Export limit exceeded: 16033 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (16033 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-14357 | 2 Dplugins, Wordpress | 2 Devkit Pro, Wordpress | 2026-09-02 | 8.8 High |
| The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing nonce validation in the DPDEV_install_themes_func() function registered on the wp_ajax_DPDEV_install_themes action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary theme ZIP packages containing PHP files that are extracted into the web-accessible wp-content/themes/ directory, which may make remote code execution possible. | ||||
| CVE-2026-81294 | 2 Paul Ryan, Wordpress | 2 Authorizer, Wordpress | 2026-09-02 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions. | ||||
| CVE-2026-81770 | 2 Mapgeo, Wordpress | 2 Interactive Geo Maps, Wordpress | 2026-09-02 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions. | ||||
| CVE-2026-81771 | 2 Trustedsite, Wordpress | 2 Trustedsite, Wordpress | 2026-09-02 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions. | ||||
| CVE-2026-81774 | 2 Dotstore, Wordpress | 2 Woocommerce Product Attachment, Wordpress | 2026-09-02 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions. | ||||
| CVE-2026-84835 | 2 Dimafreund, Wordpress | 2 Rentsyst, Wordpress | 2026-09-02 | 5.3 Medium |
| Missing Authorization vulnerability in DimaFreund Rentsyst allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rentsyst: from n/a through 2.1.2. | ||||
| CVE-2026-84770 | 2 Kitae-park, Wordpress | 2 Mang Board Wp, Wordpress | 2026-09-02 | 8.8 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions. | ||||
| CVE-2026-82223 | 2 Arraytics, Wordpress | 2 Wp Event Solution, Wordpress | 2026-09-02 | 6.5 Medium |
| Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions. | ||||
| CVE-2026-81288 | 2 Wordpress, Wp Swings | 2 Wordpress, Upsell Order Bump Offer For Woocommerce | 2026-09-02 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions. | ||||
| CVE-2026-66652 | 2 Themegoods, Wordpress | 2 Grand Tour, Wordpress | 2026-09-02 | 5.4 Medium |
| Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery. This issue affects Grand Tour: from n/a through 5.5.1. | ||||
| CVE-2026-82852 | 2 Mapsvg, Wordpress | 2 Mapsvg, Wordpress | 2026-09-02 | 5.4 Medium |
| Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions. | ||||
| CVE-2026-81756 | 2 E-goi, Wordpress | 2 Smart Marketing Sms And Newsletters Forms, Wordpress | 2026-09-02 | 9.3 Critical |
| Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. | ||||
| CVE-2026-81291 | 2 Uncode, Wordpress | 2 Uncode, Wordpress | 2026-09-02 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions. | ||||
| CVE-2026-74010 | 2 John James Jacoby, Wordpress | 2 Bbpress, Wordpress | 2026-09-02 | 5.3 Medium |
| Missing Authorization vulnerability in John James Jacoby bbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects bbPress: from n/a through 2.6.14. | ||||
| CVE-2026-66047 | 2 Properfraction, Wordpress | 2 Profilepress, Wordpress | 2026-09-02 | 8.1 High |
| ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the ppress_connect_process AJAX handler. Attackers can supply a caller-controlled URL through the file request parameter to trigger silent plugin installation and activation, achieving PHP code execution as the web-server user. | ||||
| CVE-2026-74927 | 2 Multivendorx, Wordpress | 2 Multivendorx, Wordpress | 2026-09-02 | 5.3 Medium |
| The MultiVendorX WordPress plugin before 5.0.15 does not have proper authorisation controls on one of its REST API listing routes, allowing unauthenticated users to retrieve vendor contact and payout details, pending payout amounts, and administrative notes attached to store applications. | ||||
| CVE-2026-83562 | 2 Wclovers, Wordpress | 2 Wcfm Marketplace, Wordpress | 2026-09-02 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions. | ||||
| CVE-2026-19251 | 2 Ultimatemember, Wordpress | 2 Ultimate Member, Wordpress | 2026-09-02 | 5.3 Medium |
| The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whether the profile it belongs to is private, before returning profile activity to unauthenticated visitors, allowing them to read the content of comments still awaiting moderation. | ||||
| CVE-2026-19453 | 2 Jetbackup, Wordpress | 2 Jetbackup, Wordpress | 2026-09-02 | 7.1 High |
| The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it administrator privileges, allowing a subscriber-level user to gain administrator access after the site owner restores or migrates the site. | ||||
| CVE-2026-77783 | 2 Rank Math Seo, Wordpress | 2 Rank Math Seo, Wordpress | 2026-09-02 | 3.7 Low |
| The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated visitors to disclose the schema and associated content of draft, pending, private, scheduled and password-protected posts. | ||||