Export limit exceeded: 15080 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (15080 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-66465 2 Agnihd, Wordpress 2 Cartify, Wordpress 2026-08-14 9.8 Critical
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
CVE-2026-66466 2 Wedevs, Wordpress 2 Storegrowth: Smart Sales Booster For Woocommerce | Bogo, Upsells, Direct Checkout, Quick View, Side Cart, Wordpress 2026-08-14 7.5 High
Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions.
CVE-2026-66468 2 Powerfulwp, Wordpress 2 Local Delivery Drivers For Woocommerce, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions.
CVE-2026-66469 2 Afonso Matos, Wordpress 2 Arvow Ai Seo Writer, Wordpress 2026-08-14 7.5 High
Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.
CVE-2026-66654 2 Tangiblewp, Wordpress 2 Vehica Core, Wordpress 2026-08-14 6 Medium
Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions.
CVE-2026-66661 2 Onokazu, Wordpress 2 Directories Pro, Wordpress 2026-08-14 7.7 High
Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.
CVE-2026-66691 2 Scriptsbundle, Wordpress 2 Nokri, Wordpress 2026-08-14 9.8 Critical
Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
CVE-2026-28154 2 Snstheme, Wordpress 3 M.anh - Fashion Woocoommerce Wordpress Theme, Samex - Clean, Minimal Shop Woocommerce Wordpress Theme, Wordpress 2026-08-14 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS. This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress Theme: from n/a through 2.5; M.Anh - Fashion WooCoommerce WordPress Theme: from n/a through 1.7.
CVE-2025-10308 2 Alian, Wordpress 2 Astro Booking Engine, Wordpress 2026-08-14 4.3 Medium
The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion functionality. This makes it possible for unauthenticated attackers to delete all plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2026-28184 2 10web, Wordpress 2 Form Maker By 10web, Wordpress 2026-08-14 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-12949 2 Wishlist Member, Wordpress 2 Wishlist Member, Wordpress 2026-08-14 9.8 Critical
The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter while accepting the POST mergewith and POST wpm_id parameters without verifying that the mergewith user ID references a temporary or incomplete registrant that is bound to the current registration transaction. This makes it possible for unauthenticated attackers to take over any existing WordPress account — including administrator accounts — by supplying an arbitrary user's numeric ID as the mergewith value, which causes wp_update_user() to overwrite the target account's username (additionally written via a direct $wpdb UPDATE), password, email address, first name, and last name with attacker-controlled values, while WordPress password and email change notification emails are explicitly suppressed. When wpm_id references a non-existent membership level, no role key is added to the update payload, causing wp_update_user() to preserve the target user's existing role — including administrator — making full privilege escalation a direct consequence of the takeover.
CVE-2026-27539 2 Welcart, Wordpress 2 Welcart E-commerce, Wordpress 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions.
CVE-2026-27999 2 Themefic, Wordpress 2 Tourfic, Wordpress 2026-08-13 6.5 Medium
Subscriber Broken Access Control in Tourfic <= 2.23.1 versions.
CVE-2026-61962 2 Hakan Ozevin, Wordpress 2 Wp Base Booking, Wordpress 2026-08-13 10 Critical
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
CVE-2026-28188 2 Themefic, Wordpress 2 Hydra Booking, Wordpress 2026-08-13 7.3 High
Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions.
CVE-2026-66471 2 Themepoints, Wordpress 2 Accordion, Wordpress 2026-08-13 6.5 Medium
Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions.
CVE-2026-66689 2 Acymailing Newsletter Team, Wordpress 2 Anti Spam And List Cleaner – Acychecker, Wordpress 2026-08-13 6.3 Medium
Unauthenticated Broken Access Control in Anti Spam and list cleaner &#8211; AcyChecker <= 2.0.0 versions.
CVE-2026-66697 2 Colissimo, Wordpress 2 Colissimo Officiel : Méthodes De Livraison Pour Woocommerce, Wordpress 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
CVE-2026-3639 2 Buildwps, Wordpress 2 Ppwp – Password Protect Pages, Wordpress 2026-08-13 6.4 Medium
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-28001 2 Wordpress, Wpdirectorykit 2 Wordpress, Wp Directory Kit 2026-08-13 9.3 Critical
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.