Search Results (15857 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-14982 2 Joomunited, Wordpress 2 Wp File Download, Wordpress 2026-09-04 8.1 High
The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The two-stage exploit requires a first request to the file.save task to persist the path-traversal string into file metadata, followed by a second request to the file.delete task to trigger the unlink call — both endpoints lack capability checks and nonce enforcement.
CVE-2026-82024 2 Thimpress, Wordpress 2 Learnpress, Wordpress 2026-09-03 5.4 Medium
LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persistent malicious payloads by submitting unsanitized input into quiz question answer title fields. Attackers can store arbitrary JavaScript through the answer title parameter, which is rendered through an unescaped HTML sink to execute in the browsers of any user who views the affected quiz question, including students, other instructors, and administrators.
CVE-2026-82023 2 Thimpress, Wordpress 2 Learnpress, Wordpress 2026-09-03 4.3 Medium
LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to persistently modify quiz content across courses they do not own.
CVE-2026-3851 2 Elegant Themes, Wordpress 2 Divi, Wordpress 2026-09-03 6.4 Medium
The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON format in all versions up to, and including, 4.27.6. This is due to two compounding flaws: (1) the save-time sanitization filter `et_builder_sanitize_dynamic_content_fields()` only searches for dynamic content markers in the `@ET-DC@...@` format, but the rendering engine also supports a legacy JSON format that is silently converted at render time, completely bypassing the save-time filter, and (2) the `post_meta_key` resolver in `et_builder_filter_resolve_default_dynamic_content()` does not apply `wp_kses_post()` to the resolved meta value when `enable_html` is set to `on`, passing raw `get_post_meta()` output directly to the page. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2025-7963 2 Tymotey, Wordpress 2 Easy Waveform Player, Wordpress 2026-09-03 6.4 Medium
The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer() function in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-85304 2 Unlimited-elements, Wordpress 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Wordpress 2026-09-03 5.3 Medium
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.17.
CVE-2026-84757 2 Aresit, Wordpress 2 Wp Compress, Wordpress 2026-09-03 8.2 High
Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.
CVE-2026-85305 2 Seopress, Wordpress 2 Seopress, Wordpress 2026-09-03 5.4 Medium
Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress: from n/a through 10.1.
CVE-2026-85308 2 Brainstormforce, Wordpress 2 Sureforms, Wordpress 2026-09-03 5.3 Medium
Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: from n/a through 2.12.5.
CVE-2026-85309 2 Supsystic, Wordpress 2 Ultimate Maps By Supsystic, Wordpress 2026-09-03 5.3 Medium
Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Maps by Supsystic: from n/a through 1.5.3.
CVE-2026-84814 2 Bricksforge, Wordpress 2 Bricksforge, Wordpress 2026-09-03 9.8 Critical
Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
CVE-2026-84777 2 Really-simple-plugins, Wordpress 2 Really Simple Ssl, Wordpress 2026-09-03 7.4 High
Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.
CVE-2026-84768 2 E4jvikwp, Wordpress 2 Vikappointments Services Booking Calendar, Wordpress 2026-09-03 9.3 Critical
Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.
CVE-2026-84762 2 Saad Iqbal, Wordpress 2 Wp Easypay, Wordpress 2026-09-03 5.3 Medium
Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.
CVE-2026-84752 2 Rometheme, Wordpress 2 Rtmkit, Wordpress 2026-09-03 8.8 High
Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.
CVE-2026-84215 2 Arraytics, Wordpress 2 Timetics, Wordpress 2026-09-03 6.5 Medium
Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.
CVE-2026-84756 2 Wclovers, Wordpress 2 Wcfm Membership, Wordpress 2026-09-03 7.1 High
Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.
CVE-2026-84763 2 Rometheme, Wordpress 2 Rtmkit, Wordpress 2026-09-03 7.1 High
Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions.
CVE-2026-84834 2 Eyecix, Wordpress 2 Jobsearch, Wordpress 2026-09-03 9.8 Critical
Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
CVE-2026-84774 2 Veronalabs, Wordpress 2 Wp Statistics, Wordpress 2026-09-03 6.1 Medium
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.