Search Results (15845 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-84836 2 Kirillbdev, Wordpress 2 Wc Ukraine Shipping, Wordpress 2026-09-04 7.1 High
Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions.
CVE-2026-84847 2 Brightvesseldev, Wordpress 2 Quick Event Manager, Wordpress 2026-09-04 7.5 High
Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
CVE-2026-84848 2 Brightvesseldev, Wordpress 2 Quick Event Manager, Wordpress 2026-09-04 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.
CVE-2026-85307 2 Kevin Pirnie, Wordpress 2 Kp Agent Ready, Wordpress 2026-09-04 5.3 Medium
Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready allows Retrieve Embedded Sensitive Data. This issue affects KP Agent Ready: from n/a before 1.2.08.
CVE-2026-11613 2 Divi Engine, Wordpress 2 Divi Ajax Filter, Wordpress 2026-09-04 9.8 Critical
The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. This vulnerability is only exploitable when the loop_templates parameter is set to 'custom-template'.
CVE-2026-15354 2 Mauro Cassani, Wordpress 2 Acpt (premium), Wordpress 2026-09-04 9.8 Critical
The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling `wp_update_user()`. This makes it possible for unauthenticated attackers to overwrite any WordPress user's email address and password, including an administrator's, and take over the account. Successful exploitation requires a public ACPT user form that permits anonymous submissions.
CVE-2026-27347 2 Crocoblock, Wordpress 2 Jetpopup, Wordpress 2026-09-04 5.3 Medium
Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JetPopup: from n/a through 2.0.20.2.
CVE-2026-79632 2 Getwpfunnels, Wordpress 2 Wpfunnels, Wordpress 2026-09-04 5.3 Medium
The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing unauthenticated users to make the site send emails to arbitrary recipients with an arbitrary subject.
CVE-2026-82194 2 Wordpress, Wpvividplugins 2 Wordpress, Wpvivid — Backup, Migration & Staging 2026-09-04 5.5 Medium
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root.
CVE-2026-84146 2 Wordpress, Xpro 2 Wordpress, Xpro Addons — 140+ Widgets For Elementor 2026-09-04 5.3 Medium
The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summary from a supplied product identifier, allowing unauthenticated visitors to retrieve the title, price, SKU, description and stock details of products that are not publicly published (draft, pending, private or scheduled status).
CVE-2026-12483 2 Stellarwp, Wordpress 2 Learndash Lms, Wordpress 2026-09-04 7.5 High
The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. This is due to insufficient input validation in the 'learndash_fileupload_process' function, which iterates through an entire array and validates only the first file. This makes it possible for authenticated attackers, with subscriber-level access and above who are enrolled in a course with assignment uploads enabled, to upload arbitrary disallowed files, including PHP files, to the server's wp-content/uploads/learndash/assignments/ directory. The uploaded files can only be used for Remote Code Execution if default server configurations have been changed to allow for execution.
CVE-2026-85306 2 Cascadiawebservices, Wordpress 2 Mountdev Ai Mcp Connector For Wordpress, Wordpress 2026-09-04 6.5 Medium
Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MountDev AI MCP Connector for WordPress: from n/a through 1.6.5.
CVE-2026-84813 2 Paolo, Wordpress 2 Geodirectory, Wordpress 2026-09-04 9.3 Critical
Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.
CVE-2026-84761 2 Litespeed Technologies, Wordpress 2 Litespeed Cache, Wordpress 2026-09-04 7.2 High
Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions.
CVE-2026-79630 2 Getwpfunnels, Wordpress 2 Wpfunnels, Wordpress 2026-09-04 5.3 Medium
The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was configured for, allowing unauthenticated users to obtain any purchasable product at a discount intended for a different one, with the reduced price carried through to the total of the order they place.
CVE-2026-79631 2 Getwpfunnels, Wordpress 2 Wpfunnels, Wordpress 2026-09-04 5.3 Medium
The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, allowing unauthenticated users to download customer order details and opt-in form submissions when logging is enabled.
CVE-2026-81347 2 Dynamiapps, Wordpress 2 Frontend Admin By Dynamiapps, Wordpress 2026-09-04 5.9 Medium
The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outside the intended directory, including the WordPress root, which can render the site inoperable. Successful exploitation requires a non-default form configuration.
CVE-2026-82193 2 Wordpress, Wpvividplugins 2 Wordpress, Wpvivid — Backup, Migration & Staging 2026-09-04 5.5 Medium
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing administrators to write files of permitted types to arbitrary locations on the server and to overwrite existing files.
CVE-2026-80438 2 Ninjaforms, Wordpress 2 Ninja Forms, Wordpress 2026-09-04 5.9 Medium
The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user granted that capability to read Ninja Forms WordPress plugin before 3.15.2 settings and stored form submissions, overwrite the Ninja Forms WordPress plugin before 3.15.2's configuration, and create or modify arbitrary posts and pages. The capability belongs to no default WordPress role and the Ninja Forms WordPress plugin before 3.15.2 never grants it, so an administrator must have assigned it, typically when delegating access to the form builder.
CVE-2026-32480 2 Wclovers, Wordpress 2 Wcfm Membership, Wordpress 2026-09-04 5.3 Medium
Missing Authorization vulnerability in WC Lovers WCFM Membership allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WCFM Membership: from n/a through 2.11.11.