Search Results (15770 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-19435 2 Duplicate Post Project, Wordpress 2 Duplicate Post, Wordpress 2026-08-21 2.7 Low
The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft content.
CVE-2026-15150 2 Mycred, Wordpress 2 Mycred, Wordpress 2026-08-21 5.3 Medium
The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification matches the site's configured merchant account, allowing unauthenticated attackers to have arbitrary amounts of the site's in-site currency credited to an account by completing a payment for the expected amount to a gateway account they control rather than the site's.
CVE-2025-15671 2 Welcart, Wordpress 2 Welcart E-commerce, Wordpress 2026-08-21 5.4 Medium
The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier from a user-supplied request parameter, allowing an unauthenticated attacker to fixate a shop member's session and take over their customer account after the victim logs in through an attacker-crafted request.
CVE-2026-14601 2 Linkwhisper, Wordpress 2 Link Whisper Free, Wordpress 2026-08-21 6.8 Medium
The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection attacks.
CVE-2026-16959 2 Media Library Assistant Project, Wordpress 2 Media Library Assistant, Wordpress 2026-08-21 6.8 Medium
The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection.
CVE-2026-13176 2 Eventin, Wordpress 2 Eventin, Wordpress 2026-08-21 2.7 Low
The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify event ownership, allowing users with contributor-level access and above to trigger blind server-side requests to arbitrary hosts.
CVE-2026-19848 2 Profilepress, Wordpress 2 Profilepress, Wordpress 2026-08-21 6.5 Medium
The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before rendering them on public pages, allowing unauthenticated attackers to store shortcodes that are then executed when the page is viewed, disclosing a chosen user's email address, login and registration date.
CVE-2026-16576 2 Dokan, Wordpress 2 Ai Powered Woocommerce Multivendor Marketplace Solution:dokan: Ai Powered Woocommerce Multivendor Marketplace Solution, Wordpress 2026-08-21 7.2 High
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some of its admin REST API routes, checking only for a WooCommerce management capability instead of the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14-installation capability, allowing users such as Shop Managers to install and activate arbitrary Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 from WordPress.org.
CVE-2026-16575 2 Dokan, Wordpress 2 Ai Powered Woocommerce Multivendor Marketplace Solution:dokan: Ai Powered Woocommerce Multivendor Marketplace Solution, Wordpress 2026-08-21 5.3 Medium
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission configuration returned by one of its unauthenticated store REST endpoints, allowing any unauthenticated user to disclose a vendor's commission type and, when category-based commission is configured, the per-category and default commission rates.
CVE-2026-14325 2 Drag And Drop Multiple File Uploader Pro - Contact Form 7 Project, Wordpress 2 Drag And Drop Multiple File Uploader Pro - Contact Form 7, Wordpress 2026-08-21 3.5 Low
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field.
CVE-2026-66593 2 Cleantalk, Wordpress 2 Security & Malware Scan, Wordpress 2026-08-21 9.3 Critical
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
CVE-2026-66614 2 Squirrly, Wordpress 2 Seo Plugin By Squirrly Seo, Wordpress 2026-08-21 7.1 High
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.
CVE-2026-74001 2 Wordpress, Wpeverest 2 Wordpress, User Registration & Membership 2026-08-21 9.8 Critical
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
CVE-2026-11801 2 Gwin, Wordpress 2 Wpadverts – Classifieds Plugin, Wordpress 2026-08-21 7.5 High
The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve internal site configuration data exposed by the classifieds-types REST endpoint, including registered post types, labels, associated taxonomies, form scheme metadata, contact options, and custom field meta keys.
CVE-2026-75091 2 Mdmag, Wordpress 2 Quill Forms | Conversational Multi Step Forms, Surveys & Quizzes, Wordpress 2026-08-21 7.2 High
The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-28567 2 Fahad Mahmood, Wordpress 2 Wp Sort Order, Wordpress 2026-08-21 7.5 High
Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.
CVE-2026-28570 2 Spabrice, Wordpress 2 Vavo Core, Wordpress 2026-08-21 8.1 High
Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.
CVE-2026-32444 2 Cwicly, Wordpress 2 Cwicly, Wordpress 2026-08-21 9.9 Critical
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
CVE-2026-32463 2 Kamlesh Parmar, Wordpress 2 Sync Post With Other Site, Wordpress 2026-08-21 9.9 Critical
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
CVE-2026-32464 2 Vladimir Prelovac, Wordpress 2 Theme Test Drive, Wordpress 2026-08-21 8.1 High
Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.