Search

Search Results (369980 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-15015 2 Cascadiawebservices, Wordpress 2 Mountdev Ai Mcp Connector For Wordpress, Wordpress 2026-07-23 9.8 Critical
The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain an administrator-bound OAuth Bearer token via a self-registered client, granting full administrator-equivalent access to the plugin's MCP tool surface and all exposed WordPress content, users, and options. This is exploitable by combining the publicly accessible Dynamic Client Registration endpoint, which allows unauthenticated callers to register arbitrary OAuth clients with an attacker-controlled redirect_uri, with the unprotected authorization endpoint to complete the full OAuth flow without any administrator interaction.
CVE-2025-68081 2 Lester Chan, Wordpress 2 Wp-polls, Wordpress 2026-07-23 5.9 Medium
Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.
CVE-2026-24552 2 Mischiefmarmot, Wordpress 2 Create By Mediavine, Wordpress 2026-07-23 8.5 High
Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions.
CVE-2026-24628 2 Supsystic, Wordpress 2 Photo Gallery By Supsystic, Wordpress 2026-07-23 5.9 Medium
Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.
CVE-2026-24639 2 Ronald Huereca, Wordpress 2 Photo Block, Wordpress 2026-07-23 4.4 Medium
Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
CVE-2026-25405 2 Digitalme, Wordpress 2 Eroom, Wordpress 2026-07-23 8.5 High
Contributor SQL Injection in eRoom <= 1.7.1 versions.
CVE-2026-25427 2 Digitalme, Wordpress 2 Eroom, Wordpress 2026-07-23 5.4 Medium
Subscriber Broken Access Control in eRoom <= 1.7.1 versions.
CVE-2026-27064 2 Everpress, Wordpress 2 Mailster, Wordpress 2026-07-23 9.1 Critical
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
CVE-2026-27377 2 Axiomthemes, Wordpress 2 Quickcal - Appointment Booking Calendar For Wordpress, Wordpress 2026-07-23 6.7 Medium
Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.
CVE-2026-27399 2 Webwizards, Wordpress 2 Marketking, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.
CVE-2026-27422 2 Bplugins, Wordpress 2 Yt Player, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.
CVE-2026-57370 2 Codepress It Solutions Llc, Wordpress 2 Visitor Traffic Real Time Statistics Pro, Wordpress 2026-07-23 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.
CVE-2026-57397 2 Thimpress., Wordpress 2 Coaching, Wordpress 2026-07-23 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions.
CVE-2026-57425 2 Wordpress, Wpdesk 2 Wordpress, Autopay Dla Woocommerce 2026-07-23 6.5 Medium
Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.
CVE-2026-57427 2 Download Monitor, Wordpress 2 Download Monitor - Wpforms Lock, Wordpress 2026-07-23 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.
CVE-2026-57699 2 Bqworks, Wordpress 2 Slider Pro, Wordpress 2026-07-23 7.1 High
Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.
CVE-2026-57785 2 Apustheme, Wordpress 2 Apuslisting, Wordpress 2026-07-23 8.8 High
Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.
CVE-2026-59514 2 Mightynetworks Vs Buddyboss, Wordpress 2 Buddyboss Platform, Wordpress 2026-07-23 9.3 Critical
Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.
CVE-2026-59542 2 Wordpress, Wp Chill 2 Wordpress, Kali Forms 2026-07-23 7.7 High
Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
CVE-2026-59543 2 Wordpress, Wplake 2 Wordpress, Advanced Views 2026-07-23 9.9 Critical
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.