Export limit exceeded: 15644 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15644 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-78269 | 2 Tammersoft, Wordpress | 2 Shared Files, Wordpress | 2026-08-24 | 6.4 Medium |
| Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions. | ||||
| CVE-2026-19883 | 2 Etruel, Wordpress | 2 Wpematico Rss Feed Fetcher, Wordpress | 2026-08-24 | 8.8 High |
| The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and including, 2.8.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access. | ||||
| CVE-2026-76057 | 2 Rubengc, Wordpress | 2 Automatorwp – Automator Plugin For No-code Automations, Webhooks & Custom Integrations In Wordpress, Wordpress | 2026-08-24 | 4.3 Medium |
| The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve all ConvertKit form data configured by the site's manager account, exposing integration details intended to be restricted to plugin managers. The required nonce is localized on every admin page load, making it accessible to any authenticated user who can reach /wp-admin. | ||||
| CVE-2026-76074 | 2 Rubengc, Wordpress | 2 Automatorwp – Automator Plugin For No-code Automations, Webhooks & Custom Integrations In Wordpress, Wordpress | 2026-08-24 | 4.3 Medium |
| The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve the site's configured Campaign Monitor mailing list catalog, including all list IDs and names, that should be restricted to users with the plugin's manager capability. The required nonce is emitted unconditionally on every WordPress admin page via wp_localize_script, meaning any subscriber visiting /wp-admin/profile.php can obtain it without any elevated access. | ||||
| CVE-2026-4244 | 2 Metaphorcreations, Wordpress | 2 Post Duplicator, Wordpress | 2026-08-24 | 4.3 Medium |
| The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `duplicate_post()` function in all versions up to, and including, 3.0.11. This is due to the function not verifying that the user has `edit_others_posts` capability before accepting a `selectedAuthorId` parameter via the `duplicate-post` REST endpoint. This makes it possible for authenticated attackers, with Contributor-level access and above, to create duplicated posts attributed to any user, including administrators. | ||||
| CVE-2026-2996 | 2 Maartenbelmans, Wordpress | 2 Advanced Product Fields Product Addons For Woocommerce, Wordpress | 2026-08-24 | 7.5 High |
| The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid addons and complete purchases at the base product price only, effectively stealing products by paying a fraction of the intended total. The vulnerability was partially patched in version 1.6.19. | ||||
| CVE-2026-4561 | 2 Dvankooten, Wordpress | 2 Mc4wp: Mailchimp For Wordpress, Wordpress | 2026-08-24 | 6.4 Medium |
| The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form response message post meta fields (e.g., 'text_subscribed', 'text_error') in all versions up to, and including, 4.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-5093 | 2 Wordpress, Wpsoul | 2 Wordpress, Greenshift – Animation And Page Builder Blocks | 2026-08-24 | 4.3 Medium |
| The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 12.8.9. This is due to a missing capability check on the 'gspb_update_global_wp_settings' function that only verifies the 'edit_posts' capability instead of requiring administrative privileges. This makes it possible for authenticated attackers, with contributor-level access and above, to modify global WordPress theme color settings site-wide, leading to site defacement. | ||||
| CVE-2026-16612 | 2 Fibosearch, Wordpress | 2 Fibosearch, Wordpress | 2026-08-23 | 5.3 Medium |
| The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected products and their metadata without entering the product password. Two endpoints are affected: the autocomplete search endpoint (dgwt_wcas_ajax_search) and the Details Panel endpoint (dgwt_wcas_result_details) when queried for taxonomy details. | ||||
| CVE-2026-77003 | 2 Content Mask Project, Wordpress | 2 Content Mask, Wordpress | 2026-08-23 | 2.7 Low |
| The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role as low as Contributor to publish posts and pages on the site without holding the publish capability. | ||||
| CVE-2026-7526 | 2 Smub, Wordpress | 2 Pdf Embedder, Wordpress | 2026-08-22 | 4.3 Medium |
| The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.3 via the enqueue_block_assets. This makes it possible for authenticated attackers, with contributor-level access and above, to extract configuration data. License key exposure occurs when the premium add-on is also installed and has saved a key; on Lite-only installations, the exposed data is limited to non-sensitive viewer configuration values such as width, height, toolbar settings, usage tracking, and plan. | ||||
| CVE-2026-73396 | 2 Makewebbetter, Wordpress | 2 Hubspot For Woocommerce, Wordpress | 2026-08-21 | 7.1 High |
| Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. | ||||
| CVE-2026-73404 | 2 Stylemixthemes, Wordpress | 2 Masterstudy Lms, Wordpress | 2026-08-21 | 6.5 Medium |
| Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. | ||||
| CVE-2026-73996 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-08-21 | 9.8 Critical |
| Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. | ||||
| CVE-2026-74004 | 2 Wordpress, Wpmonks | 2 Wordpress, Gravity Booster – Styles & Layouts For Gravity Forms | 2026-08-21 | 5.4 Medium |
| Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions. | ||||
| CVE-2026-74006 | 2 Wordpress, Wptablebuilder | 2 Wordpress, Wp Table Builder | 2026-08-21 | 4.3 Medium |
| Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions. | ||||
| CVE-2026-74007 | 2 Iberezansky, Wordpress | 2 3d Flipbook – Pdf Embedder, Pdf Flipbook Viewer, Flipbook Image Gallery, Wordpress | 2026-08-21 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions. | ||||
| CVE-2026-27365 | 2 Publishpress, Wordpress | 2 Publishpress Series, Wordpress | 2026-08-21 | 5.9 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress PublishPress Series allows Stored XSS. This issue affects PublishPress Series: from n/a through 2.17.0. | ||||
| CVE-2026-73388 | 2 Teconcetheme, Wordpress | 2 Nikstore Core, Wordpress | 2026-08-21 | 9.3 Critical |
| Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions. | ||||
| CVE-2026-66581 | 2 Crocoblock. Jetimpex Inc., Wordpress | 2 Jetengine, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. | ||||