Export limit exceeded: 14612 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14612 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-59536 | 2 Cocart Headless, Wordpress | 2 Cocart – Headless Ecommerce, Wordpress | 2026-07-27 | 7.5 High |
| Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions. | ||||
| CVE-2026-59537 | 2 Sender, Wordpress | 2 Sender – Newsletter, Sms And Email Marketing Automation For Woocommerce, Wordpress | 2026-07-27 | 7.6 High |
| Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions. | ||||
| CVE-2026-59548 | 2 Byteflows, Wordpress | 2 Byteflows Travel & Hotel Booking, Wordpress | 2026-07-27 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions. | ||||
| CVE-2026-59552 | 2 Shahadat Hossain, Wordpress | 2 3d Flipbook Pdf Viewer & Embedder, Wordpress | 2026-07-27 | 7.2 High |
| Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | ||||
| CVE-2026-59557 | 2 Franky, Wordpress | 2 Events Made Easy, Wordpress | 2026-07-27 | 6.5 Medium |
| Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions. | ||||
| CVE-2026-59559 | 2 Themewant, Wordpress | 2 Rt Mega Menu – Mega Menu Builder For Elementor & Gutenberg, Wordpress | 2026-07-27 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | ||||
| CVE-2026-65433 | 2 Themewant, Wordpress | 2 Rt Mega Menu – Mega Menu Builder For Elementor & Gutenberg, Wordpress | 2026-07-27 | 6.5 Medium |
| Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | ||||
| CVE-2026-65435 | 2 Thrive Themes Coupon, Wordpress | 2 Thrive Leads Version, Wordpress | 2026-07-27 | 6.5 Medium |
| Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions. | ||||
| CVE-2026-65558 | 2 Wordpress, Wpcenter | 2 Wordpress, Affiliatex | 2026-07-27 | 5.4 Medium |
| Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions. | ||||
| CVE-2026-65561 | 2 Miniorange, Wordpress | 2 Wordpress Social Login And Register, Wordpress | 2026-07-27 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions. | ||||
| CVE-2026-65563 | 2 Themeisle, Wordpress | 2 Orbit Fox By Themeisle, Wordpress | 2026-07-27 | 5.9 Medium |
| Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions. | ||||
| CVE-2026-65567 | 2 Nexcess, Wordpress | 2 Event Tickets, Wordpress | 2026-07-27 | 5.3 Medium |
| Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions. | ||||
| CVE-2026-66434 | 2 Sayontan Sinha, Wordpress | 2 Photonic Gallery & Lightbox For Flickr, Smugmug & Others, Wordpress | 2026-07-27 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions. | ||||
| CVE-2026-66437 | 2 Themeisle, Wordpress | 2 Feedzy, Wordpress | 2026-07-27 | 4.9 Medium |
| Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions. | ||||
| CVE-2026-66442 | 2 Wordpress, Yaycommerce | 2 Wordpress, Yaypricing | 2026-07-27 | 5.4 Medium |
| Subscriber Broken Access Control in YayPricing <= 3.5.6 versions. | ||||
| CVE-2026-66474 | 2 Ht Plugins, Wordpress | 2 Insert Headers And Footers Code – Ht Script, Wordpress | 2026-07-27 | 4.3 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions. | ||||
| CVE-2026-66475 | 2 Acowebs, Wordpress | 2 Checkout Field Editor For Woocommerce – Checkout Manager, Wordpress | 2026-07-27 | 5.9 Medium |
| Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versions. | ||||
| CVE-2026-15962 | 2 Techjewel, Wordpress | 2 Fluent Forms Pro Add On Pack, Wordpress | 2026-07-27 | 8.8 High |
| The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a user meta field is mapped. | ||||
| CVE-2026-12987 | 2 Events Manager Project, Wordpress | 2 Events Manager, Wordpress | 2026-07-27 | 7.5 High |
| The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP object injection. The resulting gadget chain reaches a database query that is built without parameterisation, so an unauthenticated attacker can read arbitrary database data (e.g. user password hashes, secret keys) when the booking is later loaded. | ||||
| CVE-2026-65564 | 2 Chrisrichardson, Wordpress | 2 Mappress Maps For Wordpress, Wordpress | 2026-07-27 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions. | ||||