Export limit exceeded: 385269 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 15614 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (15614 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-73361 2 Wordpress, Wpzoom 2 Wordpress, Recipe Card Blocks For Gutenberg & Elementor 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions.
CVE-2026-73362 2 Kaizencoders, Wordpress 2 Url Shortify, Wordpress 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions.
CVE-2026-73393 2 Wedevs, Wordpress 2 Subscribe2, Wordpress 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
CVE-2026-73400 2 Jetmonsters, Wordpress 2 Restaurant Menu By Motopress, Wordpress 2026-08-18 8.1 High
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
CVE-2026-66637 2 Alex, Wordpress 2 Featured Video Plus, Wordpress 2026-08-18 6.5 Medium
Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.
CVE-2026-66629 2 Themeum, Wordpress 2 Kirki, Wordpress 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.
CVE-2026-32553 2 Brainstorm Force, Wordpress 2 Ottokit, Wordpress 2026-08-18 7.2 High
Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.
CVE-2026-15748 2 Wordpress, Wpmudev 2 Wordpress, Forminator Forms – Contact Form, Payment Form & Custom Form Builder 2026-08-18 9.8 Critical
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.
CVE-2026-68565 2 Paolo, Wordpress 2 Geodirectory, Wordpress 2026-08-18 6.5 Medium
Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.
CVE-2026-32465 2 G5theme, Wordpress 2 Essential Real Estate, Wordpress 2026-08-18 8.8 High
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
CVE-2026-32481 2 Ezoic, Wordpress 2 Ezoic, Wordpress 2026-08-18 7.5 High
Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.
CVE-2026-32549 2 Codexpert, Wordpress 2 Thumbpress, Wordpress 2026-08-18 7.5 High
Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.
CVE-2026-28571 2 Wordpress, Wppool 2 Wordpress, Formychat 2026-08-18 7.5 High
Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.
CVE-2026-15384 2 Manual Image Crop Project, Wordpress 2 Manual Image Crop, Wordpress 2026-08-18 5.7 Medium
The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that crops attachment images; its only guard passes for any logged-in user. A subscriber-level user can therefore supply an arbitrary attachment ID and overwrite that attachment's generated intermediate-size image (for example its thumbnail) and mutate its stored metadata, regardless of who owns the media. This is a cross-user integrity/defacement issue over the Media Library. The action also has no nonce, so it is additionally susceptible to CSRF.
CVE-2026-6229 2 Wordpress, Wproyal 2 Wordpress, Royal Addons For Elementor – Addons And Templates Kit For Elementor 2026-08-17 7.2 High
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by including 'docs.google.com/spreadsheets' in a query parameter, and the subsequent use of these URLs in fopen() calls without blocking internal or private network addresses. This makes it possible for authenticated attackers, with Contributor-level access and above, to make requests to arbitrary URLs and retrieve sensitive information from internal services.
CVE-2026-19728 2 Actpro, Wordpress 2 Extra Product Options For Woocommerce, Wordpress 2026-08-17 7.5 High
The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploaded file before serving it, allowing unauthenticated users who obtain a file's stored name to retrieve it. The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 writes a deny-all rule into its upload directories, so the disclosure only crosses a boundary on web servers that honour it, such as Apache. Where it is ignored, as on a default nginx setup, the same files are already served at their direct URL and the endpoint exposes nothing further.
CVE-2026-19714 2 Simple Jwt Login Project, Wordpress 2 Simple Jwt Login, Wordpress 2026-08-17 9.1 Critical
The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate as any user whose email address such a token carries, up to and including an administrator. Every site with the Simple JWT Login WordPress plugin before 3.6.8's Google sign-in enabled is affected.
CVE-2026-19725 2 Wordpress, Wpvividplugins 2 Wordpress, Wpvivid — Backup, Migration & Staging 2026-08-17 9.1 Critical
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to build a log file path, allowing an attacker holding a site to site transfer key to create a log file in any existing writable directory of the site, including the web root. The file name always carries a fixed suffix and the contents are always the WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131's own log header, so only the location of the file is attacker controlled.
CVE-2026-18653 2 Wordpress, Wpdirectorykit 2 Wordpress, Wp Directory Kit 2026-08-17 7.2 High
The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrators to perform SQL injection attacks. On a multisite installation this lets an administrator of a single site read data belonging to the entire network, which they are not otherwise able to reach.
CVE-2026-17533 2 Wordpress, Yaniiliev 2 Wordpress, All In One Wp Migration And Backup 2026-08-17 7.2 High
The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, allowing an administrator of a single subsite to execute arbitrary PHP code across the entire network.