Export limit exceeded: 15736 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15736 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66431 | 2 Woompaloompa, Wordpress | 2 Bitcoin Lightning Payment Gateway For Woocommerce (via Clink), Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. | ||||
| CVE-2026-66446 | 2 If-so Dynamic Content, Wordpress | 2 If-so Dynamic Content Personalization, Wordpress | 2026-08-14 | 9.3 Critical |
| Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. | ||||
| CVE-2026-66455 | 2 Rockiger, Wordpress | 2 Reactpress, Wordpress | 2026-08-14 | 6 Medium |
| Subscriber Broken Access Control in ReactPress <= 3.4.0 versions. | ||||
| CVE-2026-66459 | 2 Space Codes, Wordpress | 2 Ai For Seo, Wordpress | 2026-08-14 | 6.5 Medium |
| Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions. | ||||
| CVE-2026-66462 | 2 Bookingwp, Wordpress | 2 Woocommerce Appointments, Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions. | ||||
| CVE-2026-66463 | 2 Hassan Fakih, Wordpress | 2 Icarry, Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions. | ||||
| CVE-2026-66464 | 2 Toast Plugins, Wordpress | 2 Internal Link Optimiser, Wordpress | 2026-08-14 | 6.5 Medium |
| Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions. | ||||
| CVE-2026-66465 | 2 Agnihd, Wordpress | 2 Cartify, Wordpress | 2026-08-14 | 9.8 Critical |
| Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions. | ||||
| CVE-2026-66466 | 2 Wedevs, Wordpress | 2 Storegrowth: Smart Sales Booster For Woocommerce | Bogo, Upsells, Direct Checkout, Quick View, Side Cart, Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions. | ||||
| CVE-2026-66468 | 2 Powerfulwp, Wordpress | 2 Local Delivery Drivers For Woocommerce, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions. | ||||
| CVE-2026-66469 | 2 Afonso Matos, Wordpress | 2 Arvow Ai Seo Writer, Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions. | ||||
| CVE-2026-66654 | 2 Tangiblewp, Wordpress | 2 Vehica Core, Wordpress | 2026-08-14 | 6 Medium |
| Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions. | ||||
| CVE-2026-66661 | 2 Onokazu, Wordpress | 2 Directories Pro, Wordpress | 2026-08-14 | 7.7 High |
| Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions. | ||||
| CVE-2026-66691 | 2 Scriptsbundle, Wordpress | 2 Nokri, Wordpress | 2026-08-14 | 9.8 Critical |
| Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions. | ||||
| CVE-2025-10308 | 2 Alian, Wordpress | 2 Astro Booking Engine, Wordpress | 2026-08-14 | 4.3 Medium |
| The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion functionality. This makes it possible for unauthenticated attackers to delete all plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | ||||
| CVE-2026-28184 | 2 10web, Wordpress | 2 Form Maker By 10web, Wordpress | 2026-08-14 | N/A |
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||||
| CVE-2026-27539 | 2 Welcart, Wordpress | 2 Welcart E-commerce, Wordpress | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions. | ||||
| CVE-2026-27999 | 2 Themefic, Wordpress | 2 Tourfic, Wordpress | 2026-08-13 | 6.5 Medium |
| Subscriber Broken Access Control in Tourfic <= 2.23.1 versions. | ||||
| CVE-2026-61962 | 2 Hakan Ozevin, Wordpress | 2 Wp Base Booking, Wordpress | 2026-08-13 | 10 Critical |
| Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. | ||||
| CVE-2026-28188 | 2 Themefic, Wordpress | 2 Hydra Booking, Wordpress | 2026-08-13 | 7.3 High |
| Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions. | ||||