Export limit exceeded: 387012 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (387012 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-84021 | 2026-09-06 | 6.8 Medium | ||
| The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a filter that can be evaded, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user clicks the affected link. | ||||
| CVE-2026-83544 | 2026-09-06 | 6.8 Medium | ||
| The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed. | ||||
| CVE-2026-83543 | 2026-09-06 | 4.1 Medium | ||
| The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the response. | ||||
| CVE-2026-82846 | 2026-09-06 | 6.8 Medium | ||
| The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of anyone viewing the course, including a logged-in administrator. | ||||
| CVE-2026-82304 | 2 Musicstore, Wordpress | 2 Music Store, Wordpress | 2026-09-06 | 8.6 High |
| The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users. | ||||
| CVE-2026-81424 | 2026-09-06 | 5.3 Medium | ||
| The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who complete a genuine payment to obtain fulfilment for a different, equal- or lower-priced product than the one they paid for. | ||||
| CVE-2026-81423 | 2026-09-06 | 4.3 Medium | ||
| The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect visitors to an arbitrary external website, which can be leveraged for phishing. | ||||
| CVE-2026-81404 | 2026-09-06 | 7.1 High | ||
| The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who are tricked into submitting a crafted request. | ||||
| CVE-2026-81348 | 2026-09-06 | 3.7 Low | ||
| The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post content, comments and post URLs from a site the administrator placed behind mandatory login. | ||||
| CVE-2026-80439 | 2 Redirection-for-contact-form7, Wordpress | 2 Redirection For Contact Form 7, Wordpress | 2026-09-06 | 4.8 Medium |
| The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticated users to run any shortcode registered on the site and read its output. | ||||
| CVE-2026-80437 | 2 Ninjaforms, Wordpress | 2 Ninja Forms, Wordpress | 2026-09-06 | 4.8 Medium |
| The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site. | ||||
| CVE-2026-78362 | 2026-09-06 | 9.8 Critical | ||
| The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, which is its normal operating state. | ||||
| CVE-2026-78150 | 2026-09-06 | 2.7 Low | ||
| The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges and above to copy any private or password protected post into a draft of their own and read its content and metadata. | ||||
| CVE-2026-78149 | 2026-09-06 | 5.3 Medium | ||
| The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenticated AJAX action, allowing unauthenticated users to read protected post content and the password that guards it. | ||||
| CVE-2026-77826 | 2 Registrationmagic, Wordpress | 2 Registrationmagic, Wordpress | 2026-09-06 | 8.8 High |
| The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user registration is disabled. | ||||
| CVE-2026-75793 | 2 Surecart, Wordpress | 2 Surecart, Wordpress | 2026-09-06 | 6.5 Medium |
| The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled. | ||||
| CVE-2026-19862 | 2026-09-06 | 4.8 Medium | ||
| The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender. Exploitation requires the site to be configured to take one of the message's addresses from a form field. | ||||
| CVE-2026-19861 | 2026-09-06 | 4.7 Medium | ||
| The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other recipients. Whether injected script executes depends on the recipient's mail client, but the injected markup is rendered regardless. | ||||
| CVE-2026-19859 | 2026-09-06 | 6.5 Medium | ||
| The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registered on the site on any page displaying a form. Escaping is applied to that content before a later shortcode-expansion pass rather than after it, so the escaping can be bypassed. | ||||
| CVE-2026-19858 | 2026-09-06 | 7.5 High | ||
| The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft content, and secrets other JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 store in metadata. | ||||