Export limit exceeded: 399886 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 399886 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399886 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-93770 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions. | ||||
| CVE-2026-93651 | 2026-09-30 | 7.2 High | ||
| Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions. | ||||
| CVE-2026-93624 | 2026-09-30 | 7.2 High | ||
| Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions. | ||||
| CVE-2026-93621 | 2026-09-30 | 8.2 High | ||
| Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions. | ||||
| CVE-2026-93580 | 2026-09-30 | 5.3 Medium | ||
| The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an IP check that is not enforced, allowing unauthenticated attackers who know a target order's parcel tracking number to forge its shipment status and prematurely mark the order completed. | ||||
| CVE-2026-93514 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions. | ||||
| CVE-2026-93512 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions. | ||||
| CVE-2026-92994 | 2026-09-30 | 8.8 High | ||
| The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it. | ||||
| CVE-2026-92424 | 2026-09-30 | 6.8 Medium | ||
| The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary web scripts unfiltered under a privileged user's account, executing in the context of anyone who later views that content. | ||||
| CVE-2026-91832 | 2026-09-30 | 7.1 High | ||
| The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting. | ||||
| CVE-2026-91072 | 2026-09-30 | 4.4 Medium | ||
| The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an attacker with Administrator-level access rename or delete existing WebP-derivative image files outside that scope, including, on a multisite network, files belonging to a different site they have no access to. | ||||
| CVE-2026-91051 | 2026-09-30 | 6.6 Medium | ||
| The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta field that is deserialized when the post is rendered, allowing them to perform PHP Object Injection, which can lead to remote code execution when a suitable gadget chain is present via another installed EWWW Image Optimizer WordPress plugin before 8.8.0 or . | ||||
| CVE-2026-90953 | 2026-09-30 | 4.3 Medium | ||
| The Image Optimizer WordPress plugin before 1.7.7 does not enforce its intended capability check on several of its read REST routes, allowing any authenticated user to read attachment metadata and site-wide statistics that should be restricted to administrators. | ||||
| CVE-2026-89193 | 2026-09-30 | 7.5 High | ||
| The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators. | ||||
| CVE-2026-89190 | 2026-09-30 | 4.3 Medium | ||
| The Robin Image Optimizer WordPress plugin before 2.0.8 does not check the user's capabilities before dispatching one of its bundled admin framework's request handlers, allowing users with a subscriber-level account to render admin-only Robin Image Optimizer WordPress plugin before 2.0.8 pages and disclose the Robin Image Optimizer WordPress plugin before 2.0.8's stored settings. | ||||
| CVE-2026-88797 | 2026-09-30 | 7.1 High | ||
| The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any hosted on the WordPress.org repository. | ||||
| CVE-2026-88791 | 2026-09-30 | 3.4 Low | ||
| The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path. | ||||
| CVE-2026-87777 | 2026-09-30 | 6.8 Medium | ||
| The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content in the editor. | ||||
| CVE-2026-86789 | 2026-09-30 | 5.3 Medium | ||
| The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers to retrieve directory entries that are marked private or unlisted, or that are still pending moderation, including entry names, organizations, biographies, internal notes and street addresses. The Connections Business Directory WordPress plugin through 10.4.67 has been closed on WordPress.org and no fixed version is available, so site owners should remove it or restrict unauthenticated access to its REST API routes. | ||||
| CVE-2026-85576 | 2026-09-30 | 4.3 Medium | ||
| The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them. | ||||