Search Results (537 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-89424 2 Inisev, Wordpress-extensions 2 Duplicate Post, Duplicate Post 2026-10-01 6.4 Medium
The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires that the site owner has enabled the plugin's User Level Permissions for the Subscriber role, as this grants access to the i_saw_this_noti AJAX branch needed to deliver the payload.
CVE-2026-97661 2 Scottpaterson, Wordpress-extensions 2 Business Essentials For Contact Form 7, Business Essentials For Contact Form 7 2026-10-01 7.2 High
The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Form Field in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Payments module to be enabled and a form to be configured to accept both PayPal and Stripe as payment gateways.
CVE-2026-103353 2 Wordpress-extensions, Wpmanageninja 2 Fluentform, Fluent Forms 2026-10-01 5.3 Medium
Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects FluentForm: from n/a through 6.2.14.
CVE-2026-103067 2 Memberful, Wordpress-extensions 2 Memberful - Membership Plugin, Memberful 2026-10-01 8 High
Cross-Site Request Forgery (CSRF) vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Cross Site Request Forgery.This issue affects Memberful - Membership Plugin: from n/a through 1.81.0.
CVE-2026-103340 2 Geminilabs, Wordpress-extensions 2 Site Reviews, Site Reviews 2026-10-01 5.3 Medium
Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 8.3.2.
CVE-2026-102381 2 Ahmad, Wordpress-extensions 2 Majestic Support, Majestic Support 2026-10-01 5.3 Medium
Missing Authorization vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0.
CVE-2026-102390 2 Villatheme, Wordpress-extensions 2 Affi – Affiliate Marketing For Woocommerce, Affi - Affiliate Marketing For Woocommerce 2026-10-01 5.3 Medium
Missing Authorization vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.9.
CVE-2026-103063 2 Wordpress-extensions, Wpmet 2 Elementskit Elementor Addons Lite, Elementskit Elementor Addons 2026-10-01 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor addons Lite: from n/a through 4.0.6.
CVE-2026-102379 2 Villatheme, Wordpress-extensions 2 Buildkit – Product Builder For Woocommerce – Custom Pc Builder, Buildkit-product Builder For Woocommerce-custom Pc Builder 2026-10-01 8.5 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Blind SQL Injection.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28.
CVE-2026-62061 2 Metagauss, Wordpress-extensions 2 Profilegrid, Profilegrid 2026-10-01 5.3 Medium
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 6.0.0.2.
CVE-2026-62060 2 Captivateaudio, Wordpress-extensions 2 Captivate Sync, Captivate Sync 2026-10-01 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Blind SQL Injection.This issue affects Captivate Sync: from n/a through 3.3.2.
CVE-2026-62059 2 Ultimatemember, Wordpress-extensions 2 Ultimate Member, Ultimate Member 2026-10-01 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ultimate Member: from n/a through 2.13.1.
CVE-2026-103752 2 Paul Ryan, Wordpress-extensions 2 Authorizer, Authorizer 2026-10-01 9.8 Critical
Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions.
CVE-2026-62071 2 Nickboss, Wordpress-extensions 2 Wordpress File Upload, Wordpress File Upload 2026-10-01 9.3 Critical
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.
CVE-2026-97269 2 Getwpfunnels, Wordpress-extensions 2 Wpfunnels, Wpfunnels 2026-10-01 6.5 Medium
Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions.
CVE-2026-96268 2 Getawesomesupport, Wordpress-extensions 2 Awesome Support, Awesome Support 2026-10-01 6.4 Medium
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users against other accounts because the AJAX handlers accept an arbitrary gdpr-user ID without verifying it belongs to the requester, and the required wpas-gdpr-nonce is emitted via wp_localize_script to every logged-in user on frontend plugin pages and on /wp-admin/profile.php.
CVE-2026-90992 2 Davidanderson, Wordpress-extensions 2 Redux Framework, Redux Framework 2026-10-01 6.4 Medium
The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User Meta Merge via 'user-mediaurl' Media Field in all versions up to, and including, 4.5.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users who can store a payload in user meta fields such as the biography, session_tokens (via a crafted User-Agent at login), or persisted_preferences (via the REST API), which are then promoted to the site-wide redux_demo option when a media URL repair is triggered on the demo panel.
CVE-2026-85235 2 Wordpress-extensions, Wpmudev 2 Forminator Forms, Forminator Forms 2026-10-01 7.2 High
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires an administrator to open the stored submission entry in the Forminator Entries view and interact with the planted link, at which point WordPress core's jQuery-based click handler on `.contextual-help-tabs a` evaluates the entity-decoded href as HTML, firing the attacker's payload in the administrator's authenticated wp-admin session.
CVE-2026-101925 2 Robin-w, Wordpress-extensions 2 Bbp Style Pack, Bbp Style Pack 2026-10-01 6.4 Medium
The bbp style pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name (via /wp-admin/profile.php) + bbp_reply_content (via bbPress reply form)' parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires the attacker to wrap their crafted reply in a &lt;pre&gt; block, which prevents WordPress's wpautop/wptexturize processors from converting straight double quotes in the stored display name into typographic curly-quote entities that would otherwise neutralize the attribute-injection.
CVE-2026-62058 2 Wordpress-extensions, Wpexperts 2 Cf7 Apps, Cf7 Apps 2026-10-01 5.3 Medium
Insertion of Sensitive Information Into Sent Data vulnerability in WPExperts CF7 Apps contact-form-7-honeypot allows Retrieve Embedded Sensitive Data.This issue affects CF7 Apps: from n/a through 3.7.2.