Export limit exceeded: 14518 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14518 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-14231 | 2 Lifterlms, Wordpress | 2 Lifterlms, Wordpress | 2026-07-30 | 4.3 Medium |
| The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX handlers, only verifying that the user is logged in, allowing any authenticated user with subscriber-level access to read the titles of internal post types such as coupon codes by supplying the post type. | ||||
| CVE-2026-14221 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-07-30 | 3.8 Low |
| The Easy Appointments WordPress plugin through 3.12.26 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and delete bookings. | ||||
| CVE-2026-14188 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-07-30 | 2.7 Low |
| The Easy Appointments WordPress plugin through 3.12.26 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information. | ||||
| CVE-2026-14923 | 2 Syncpostwithothersite, Wordpress | 2 Sync Post With Other Site, Wordpress | 2026-07-30 | 6.5 Medium |
| The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the post-editing capability (such as a Contributor) can create, publish, and overwrite arbitrary Pages, including modifying content authored by higher-privileged users. | ||||
| CVE-2026-12687 | 2 Profilegrid, Wordpress | 2 Profilegrid, Wordpress | 2026-07-30 | 7.5 High |
| The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's configured role, up to Administrator when such a group exists, leading to privilege escalation. | ||||
| CVE-2026-16092 | 2 Labelblanc, Wordpress | 2 Improved Save Button, Wordpress | 2026-07-30 | 6.5 Medium |
| The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field via 'Save and Duplicate' Action in all versions up to, and including, 1.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-14356 | 2 Fleekdash, Wordpress | 2 Fleekdash V2, Wordpress | 2026-07-30 | 8.8 High |
| The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the email address and password of any WordPress user, including administrators, enabling full account takeover and complete site compromise. The public /wp-json/fleekdash/v1/register endpoint auto-provisions a Subscriber-role account and returns a valid REST nonce regardless of the site's users_can_register setting, enabling unauthenticated attackers to self-provision the required credentials and nonce in a single prior request. | ||||
| CVE-2026-1360 | 2 Buddypress, Wordpress | 2 Buddypress, Wordpress | 2026-07-30 | 7.5 High |
| The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary PHP objects via XProfile textbox fields, which could lead to remote code execution if a suitable POP chain is available in the WordPress environment. | ||||
| CVE-2026-14592 | 2 Hitoy, Wordpress | 2 Wp Real Ip-based Access Control, Wordpress | 2026-07-30 | 6.1 Medium |
| The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks before storing one of its option values, and does not escape that value on output on its settings page, allowing unauthenticated users to store arbitrary JavaScript that executes in the context of any administrator who views the page. | ||||
| CVE-2026-15397 | 2 Wordpress, Wpswings | 2 Wordpress, Subscriptions For Woocommerce | 2026-07-30 | 7.2 High |
| The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. This makes it possible for authenticated attackers, with shop manager-level access and above, to install and activate arbitrary WordPress.org plugins. | ||||
| CVE-2026-13330 | 2 Wealcoder, Wordpress | 2 Animation Addons For Elementor, Wordpress | 2026-07-30 | 6.1 Medium |
| The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with the upload_files capability (Author and above) to upload files containing malicious JavaScript, leading to Stored Cross-Site Scripting. | ||||
| CVE-2026-13344 | 2 Wordpress, Wpdevteam | 2 Wordpress, Essential Addons For Elementor | 2026-07-30 | 4.8 Medium |
| The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed, including in the session of an administrator previewing or visiting the post. | ||||
| CVE-2026-14310 | 2 Tutorlms, Wordpress | 2 Tutor Lms Pro, Wordpress | 2026-07-30 | 5.4 Medium |
| The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread belongs to before returning or writing to that thread, allowing authenticated users with subscriber-level access and above who can access any single course to read the Q&A threads of other courses and to inject replies into them. | ||||
| CVE-2026-14207 | 2 Lifterlms, Wordpress | 2 Lifterlms, Wordpress | 2026-07-30 | 6.1 Medium |
| The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field before storing and rendering it, allowing users with a course-editing role to inject JavaScript that executes in the session of an administrator who views the course. | ||||
| CVE-2026-11881 | 2 Fluent Forms, Wordpress | 2 Fluent Forms, Wordpress | 2026-07-30 | 6.1 Medium |
| The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the unfiltered_html capability, e.g. in a multisite setup) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who loads the form, including administrators previewing it. | ||||
| CVE-2026-11880 | 2 Fluent Forms, Wordpress | 2 Fluent Forms, Wordpress | 2026-07-29 | 3.1 Low |
| The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users. | ||||
| CVE-2026-11887 | 2 Salonbookingsystem, Wordpress | 2 Salon Booking System, Wordpress | 2026-07-29 | 4.3 Medium |
| The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to modify a Salon Booking System WordPress plugin before 10.30.20 setting and bypass the manual approval of new bookings. | ||||
| CVE-2026-60137 | 1 Wordpress | 1 Wordpress | 2026-07-29 | 5.9 Medium |
| WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. | ||||
| CVE-2026-5114 | 2 Softaculous, Wordpress | 2 Speedycache – Cache, Optimization, Performance, Wordpress | 2026-07-29 | 4.9 Medium |
| The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.3.8. This is due to a mismatch between CSS URL validation (which allows query strings like `.css?...`) and path resolution (which strips query strings), combined with no validation that the resolved file is actually a CSS file. This makes it possible for authenticated attackers, with Administrator-level access and above, to read arbitrary files from the server (including `wp-config.php` and `/etc/passwd`) by injecting crafted `<link>` tags into page content, with the file contents written to publicly accessible cache files. | ||||
| CVE-2026-17162 | 2 Wordpress, Wpxpo | 2 Wordpress, Wowstore – Store Builder & Product Blocks For Woocommerce | 2026-07-29 | 6.4 Medium |
| The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'currentPostId' Block Attribute in all versions up to, and including, 4.4.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||