Search Results (14612 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-10818 2 Wordpress, Wpforms 2 Wordpress, Wpforms Pro 2026-07-27 8.1 High
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not being deleted upon validation failure. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.
CVE-2026-9830 2 Repute Infosystems, Wordpress 2 Bookingpress Appointment Booking Pro, Wordpress 2026-07-27 8.2 High
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
CVE-2026-14827 2 Calendar, Wordpress 2 Calendar, Wordpress 2026-07-27 6.8 Medium
The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar.
CVE-2026-14820 2 Quizandsurveymaster, Wordpress 2 Quiz And Survey Master, Wordpress 2026-07-27 5.3 Medium
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.
CVE-2026-65562 2 Wordpress, Wpdeveloper 2 Wordpress, Betterdocs 2026-07-27 6.5 Medium
Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.
CVE-2026-65557 2 Tychesoftwares, Wordpress 2 Abandoned Cart Lite For Woocommerce, Wordpress 2026-07-27 5.9 Medium
Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
CVE-2026-59539 2 Cozmoslabs, Wordpress 2 Paid Member Subscriptions, Wordpress 2026-07-27 7.5 High
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
CVE-2026-59556 2 Acowebs, Wordpress 2 Dynamic Pricing With Discount Rules For Woocommerce, Wordpress 2026-07-27 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
CVE-2026-66445 2 100plugins, Wordpress 2 Open User Map, Wordpress 2026-07-27 6.5 Medium
Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.
CVE-2026-59538 2 Ruben Garcia, Wordpress 2 Gamipress, Wordpress 2026-07-27 9.3 Critical
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
CVE-2026-59551 2 Rtcamp, Wordpress 2 Rtmedia For Wordpress, Buddypress And Bbpress, Wordpress 2026-07-27 8.5 High
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
CVE-2026-59529 2 Motovnet, Wordpress 2 Ebook Store, Wordpress 2026-07-27 7.5 High
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
CVE-2026-66428 2 Jgwhite33, Wordpress 2 Wp Google Review Slider, Wordpress 2026-07-27 4.3 Medium
Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
CVE-2026-59527 2 Romancode, Wordpress 2 Mapsvg, Wordpress 2026-07-27 9.3 Critical
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-59533 2 Christoph Vielgrader, Wordpress 2 Relevanssi Light, Wordpress 2026-07-27 9.3 Critical
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
CVE-2026-59560 2 Roxnor, Wordpress 2 Fundengine, Wordpress 2026-07-27 6.5 Medium
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
CVE-2026-66448 2 Wordpress, Wpchill 2 Wordpress, Gallery Photoblocks 2026-07-27 6.5 Medium
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.
CVE-2026-59534 2 Aurovrata Venet, Wordpress 2 Post My Cf7 Form, Wordpress 2026-07-27 7.5 High
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
CVE-2026-59546 2 John Darrel, Wordpress 2 Hide My Wp Ghost, Wordpress 2026-07-27 7.4 High
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
CVE-2026-59553 2 Rextheme, Wordpress 2 Product Feed Manager, Wordpress 2026-07-27 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.