Search Results (15739 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-84762 2 Saad Iqbal, Wordpress 2 Wp Easypay, Wordpress 2026-09-03 5.3 Medium
Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.
CVE-2026-84752 2 Rometheme, Wordpress 2 Rtmkit, Wordpress 2026-09-03 8.8 High
Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.
CVE-2026-84215 2 Arraytics, Wordpress 2 Timetics, Wordpress 2026-09-03 6.5 Medium
Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.
CVE-2026-84761 2 Litespeed Technologies, Wordpress 2 Litespeed Cache, Wordpress 2026-09-03 7.2 High
Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions.
CVE-2026-84756 2 Wclovers, Wordpress 2 Wcfm Membership, Wordpress 2026-09-03 7.1 High
Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.
CVE-2026-84763 2 Rometheme, Wordpress 2 Rtmkit, Wordpress 2026-09-03 7.1 High
Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions.
CVE-2026-84813 2 Paolo, Wordpress 2 Geodirectory, Wordpress 2026-09-03 9.3 Critical
Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.
CVE-2026-84834 2 Eyecix, Wordpress 2 Jobsearch, Wordpress 2026-09-03 9.8 Critical
Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
CVE-2026-84774 2 Veronalabs, Wordpress 2 Wp Statistics, Wordpress 2026-09-03 6.1 Medium
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.
CVE-2025-15692 2 Icegram, Wordpress 2 Icegram Express, Wordpress 2026-09-03 3.5 Low
The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users with the Administrator role and above to perform Stored Cross-Site Scripting attacks.
CVE-2026-9055 2 Ameliabooking, Wordpress 2 Booking For Appointments And Events Calendar, Wordpress 2026-09-03 9.8 Critical
The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a WordPress user with the wpamelia-manager role when the 'externalId' parameter is set to 0. This makes it possible for unauthenticated attackers to escalate their privileges to administrator by first elevating to the manager role, then creating a provider entity linked to an administrator user ID and overwriting that administrator's password.
CVE-2026-16966 2 Solacewp, Wordpress 2 Solace Extra, Wordpress 2026-09-03 5.3 Medium
The Solace Extra WordPress plugin before 1.7.0 does not perform any authorization or post-status checks in one of its AJAX actions, allowing unauthenticated visitors to read the content of non-published (draft, pending, private, and trashed) Site Builder parts that WordPress would otherwise not serve.
CVE-2026-19719 2 Inisev, Wordpress 2 Social Media Share Buttons & Social Sharing Icons, Wordpress 2026-09-03 6.8 Medium
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handler, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks which are triggered when a visitor interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration.
CVE-2026-19723 2 Inisev, Wordpress 2 Social Media Share Buttons & Social Sharing Icons, Wordpress 2026-09-03 7.1 High
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration.
CVE-2026-78151 2 Formsplayer, Wordpress 2 Formsplayer, Wordpress 2026-09-03 5.3 Medium
The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's full stored configuration in the response to its public submission handler, allowing unauthenticated users to disclose notification recipient addresses, confirmation redirect targets and integration settings, including those of unpublished forms.
CVE-2026-80467 2 Acf-extended, Wordpress 2 Advanced Custom Fields:extended, Wordpress 2026-09-03 8.1 High
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities and then escalate it to administrator.
CVE-2026-81194 2 Stylemix, Wordpress 2 Masterstudy Lms Wordpress Plugin, Wordpress 2026-09-03 4.3 Medium
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers to read other instructors' course sales records by supplying another user's identifier.
CVE-2026-81195 2 Stylemix, Wordpress 2 Masterstudy Lms Wordpress Plugin, Wordpress 2026-09-03 5.3 Medium
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning per-student course enrollment and progress data, allowing unauthenticated attackers to disclose the enrolled courses and learning progress of any registered user.
CVE-2026-81196 2 Stylemix, Wordpress 2 Masterstudy Lms Wordpress Plugin, Wordpress 2026-09-03 2.7 Low
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access to read other instructors' quiz questions, including the correct answers and explanations.
CVE-2026-81197 2 Stylemix, Wordpress 2 Masterstudy Lms Wordpress Plugin, Wordpress 2026-09-03 5.3 Medium
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route that lists an author's courses, nor does it filter that listing by publication status, allowing unauthenticated users to read the titles and IDs of unpublished (draft, pending and private) courses.