Search Results (15644 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-66603 2 Dartiss, Wordpress 2 Draft List, Wordpress 2026-08-21 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Artiss Draft List simple-draft-list allows Stored XSS. This issue affects Draft List: from n/a through 2.6.4.
CVE-2026-14287 2 10web, Wordpress 2 10web Booster, Wordpress 2026-08-21 4.7 Medium
The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated request handler and does not escape attacker-supplied stylesheet content before rendering it into the page head, allowing an unauthenticated attacker to store markup that executes as JavaScript in the browser of anonymous visitors to an affected page.
CVE-2026-14334 2 Wordpress, Wpdevart 2 Wordpress, Booking Calendar, Appointment Booking System 2026-08-21 8.8 High
The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary JavaScript when the SVG is opened, including in the session of an administrator who reviews the submitted booking.
CVE-2026-14825 2 Quizandsurveymaster, Wordpress 2 Quiz And Survey Master, Wordpress 2026-08-21 2.7 Low
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users.
CVE-2026-14826 2 Quizandsurveymaster, Wordpress 2 Quiz And Survey Master, Wordpress 2026-08-21 2.7 Low
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient addresses, of quizzes created by other users.
CVE-2026-19709 2 Wordpress, Wpswings 2 Wordpress, Membership For Woocommerce 2026-08-21 5.3 Medium
The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated attackers to reach its REST routes and disclose any user's membership plan details on sites where the API has been enabled but no keys were ever generated.
CVE-2026-66613 2 Crocoblock, Wordpress 2 Jetengine, Wordpress 2026-08-21 9.8 Critical
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
CVE-2026-73363 2 Magepeople, Wordpress 2 Taxi Booking Manager For Woocommerce, Wordpress 2026-08-21 6.5 Medium
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions.
CVE-2026-18315 2 Themetechmount, Wordpress 2 Truebooker-appointment-booking, Wordpress 2026-08-21 9.8 Critical
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including, 1.2.6. This is due to the admin_user_create_cus AJAX handler lacking any authentication or capability check before passing the attacker-supplied truebooker_wp_user_id parameter directly to wp_update_user. This makes it possible for unauthenticated attackers to overwrite the email address of any WordPress user — including an administrator — and then complete the standard WordPress lost-password flow to fully take over the targeted account.
CVE-2026-19615 2 Bowo, Wordpress 2 Admin And Site Enhancements Ase, Wordpress 2026-08-21 6.8 Medium
The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users with a role the site owner granted upload access to store a file containing JavaScript which then executes in the browser of anyone who opens it.
CVE-2026-66583 2 Wordpress, Wpmudev 2 Wordpress, Forminator Forms 2026-08-21 9.8 Critical
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
CVE-2026-66586 2 Themewinter, Wordpress 2 Wpcafe, Wordpress 2026-08-21 6.6 Medium
Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
CVE-2026-16650 2 Wordpress, Wpcharitable 2 Wordpress, Charitable 2026-08-21 5.3 Medium
The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to forge webhook notifications that mark donations as paid without any real payment.
CVE-2026-17559 2 Passster Project, Wordpress 2 Passster, Wordpress 2026-08-21 5.3 Medium
The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which REST API requests may bypass global password protection, comparing them as an unanchored substring of the request URI rather than against the resolved route, allowing an unauthenticated attacker to read the content of globally password-protected posts and pages.
CVE-2026-18356 2 Limit Login Attempts Project, Wordpress 2 Limit Login Attempts, Wordpress 2026-08-21 3.7 Low
The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's email address, allowing an account an administrator intended to block from logging in to authenticate anyway.
CVE-2026-3985 2 Constantcontact, Wordpress 2 Creative Mail – Easier Wordpress & Woocommerce Email Marketing, Wordpress 2026-08-21 7.5 High
The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parameter in all versions up to, and including, 1.6.9. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the `has_checkout_consent()` method. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-66591 2 Davidlingren, Wordpress 2 Media Library Assistant, Wordpress 2026-08-21 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS. This issue affects Media LIbrary Assistant: from n/a through 3.39.
CVE-2026-18409 2 Wordpress, Wpforms 2 Wordpress, Wpforms Pro 2026-08-21 7.2 High
The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values in all versions up to, and including, 2.0.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit relies on the plugin's own wp_kses_allowed_html filter widening the 'post' allowlist to permit iframe elements with a data-src attribute, which is not on WordPress's URI-attribute sanitization list, allowing a javascript: URI stored in data-src to survive kses processing and subsequently be promoted to a live src attribute by the bundled admin script view-entry.min.js.
CVE-2026-16577 2 Dokan, Wordpress 2 Ai Powered Woocommerce Multivendor Marketplace Solution:dokan: Ai Powered Woocommerce Multivendor Marketplace Solution, Wordpress 2026-08-21 2.7 Low
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vendor's actual outstanding balance when recording a reverse-withdrawal payment, allowing a vendor to credit their reverse-withdrawal ledger with an arbitrary amount and clear their real commission debt without paying.
CVE-2026-19085 2 Duplicate Post Project, Wordpress 2 Duplicate Post, Wordpress 2026-08-21 2.7 Low
The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role to republish another user's password-protected post as publicly readable.