Search

Search Results (404438 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-103482 2026-10-11 5.4 Medium
The Simple Newsletter Plugin – Noptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noptin_fields[<custom_field_merge_tag>] (e.g. first_name)' parameter in all versions up to, and including, 4.3.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The attack chain requires a published campaign post whose body contains a [[subscriber.*]] merge tag; the unauthenticated attacker first POSTs the entity-encoded payload to the public manage_preferences form (which issues its own nonce on the same page), then pivots execution by embedding their confirm_key in a campaign preview URL sent to a privileged user via social engineering.
CVE-2026-103478 2026-10-11 6.4 Medium
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkout[billing][phone] (and state / taxid / email)' parameter in all versions up to, and including, 7.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-103427 2026-10-11 6.4 Medium
The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'country' parameter in all versions up to, and including, 4.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Unauthenticated attackers may also exploit this vulnerability when the plugin's Enable Free Membership feature is turned on, as it permits anonymous front-end registration and profile submission.
CVE-2026-103424 2026-10-11 5.4 Medium
The Anti-Spam by CleanTalk – Spam Protection Without CAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 6.88 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is exploitable once a comment from the attacker's email address has been approved; on default WordPress installations, only the first comment from a given email address is held for moderation, meaning subsequent comments auto-approve and immediately expose the payload to site visitors.
CVE-2026-103357 2026-10-11 N/A
Missing Authorization vulnerability in VillaTheme GIFT4U gift4u-gift-cards-all-in-one-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GIFT4U: from n/a through 1.1.3.
CVE-2026-103071 2026-10-11 7.5 High
Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Code Injection.This issue affects Thank You Page Customizer for WooCommerce: from n/a through 1.2.3.
CVE-2026-102774 2026-10-11 6.4 Medium
The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Image 'alt' Attribute in Community Post Content in all versions up to, and including, 1.12.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The entity-encoded payload bypasses server-side wp_kses filtering because kses permits the img/alt tag combination and does not normalize entities inside attribute values; the decode occurs client-side when GLightbox reads the .alt DOM property and assigns the result to innerHTML.
CVE-2026-102401 2026-10-11 6.4 Medium
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regurl' parameter in all versions up to, and including, 3.3.71 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload only fires for logged-out site visitors, as the vulnerable login-form.php template branch is gated on !is_user_logged_in(); authenticated users viewing the same page are served a different template and are not affected.
CVE-2026-101921 2026-10-11 4.7 Medium
The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'attacker-chosen key referenced by the smart tag (e.g. "x")' parameter in all versions up to, and including, 2.0.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that a site administrator has previously saved a form whose description embeds a {query_var} Smart Tag inside an iframe srcdoc attribute and has enabled Show Description on a public-facing page.
CVE-2026-101920 2026-10-11 7.2 High
The Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'comment (href attribute inside comment content)' parameter in all versions up to, and including, 5.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable in the free build because the plugin's author-filter rewriter never appends the ?m_bm=true marker to its own anchors (Plugin::has_pro() returns false), meaning every href the byline script selects and rewrites is fully attacker-controlled.
CVE-2026-101324 2026-10-11 4.7 Medium
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'any attacker-chosen name matching the {get.NAME} placeholder (PoC uses 'proof')' parameter in all versions up to, and including, 6.2.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires a site administrator to have configured a Custom HTML field on a published form containing a {get.*} SmartCode inside a URL-accepting attribute such as iframe src or a href — a documented Fluent Forms feature.
CVE-2026-100196 2026-10-11 7.2 High
The LazyLoad Plugin – Lazy Load Images, Videos, and Iframes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment_content (rendered inline into the page HTML)' parameter in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress core's wp_kses_data allow-list does not strip the crafted payload on save because it uses only permitted tags and attributes; the event handler is concealed inside a broken attribute region and is only promoted to a real DOM attribute by the plugin's render-time str_replace transformation. Additionally, a site administrator must approve the crafted comment before the payload is served to other visitors.
CVE-2026-100178 2026-10-11 7.2 High
The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'adverts_location' parameter in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-100161 2026-10-11 7.2 High
The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'wcpr_image_upload_id' parameter in all versions up to, and including, 1.2.30 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The publicly-emitted `wcpr_image_upload` nonce printed on every product review form is the only gate, and no capability, authentication, or attachment ownership check is performed, allowing the payload to be stored in comment meta — which is not subject to `wp_kses` — by any unauthenticated visitor; the XSS fires once the review is visible on the frontend.
CVE-2026-100147 2 Funnelkit, Wordpress-extensions 2 Funnelkit, Funnelkit 2026-10-11 7.2 High
The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shipping_first_name' parameter in all versions up to, and including, 3.16.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-108615 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController delete handler that allows low-privileged authenticated users to delete AI evaluator records. Attackers can send DELETE requests to /airag/extData/delete with any id parameter to remove other users' AI evaluator or test-tracking records without owner or tenant checks.
CVE-2026-108681 1 Zhayujie 1 Cowagent 2026-10-11 4.3 Medium
A security flaw has been discovered in zhayujie CowAgent up to 2.1.7. Impacted is an unknown function of the file channel/web/web_channel.py of the component Web Console. The manipulation of the argument session_id results in denial of service. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. Version 2.1.7 (commit dec28324) only partly mitigates via a 512MB body cap. The vendor was contacted early about this disclosure.
CVE-2026-108584 1 Funnywolf 1 Viper 2026-10-11 5.3 Medium
A security flaw has been discovered in FunnyWolf Viper up to 3.1.11. The affected element is an unknown function of the file /root/viper/.git/config. Performing a manipulation results in hard-coded credentials. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
CVE-2026-108578 1 Neterbit 1 Nw-431f 2026-10-11 5.3 Medium
A vulnerability was identified in Neterbit NW-431F 20250715. Impacted is an unknown function of the file /sms.json of the component Embedded Web Server. Such manipulation leads to information disclosure. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-108577 1 Konstanty Bialkowski 1 Libmodplug 2026-10-11 4.3 Medium
A vulnerability was determined in Konstanty Bialkowski libmodplug up to 0.8.9.1. This issue affects the function abc_add_gchord of the file src/load_abc.cpp of the component ABC Music Format Parser. This manipulation causes resource consumption. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.