Export limit exceeded: 15768 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 15768 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15768 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-18324 | 2 Wordpress, Wpmudev | 2 Wordpress, Forminator Forms – Contact Form, Payment Form & Custom Form Builder | 2026-08-28 | 7.2 High |
| The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that the targeted Textarea field has the Rich-Text editor option enabled. | ||||
| CVE-2026-16759 | 2 Themeum, Wordpress | 2 Tutor Lms – Elearning And Online Course Solution, Wordpress | 2026-08-28 | 6.5 Medium |
| The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote Code Execution limited to zero-argument function invocation in all versions up to, and including, 4.0.5 via the tutor_course_filter_ajax AJAX action. This is due to missing authorization on the handler combined with unsanitized array keys being passed to extract() inside tutor_load_template(), allowing attacker-controlled POST data to overwrite the local $template variable and, in the resulting templates/single-content-loader.php template, the $method_map and $context variables invoked at $method_map[$context](). This makes it possible for unauthenticated attackers to call an arbitrary zero-argument PHP function server-side and, via WordPress core edit_user(), to create a persistent subscriber-level account from request parameters. | ||||
| CVE-2026-27330 | 2 Weptile, Wordpress | 2 Mobile App For Woocommerce, Wordpress | 2026-08-28 | 8.6 High |
| Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions. | ||||
| CVE-2026-32550 | 2 Liquid Web, Llc, Wordpress | 2 Kadence Shop Kit, Wordpress | 2026-08-28 | 8.5 High |
| Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions. | ||||
| CVE-2026-78260 | 2 Epayco, Wordpress | 2 Epayco, Wordpress | 2026-08-28 | 9.3 Critical |
| Unauthenticated SQL Injection in Epayco <= 8.4.6 versions. | ||||
| CVE-2026-78281 | 2 Codepeople, Wordpress | 2 Cp Media Player, Wordpress | 2026-08-28 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions. | ||||
| CVE-2026-78283 | 2 Codepeople, Wordpress | 2 Music Player For Woocommerce, Wordpress | 2026-08-28 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions. | ||||
| CVE-2026-81272 | 2 Wordpress, Wp Manage Ninja | 2 Wordpress, Fluentplayer Pro | 2026-08-28 | 4.9 Medium |
| Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions. | ||||
| CVE-2026-81277 | 2 Villatheme, Wordpress | 2 Suggestion Engine For Woocommerce, Wordpress | 2026-08-28 | 8.5 High |
| Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions. | ||||
| CVE-2026-6128 | 2 Servmask, Wordpress | 2 All-in-one Wp Migration Unlimited Extension, Wordpress | 2026-08-28 | 6.4 Medium |
| The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ai1wm_backups_path' parameter in all versions up to, and including, 2.84. This is due to insufficient input sanitization and output escaping on user-supplied attributes combined with missing authorization checks on the settings() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the plugin settings page. The vulnerability was partially patched in version 2.84. | ||||
| CVE-2026-19423 | 2 Ultimatemember, Wordpress | 2 Ultimate Member, Wordpress | 2026-08-28 | 8.1 High |
| The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form permits, and screens the value against the site's registered role names rather than against the form's own allow-list, allowing unauthenticated users who register through the Ultimate Member WordPress plugin before 2.13.0's own form to grant themselves arbitrary capabilities and reach administrator-equivalent access. | ||||
| CVE-2026-76053 | 2 Cozmoslabs, Wordpress | 2 Translatepress – Translate Multilingual Sites With Ai Translation, Wordpress | 2026-08-28 | 7.2 High |
| The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser in all versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation is possible because WordPress's comment KSES allowlist permits the payload structure — an anchor tag with href and title attributes alongside a code tag — causing the malicious comment to be stored verbatim in the database, where it is later processed by the vulnerable parser during page translation. | ||||
| CVE-2026-82123 | 2 Tangible, Wordpress | 2 Loops & Logic, Wordpress | 2026-08-28 | 6.5 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tangible Loops & Logic. | ||||
| CVE-2026-5097 | 2 Tomdever, Wordpress | 2 Wpforo Forum, Wordpress | 2026-08-28 | 7.5 High |
| The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-76581 | 2 Wordpress, Wpmudev | 2 Wordpress, Wpmu Dev Dashboard | 2026-08-28 | 9.8 Critical |
| The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated concatenation of the token, state, redirect, and domain values, while step 2 verifies an unseparated concatenation that omits the domain field. This makes it possible for unauthenticated attackers, on sites connected to WPMU DEV with Hub SSO enabled and mapped to an administrator, to obtain a valid HMAC from step 1 and replay it to step 2 by moving the domain value into the redirect field, resulting in an authenticated administrator session. | ||||
| CVE-2026-78125 | 2 Learnpress, Wordpress | 2 Learnpress, Wordpress | 2026-08-27 | 5.3 Medium |
| The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in all versions up to, and including, 4.0.2, allowing unauthenticated attackers to disclose the payment status of arbitrary orders by enumerating order identifiers. | ||||
| CVE-2021-47983 | 3 Checkoutplugins, Mra13, Wordpress | 3 Stripe Payments For Woocommerce, Accept Stripe Payments, Wordpress | 2026-08-27 | 6.4 Medium |
| WordPress Plugin Stripe Payments before 2.0.40 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the AcceptStripePayments-settings[currency_code] parameter. Attackers can submit POST requests to /wp-admin/options.php with script payloads in the currency_code field to execute arbitrary JavaScript in administrator browsers when settings are viewed. | ||||
| CVE-2026-78292 | 2 Hashthemes, Wordpress | 2 Hash Form, Wordpress | 2026-08-27 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions. | ||||
| CVE-2026-32566 | 2 Acpt, Wordpress | 2 Acpt (pro) - Custom Post Types Plugin For Wordpress, Wordpress | 2026-08-27 | 9.8 Critical |
| Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | ||||
| CVE-2026-19892 | 2 Infused Addons, Wordpress | 2 Infusedwoo Pro, Wordpress | 2026-08-27 | 8.8 High |
| The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due to a missing capability check in the `ajax_iwar_preview_email()` function, which uses `is_admin()` as its only authorization check and allows low-privilege users to render email preview merge fields for an arbitrary email address. This makes it possible for authenticated attackers, with subscriber-level access and above, to generate and retrieve a valid password reset link for any WordPress user, including administrators, enabling account takeover. | ||||
