Export limit exceeded: 25263 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (537 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-6831 | 2 Vsourz, Wordpress-extensions | 2 Advanced Contact Form 7 Db, Advanced Contact Form 7 Db | 2026-09-28 | 6.5 Medium |
| The Advanced Contact form 7 DB plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 2.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to read all Contact Form 7 submission data via the 'acf7db' shortcode. | ||||
| CVE-2026-86601 | 1 Wordpress-extensions | 1 Wp Recipe Maker | 2026-09-28 | 6.5 Medium |
| The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it while building a page's structured metadata, allowing unauthenticated users to have arbitrary shortcodes executed server side and to read the content of unpublished recipes. | ||||
| CVE-2026-86612 | 1 Wordpress-extensions | 1 Ninja Tables | 2026-09-28 | 5.6 Medium |
| The Ninja Tables WordPress plugin before 5.2.17 does not restrict shortcode expansion to administrator-authored table rows which, in a non-default configuration, allows unauthenticated users to have arbitrary shortcodes executed on a public page, and to permanently break that page, by submitting an ordinary form entry. | ||||
| CVE-2026-87070 | 1 Wordpress-extensions | 1 Forminator Forms | 2026-09-28 | 5.3 Medium |
| The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before preferring client-supplied forwarding headers over the connecting address, and it uses that value both to enforce its per-visitor voting limit and to record who submitted an entry. Unauthenticated visitors can therefore vote without limit on any poll and can choose the address stored against every submission they make. | ||||
| CVE-2026-87071 | 1 Wordpress-extensions | 1 Forminator Forms | 2026-09-28 | 5.3 Medium |
| The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys WordPress reserves for its own use, so unauthenticated visitors submitting a public form that collects post content can attach metadata of their choosing to the post their submission creates. | ||||
| CVE-2026-87848 | 1 Wordpress-extensions | 1 Mpcx Lightbox | 2026-09-28 | 3.7 Low |
| The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any authorisation or authentication on one of its AJAX actions available to unauthenticated users, nor does it check the status of the requested post, allowing unauthenticated visitors to retrieve the title, content or excerpt of arbitrary posts, including private, draft, pending, trashed and password-protected ones. | ||||
| CVE-2026-87978 | 1 Wordpress-extensions | 1 Paymob For Woocommerce | 2026-09-28 | 5.3 Medium |
| The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its payment webhook, allowing unauthenticated attackers to mark arbitrary WooCommerce orders as paid without any payment. | ||||
| CVE-2026-90950 | 1 Wordpress-extensions | 1 Paid Member Subscriptions | 2026-09-28 | 5.3 Medium |
| The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the request, allowing unauthenticated users to create accounts without solving the reCAPTCHA the site has enabled. | ||||
| CVE-2026-93618 | 2 Crocoblock. Jetimpex Inc., Wordpress-extensions | 2 Jettricks, Jettricks | 2026-09-28 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetTricks allows Stored XSS. This issue affects JetTricks: from n/a through 2.0.1. | ||||
| CVE-2026-3253 | 2 Mailerlite, Wordpress-extensions | 2 Mailerlite Signup Forms, Mailerlite-signup Forms | 2026-09-28 | 4.3 Medium |
| The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the forms() method of the AdminController class in all versions up to, and including, 1.7.21. This makes it possible for authenticated attackers, with Contributor-level access and above, to create or delete arbitrary signup forms. | ||||
| CVE-2026-4806 | 2 Alexvtn, Wordpress-extensions | 2 Custom Thank You Page For Woocommerce, Custom Thank You Page For Woocommerce | 2026-09-28 | 6.5 Medium |
| The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the save_option() function in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to export or reset(delete) the plugin's settings. | ||||
| CVE-2026-89303 | 1 Wordpress-extensions | 1 Post Voting System | 2026-09-28 | 6.4 Medium |
| The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks. | ||||
| CVE-2026-93000 | 1 Wordpress-extensions | 1 Sps-suite | 2026-09-28 | 6.8 Medium |
| The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks. | ||||
| CVE-2026-89300 | 1 Wordpress-extensions | 1 Wp Verify Api | 2026-09-28 | 5.3 Medium |
| The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate limited either. | ||||
| CVE-2026-84744 | 1 Wordpress-extensions | 1 Wpforms Lite | 2026-09-28 | 6.5 Medium |
| The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts. | ||||
| CVE-2026-86838 | 1 Wordpress-extensions | 1 Bookly | 2026-09-28 | 5.3 Medium |
| The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step. | ||||
| CVE-2026-92996 | 1 Wordpress-extensions | 1 Verge3d | 2026-09-28 | 5.3 Medium |
| The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users to mark any order as paid. | ||||
| CVE-2026-88828 | 1 Wordpress-extensions | 1 Blacklist Manager For Woocommerce | 2026-09-28 | 5.4 Medium |
| The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded. | ||||
| CVE-2026-89411 | 1 Wordpress-extensions | 1 Paymattic | 2026-09-28 | 5.3 Medium |
| The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it. | ||||
| CVE-2026-82841 | 1 Wordpress-extensions | 1 Updraftplus | 2026-09-28 | 5.3 Medium |
| The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration state, allowing any authenticated user, such as a subscriber, to retrieve the credentials of the configured backup destinations, such as passwords and secret keys. | ||||