Search Results (15560 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-66587 2 Wordpress, Wpcafe 2 Wordpress, Wp Cafe Pro 2026-08-24 9.8 Critical
Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
CVE-2026-66648 2 Mvpthemes, Wordpress 2 Jawn, Wordpress 2026-08-24 9.8 Critical
Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
CVE-2026-66670 2 Elated-themes, Wordpress 2 Måne, Wordpress 2026-08-24 8.1 High
Unauthenticated Local File Inclusion in Måne <= 1.7 versions.
CVE-2026-28192 2 Piotnet, Wordpress 2 Piotnet Addons For Elementor, Wordpress 2026-08-24 9.6 Critical
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
CVE-2026-28568 2 Mdmag, Wordpress 2 Quill Forms, Wordpress 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions.
CVE-2026-28569 2 Sslzen, Wordpress 2 Ssl Zen, Wordpress 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.
CVE-2026-32468 2 Duitku, Wordpress 2 Duitku Payment Gateway, Wordpress 2026-08-24 7.5 High
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
CVE-2026-32547 2 Wordplus, Wordpress 2 Better Messages, Wordpress 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.
CVE-2026-66635 2 10web, Wordpress 2 Sliderby10web, Wordpress 2026-08-24 7.4 High
Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.
CVE-2026-66638 2 Shabti, Wordpress 2 Frontend Admin By Dynamapps, Wordpress 2026-08-24 6.5 Medium
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
CVE-2026-68568 2 Stylemixthemes, Wordpress 2 Masterstudy Lms, Wordpress 2026-08-24 6.3 Medium
Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.
CVE-2026-73190 2 Shahjada, Wordpress 2 Wpdm Premium Packages, Wordpress 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.
CVE-2026-73378 2 Supsysticcom, Wordpress 2 Contact Form By Supsystic, Wordpress 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions.
CVE-2026-73379 2 Supsysticcom, Wordpress 2 Contact Form By Supsystic, Wordpress 2026-08-24 6.5 Medium
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
CVE-2026-73395 2 Wordpress, Wpdevart 3 Wordpress, Booking Calendar, Booking Calendar, Appointment Booking System 2026-08-24 6.5 Medium
Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.
CVE-2026-18027 2 Webtoffee, Wordpress 2 Woocommerce Pdf Invoices, Packing Slips, Delivery Notes And Shipping Labels, Wordpress 2026-08-24 6.5 Medium
The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base64 function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The base64-encoded file contents are embedded into the cached invoice HTML and served directly to the attacker via the plugin's own Print/Download invoice endpoints, which require only a valid nonce and access key.
CVE-2026-66584 2 Code4recovery, Wordpress 2 12 Step Meeting List, Wordpress 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.
CVE-2026-78258 2 Magepeople, Wordpress 2 Booking & Rental Manager, Wordpress 2026-08-24 5.3 Medium
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.
CVE-2026-78270 2 Wordpress, Wpmanageninja 2 Wordpress, Fluentcrm 2026-08-24 7.6 High
Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.
CVE-2026-78272 2 Wordpress, Wpmanageninja 2 Wordpress, Fluent Support 2026-08-24 5.4 Medium
Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.