ) )` and is concatenated directly into an HTML `href` attribute on every singular post or page where the plugin's sharing link is displayed. WordPress's security handbook mandates that every URL placed in HTML output must be passed through `esc_url()`, which both HTML-encodes special characters (converting `"`, `<`, `>` into their safe HTML entity equivalents) and strips dangerous URI schemes such as `javascript:` and `data:`. The omission of this function means that if the `$url` value ever contains HTML-special characters or a dangerous URI scheme — through a `home_url` WordPress filter applied by another plugin or theme, through certain web server or hosting configurations, or through future code changes — the unescaped content will be injected verbatim into the rendered HTML of every post or page on the site. Version 1.2.1 contains a patch for the issue. | ||||
| CVE-2026-11907 | 2 Wordpress, Xwp | 2 Wordpress, Stream – Activity Log & Audit Trail | 2026-08-08 | 6.5 Medium |
| The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to access all Stream activity records via the Heartbeat API. | ||||
| CVE-2026-66701 | 2 Cozmoslabs, Wordpress | 2 Profile Builder, Wordpress | 2026-08-08 | 5.3 Medium |
| Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions. | ||||
| CVE-2026-66692 | 2 Colissimo, Wordpress | 2 Colissimo Officiel : Méthodes De Livraison Pour Woocommerce, Wordpress | 2026-08-08 | 4.3 Medium |
| Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions. | ||||
| CVE-2026-66684 | 2 Akshaymenariya, Wordpress | 2 Export Import Menus, Wordpress | 2026-08-08 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions. | ||||
| CVE-2026-66452 | 2 It-recht Kanzlei, Wordpress | 2 Legal Text Connector Of The It-recht Kanzlei, Wordpress | 2026-08-08 | 6.5 Medium |
| Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions. | ||||
| CVE-2026-66425 | 2 Saadiqbal, Wordpress | 2 Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, And Custom Form Builder, Wordpress | 2026-08-08 | 6.5 Medium |
| Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 versions. | ||||
| CVE-2026-16263 | 2 Wordpress, Wp Maps | 2 Wordpress, Wp Maps | 2026-08-07 | 8.8 High |
| The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server. | ||||
| CVE-2026-64638 | 1 Wordpress | 1 Wordpress | 2026-08-07 | N/A |
| WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/). | ||||
| CVE-2026-15359 | 2 Templately, Wordpress | 2 Templately, Wordpress | 2026-08-07 | 6.5 Medium |
| The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers to overwrite the administrator's stored cloud service connection with an account under their control, disconnecting the legitimate administrator and redirecting the site's cloud template library to attacker-controlled content. | ||||
| CVE-2026-15149 | 2 Wordpress, Wp Hotel Booking | 2 Wordpress, Wp Hotel Booking | 2026-08-07 | 5.3 Medium |
| The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a booking, and relies on client-controlled cart data, allowing unauthenticated users to create confirmed reservations for free or at an arbitrarily reduced price. | ||||
| CVE-2026-16265 | 2 Wordpress, Wp Maps | 2 Wordpress, Wp Maps | 2026-08-07 | 6.5 Medium |
| The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not restrict the operation it dispatches, allowing users with a Subscriber account to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service. | ||||
| CVE-2026-15211 | 2 Wordpress, Wpswings | 2 Wordpress, Subscriptions For Woocommerce | 2026-08-07 | 5.9 Medium |
| The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed on the WooCommerce order-received flow: it captures a client-supplied token and marks the order paid whenever the capture status is COMPLETED, without comparing the captured amount to the order total. This allows an attacker (unauthenticated where guest checkout is enabled) to substitute an approved, uncaptured PayPal order token and have an expensive order marked paid without paying its price. | ||||