Search Results (20784 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-15991 2 Bitpressadmin, Wordpress 2 File Manager, Wordpress 2026-08-07 8.8 High
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary files on the server, which can lead to remote code execution when the right file is deleted (such as wp-config.php). The bypass is triggered by passing cmd=rm or cmf=file in the URL query string of a POST request: elFinder's bind registration reads the command exclusively from $_POST and therefore never registers the rm.pre permission handler, while the dispatcher reads from the merged $_GET+$_POST superglobal and executes the rm or file command unchecked against a volume that defaults to ABSPATH.
CVE-2026-15459 2 Wordpress, Wpmudev 2 Wordpress, Wpmu Dev Dashboard 2026-08-07 8.1 High
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys the WDP-AUTH request signature is empty, making the signature verified by validate_hash() trivially forgeable; version 5.0.0 additionally removed the replay check in validate_nonce(), and the remote handler is bound to the public init hook with no capability check. This makes it possible for unauthenticated attackers to invoke privileged Hub actions — including installing and activating a plugin from an attacker-supplied URL (resulting in remote code execution), deleting plugins and themes, upgrading WordPress core, or logging in as an administrator via SSO. Sites connected to a WPMU DEV account, which have a non-empty 64-character API key, are not affected.
CVE-2026-18400 2 Metaslider, Wordpress 2 Slider, Gallery, And Carousel By Metaslider – Image Slider, Video Slider, Wordpress 2026-08-07 6.4 Medium
The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and including, 3.111.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The ml-slider custom post type is registered without custom capability restrictions and the ml-slider_settings meta key is unprotected, allowing Author-level users to set the malicious delay value via XML-RPC custom_fields when creating an ml-slider post.
CVE-2025-15678 2 Posimyth, Wordpress 2 Nexter Blocks, Wordpress 2026-08-07 6.1 Medium
The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Author by default), allowing them to upload a file containing malicious JavaScript that executes when the file is accessed, leading to Stored Cross-Site Scripting.
CVE-2026-14204 2 Ivan, Wordpress 2 Google Authenticator Wordpress, Wordpress 2026-08-07 6.5 Medium
The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out of their account.
CVE-2026-5391 2 Latepoint, Wordpress 2 Appointment Booking Plugin – Latepoint | Calendar & Scheduling For Wordpress, Wordpress 2026-08-07 6.4 Medium
The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' shortcode in all versions up to, and including, 5.3.2. This is due to insufficient input sanitization and output escaping in the 'locations' branch of the 'shortcode_latepoint_resources' function. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2025-9266 2 Themegrill, Wordpress 2 Accelerate, Wordpress 2026-08-07 4.3 Medium
The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enqueue_scripts() function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate the ThemeGrill Demo Importer plugin.
CVE-2026-65553 2 Wbolt.com, Wordpress 2 Spider Analyser – Wordpress搜索引擎蜘蛛分析插件, Wordpress 2026-08-07 10 Critical
Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
CVE-2026-15209 2 Jshelpdesk, Wordpress 2 Jshelpdesk, Wordpress 2026-08-07 6.5 Medium
The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body.
CVE-2026-14817 2 Bdthemes, Wordpress 2 Element Pack Addons For Elementor, Wordpress 2026-08-07 6.8 Medium
The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level access or higher to inject arbitrary JavaScript that executes in the session of any visitor who views the affected content.
CVE-2026-16540 2 Nsqua, Wordpress 2 Simply Schedule Appointments, Wordpress 2026-08-07 7.5 High
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.
CVE-2026-16532 2 Link Library Project, Wordpress 2 Link Library, Wordpress 2026-08-07 9.1 Critical
The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
CVE-2026-16968 2 Wordpress, Wpgeodirectory 2 Wordpress, Geodirectory 2026-08-07 6.5 Medium
The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.
CVE-2025-15677 2 Wordpress, Wpgeodirectory 2 Wordpress, Geodirectory 2026-08-07 3.5 Low
The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in a multisite setup).
CVE-2026-15210 2 Glboy, Wordpress 2 Otp Login With Phone Number, Otp Verification, Wordpress 2026-08-07 9.1 Critical
The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.
CVE-2026-15372 2 Wordpress, Wp2fac 2 Wordpress, Wp2fac 2026-08-07 7.5 High
The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.
CVE-2026-16065 2 Welcart, Wordpress 2 Welcart E-commerce, Wordpress 2026-08-07 6.5 Medium
The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks.
CVE-2026-12713 2 Arni Cinco, Wordpress 2 Wpcargo Track & Trace, Wordpress 2026-08-07 9.1 Critical
The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by CVE-2024-44004.
CVE-2026-13153 2 Wordpress, Wpdevteam 2 Wordpress, Gutenberg Essential Blocks 2026-08-07 7.5 High
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product.
CVE-2026-13154 2 Wordpress, Wpdevteam 2 Wordpress, Gutenberg Essential Blocks 2026-08-07 7.5 High
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public.