Export limit exceeded: 15669 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15669 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-53999 | 2 Themegoods, Wordpress | 2 Altair, Wordpress | 2026-08-20 | 6.5 Medium |
| Unauthenticated Broken Access Control in Altair <= 5.2.2 versions. | ||||
| CVE-2026-66592 | 2 Rtcamp, Wordpress | 2 Rtmedia For Wordpress, Buddypress And Bbpress, Wordpress | 2026-08-20 | 9.3 Critical |
| Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. | ||||
| CVE-2026-18778 | 2 Truebooker, Wordpress | 2 Truebooker, Wordpress | 2026-08-20 | 5.3 Medium |
| The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to retrieve the personal information of customers who booked an appointment, including their name, email address, phone number and postal address. | ||||
| CVE-2026-28164 | 2 Hashthemes, Wordpress | 2 Easy Elementor Addons, Wordpress | 2026-08-20 | 9.6 Critical |
| Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7. | ||||
| CVE-2026-74992 | 2 Kirki, Wordpress | 2 Kirki, Wordpress | 2026-08-20 | 6.8 Medium |
| The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not remove all unwanted files after extracting them, allowing such users to upload arbitrary files to a web accessible directory, leading to Stored XSS as well as RCE on some server configurations. | ||||
| CVE-2026-75963 | 2 Liedekef, Wordpress | 2 Events Made Easy, Wordpress | 2026-08-20 | 7.5 High |
| The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal payload is triggered passively when any visitor loads the affected single-event page, meaning post-submission execution does not require additional attacker interaction. | ||||
| CVE-2026-11565 | 2 Advancedfilemanager, Wordpress | 2 Advanced File Manager, Wordpress | 2026-08-20 | 8.5 High |
| The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server — including sensitive configuration files — and to overwrite existing non-PHP files, which can be leveraged to compromise administrator accounts and the whole site. | ||||
| CVE-2026-73184 | 2 Lcweb, Wordpress | 2 Global Gallery, Wordpress | 2026-08-19 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions. | ||||
| CVE-2026-66596 | 2 Stefanno Lissa, Wordpress | 2 Newsletter, Wordpress | 2026-08-19 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions. | ||||
| CVE-2026-32475 | 2 Elementor, Wordpress | 2 Elementor Pro, Wordpress | 2026-08-19 | 9 Critical |
| Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1. | ||||
| CVE-2026-19406 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-08-19 | 2.7 Low |
| The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses. | ||||
| CVE-2026-18779 | 2 Truebooker, Wordpress | 2 Truebooker, Wordpress | 2026-08-19 | 5.3 Medium |
| The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records. | ||||
| CVE-2026-18777 | 2 Truebooker, Wordpress | 2 Truebooker, Wordpress | 2026-08-19 | 5.3 Medium |
| The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to change the status of arbitrary appointments, as well as to trigger notification emails to the affected customers. | ||||
| CVE-2026-18776 | 2 Truebooker, Wordpress | 2 Truebooker, Wordpress | 2026-08-19 | 9.8 Critical |
| The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including administrators, and subsequently take over their account via the password reset flow. | ||||
| CVE-2026-18466 | 2 Wordpress, Wp Maps | 2 Wordpress, Wp Maps | 2026-08-19 | 5.4 Medium |
| The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with a Subscriber account to create an unlimited number of options in the database, each of which is loaded on every page request. | ||||
| CVE-2026-18197 | 3 Wordpress, Yannick Lefebvre, Ylefebvre | 3 Wordpress, Link Library, Link Library | 2026-08-19 | 6.1 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripting (XSS). This issue affects Link Library: before 7.9.4. | ||||
| CVE-2026-73386 | 2 Wordpress, Zealousweb | 2 Wordpress, Track Geolocation Of Users Using Contact Form 7 | 2026-08-19 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions. | ||||
| CVE-2026-15780 | 2 Veronalabs, Wordpress | 2 Wp Statistics – Simple, Privacy-friendly Google Analytics Alternative, Wordpress | 2026-08-19 | 7.2 High |
| The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions up to, and including, 14.16.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload can be planted without authentication via the public /wp-statistics/v2/hit REST endpoint, because the required signature is exposed on the public homepage and a base64-encoded page_uri POST parameter overrides the previously sanitized REQUEST_URI, allowing the malicious utm_campaign value to bypass sanitization and be stored in the database. | ||||
| CVE-2026-13169 | 2 Eventin, Wordpress | 2 Eventin, Wordpress | 2026-08-19 | 8.1 High |
| The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different author, allowing users with contributor-level access and above to alter, delete, or take over events created by other users including administrators. | ||||
| CVE-2025-11729 | 2 Buildwps, Wordpress | 2 Ppwp – Password Protect Pages, Wordpress | 2026-08-19 | 4.3 Medium |
| The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the can_access function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Contributor-level access and above, to retrieve a master-password and access any password-protected content. | ||||