Export limit exceeded: 15643 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (15643 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-5097 2 Tomdever, Wordpress 2 Wpforo Forum, Wordpress 2026-08-28 7.5 High
The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-76581 2 Wordpress, Wpmudev 2 Wordpress, Wpmu Dev Dashboard 2026-08-28 9.8 Critical
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated concatenation of the token, state, redirect, and domain values, while step 2 verifies an unseparated concatenation that omits the domain field. This makes it possible for unauthenticated attackers, on sites connected to WPMU DEV with Hub SSO enabled and mapped to an administrator, to obtain a valid HMAC from step 1 and replay it to step 2 by moving the domain value into the redirect field, resulting in an authenticated administrator session.
CVE-2026-78125 2 Learnpress, Wordpress 2 Learnpress, Wordpress 2026-08-27 5.3 Medium
The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in all versions up to, and including, 4.0.2, allowing unauthenticated attackers to disclose the payment status of arbitrary orders by enumerating order identifiers.
CVE-2026-78570 2 Klbtheme, Wordpress 2 Total Donations, Wordpress 2026-08-27 9.8 Critical
The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to elevate their privileges to that of an adminsitrator.
CVE-2021-47983 3 Checkoutplugins, Mra13, Wordpress 3 Stripe Payments For Woocommerce, Accept Stripe Payments, Wordpress 2026-08-27 6.4 Medium
WordPress Plugin Stripe Payments before 2.0.40 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the AcceptStripePayments-settings[currency_code] parameter. Attackers can submit POST requests to /wp-admin/options.php with script payloads in the currency_code field to execute arbitrary JavaScript in administrator browsers when settings are viewed.
CVE-2026-78292 2 Hashthemes, Wordpress 2 Hash Form, Wordpress 2026-08-27 9.8 Critical
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
CVE-2026-32566 2 Acpt, Wordpress 2 Acpt (pro) - Custom Post Types Plugin For Wordpress, Wordpress 2026-08-27 9.8 Critical
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
CVE-2026-19892 2 Infused Addons, Wordpress 2 Infusedwoo Pro, Wordpress 2026-08-27 8.8 High
The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due to a missing capability check in the `ajax_iwar_preview_email()` function, which uses `is_admin()` as its only authorization check and allows low-privilege users to render email preview merge fields for an arbitrary email address. This makes it possible for authenticated attackers, with subscriber-level access and above, to generate and retrieve a valid password reset link for any WordPress user, including administrators, enabling account takeover.
CVE-2026-81271 2 Paolo, Wordpress 2 Geodirectory, Wordpress 2026-08-27 8.8 High
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
CVE-2026-78261 2 Realtyna, Wordpress 2 Realtyna Organic Idx Plugin, Wordpress 2026-08-27 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.
CVE-2026-78267 2 Cozmoslabs, Wordpress 2 Translatepress, Wordpress 2026-08-27 9.8 Critical
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
CVE-2026-78262 2 Wedevs, Wordpress 2 Wp Project Manager, Wordpress 2026-08-27 9.8 Critical
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
CVE-2026-19454 2 Jetbackup, Wordpress 2 Jetbackup, Wordpress 2026-08-27 4.4 Medium
The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network, including every site's data and the shared webroot.
CVE-2026-76549 2 Updraftplus, Wordpress 2 Updraftplus, Wordpress 2026-08-27 5.9 Medium
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier state, via a crafted link.
CVE-2026-32564 2 Acpt, Wordpress 2 Acpt (pro) - Custom Post Types Plugin For Wordpress, Wordpress 2026-08-27 8.5 High
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
CVE-2026-81274 2 Metaphorcreations, Wordpress 2 Ditty, Wordpress 2026-08-27 5.3 Medium
Subscriber Broken Access Control in Ditty <= 3.1.67 versions.
CVE-2026-78293 2 Axew3, Wordpress 2 Wp W3all Phpbb, Wordpress 2026-08-27 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
CVE-2026-78289 2 Loftocean, Wordpress 2 Cozystay, Wordpress 2026-08-27 7.1 High
Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
CVE-2026-78285 2 Likebtn, Wordpress 2 Like Button Rating, Wordpress 2026-08-27 8.5 High
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
CVE-2026-78286 2 Infinitumform, Wordpress 2 Geo Controller, Wordpress 2026-08-27 9.8 Critical
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.