Export limit exceeded: 399423 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399423 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16557 | 1 Wordpress-extensions | 1 Nimble Builder | 2026-09-28 | 4.3 Medium |
| The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-builder content of arbitrary non-public (draft, pending, private, scheduled) posts and pages. | ||||
| CVE-2025-15698 | 1 Wordpress-extensions | 1 Business Name Generator | 2026-09-28 | 3.5 Low |
| The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2026-19860 | 2 Jetmonsters, Wordpress-extensions | 2 Jetformbuilder — Dynamic Blocks Form Builder, Jetformbuilder | 2026-09-28 | 5.5 Medium |
| The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server to be deleted. The deletion itself is carried out when the form is submitted, which requires no authentication. | ||||
| CVE-2026-76554 | 1 Wordpress-extensions | 1 Wp Import Export Lite | 2026-09-28 | 7.2 High |
| The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to create or modify user accounts and assign roles, allowing users granted a delegated WP Import Export Lite WordPress plugin before 3.9.35 permission, who cannot otherwise manage users, to create administrator accounts and to overwrite the credentials and role of existing accounts, including administrators. | ||||
| CVE-2026-76790 | 1 Wordpress-extensions | 1 Estatik | 2026-09-28 | 7.1 High |
| The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back in an unauthenticated AJAX response, leading to Reflected Cross-Site Scripting. | ||||
| CVE-2026-84750 | 1 Wordpress-extensions | 1 Ultimate Addons For Contact Form 7 | 2026-09-28 | 6.5 Medium |
| The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uploaded through one of its form fields, and stores them at a predictable public path with the attacker-chosen extension intact, allowing unauthenticated users to upload arbitrary files. The PHP handler shipped by default with the Debian and Ubuntu Apache packages maps .phar to PHP alongside .php and .phtml, so on that stack the uploaded file is executed and the issue leads to Remote Code Execution and full site takeover. Where the host routes only .php to the PHP handler, the same file is instead served from the site's own origin with its script intact, leading to Stored Cross-Site Scripting. | ||||
| CVE-2026-85574 | 1 Wordpress-extensions | 1 Unbounce Landing Pages | 2026-09-28 | 8 High |
| The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin. | ||||
| CVE-2026-86591 | 1 Wordpress-extensions | 1 Botiga Pro | 2026-09-28 | 9.8 Critical |
| The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover. The same route also allows unauthenticated users to store arbitrary web scripts which are then executed on every page of the site's front end, as well as to move arbitrary posts to the trash. | ||||
| CVE-2026-88824 | 1 Wordpress-extensions | 1 Master Blocks | 2026-09-28 | 8.8 High |
| The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page. | ||||
| CVE-2026-88926 | 1 Wordpress-extensions | 1 Vikrentitems Flexible Rental Management System | 2026-09-28 | 8.6 High |
| The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-92099 | 1 Wordpress-extensions | 1 Wpgraphql Smart Cache | 2026-09-28 | 6.5 Medium |
| The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persisted query from a request, allowing unauthenticated users to publish arbitrary query documents and claim query aliases before a site's own frontend registers them. | ||||
| CVE-2026-92403 | 1 Wordpress-extensions | 1 Secure Custom Fields | 2026-09-28 | 3.7 Low |
| The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different registered form and modify the title and content of the post that form is bound to. | ||||
| CVE-2026-92404 | 1 Wordpress-extensions | 1 Mgosync | 2026-09-28 | 7.5 High |
| The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, from a configured site. | ||||
| CVE-2026-92420 | 1 Wordpress-extensions | 1 Hydra Booking | 2026-09-28 | 3.8 Low |
| The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking-provider-level user to cancel and permanently delete other providers' bookings on the same site. | ||||
| CVE-2026-92421 | 1 Wordpress-extensions | 1 Hydra Booking | 2026-09-28 | 4.7 Medium |
| The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the user making the request, allowing authenticated users holding a Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3-assigned host role to modify other hosts' profile data and reassign ownership of another host's record to themselves. | ||||
| CVE-2026-92425 | 1 Wordpress-extensions | 1 Hydra Booking | 2026-09-28 | 5.5 Medium |
| The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its own administrator-assigned custom role to read, modify and permanently delete other hosts' records and the WordPress user accounts linked to them. | ||||
| CVE-2026-92430 | 1 Wordpress-extensions | 1 Rede Itau For Woocommerce | 2026-09-28 | 5.3 Medium |
| The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook before updating an order's status, allowing unauthenticated attackers to mark a pending order as paid without paying. | ||||
| CVE-2026-92435 | 1 Wordpress-extensions | 1 Mailchimp For Woocommerce | 2026-09-28 | 5.3 Medium |
| The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change. | ||||
| CVE-2026-9832 | 2 Themehigh, Wordpress-extensions | 2 Stripe Payment Gateway For Woocommerce, Payment Gateway Of Stripe For Woocommerce | 2026-09-28 | 5.3 Medium |
| The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_stripe` webhook endpoint (`EH_Stripe_Webhook_Handler::handle()`) wrapping the only call to `\Stripe\Webhook::constructEvent()` inside an `if (!empty($endpoint_secret))` guard that is never entered on default installations — because the `eh_stripe_webhook_secret` option is empty after a fresh plugin install — causing the raw, attacker-controlled POST body to be decoded and processed as a fully trusted Stripe event without any signature verification, authentication, or authorization. This makes it possible for unauthenticated attackers to send forged Stripe webhook events to manipulate WooCommerce order statuses, including marking unpaid orders as paid or completed via `payment_complete()`, forcing legitimate orders into a failed state, fabricating dispute notifications, and injecting forged refund events. This vulnerability is only exploitable when the Stripe webhook signing secret has not been configured by an administrator; once a valid signing secret is saved, `\Stripe\Webhook::constructEvent()` is enforced and forged requests are rejected. | ||||
| CVE-2026-15463 | 2 Sslzen, Wordpress-extensions | 2 Ssl Zen, Ssl Zen | 2026-09-28 | 6.1 Medium |
| The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'host' parameter in all versions up to, and including, 4.7.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability is only exploitable when in the system_requirements stage. | ||||