Export limit exceeded: 15987 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15987 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-32566 | 2 Acpt, Wordpress | 2 Acpt (pro) - Custom Post Types Plugin For Wordpress, Wordpress | 2026-08-27 | 9.8 Critical |
| Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | ||||
| CVE-2026-19892 | 2 Infused Addons, Wordpress | 2 Infusedwoo Pro, Wordpress | 2026-08-27 | 8.8 High |
| The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due to a missing capability check in the `ajax_iwar_preview_email()` function, which uses `is_admin()` as its only authorization check and allows low-privilege users to render email preview merge fields for an arbitrary email address. This makes it possible for authenticated attackers, with subscriber-level access and above, to generate and retrieve a valid password reset link for any WordPress user, including administrators, enabling account takeover. | ||||
| CVE-2026-81271 | 2 Paolo, Wordpress | 2 Geodirectory, Wordpress | 2026-08-27 | 8.8 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions. | ||||
| CVE-2026-78261 | 2 Realtyna, Wordpress | 2 Realtyna Organic Idx Plugin, Wordpress | 2026-08-27 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions. | ||||
| CVE-2026-78267 | 2 Cozmoslabs, Wordpress | 2 Translatepress, Wordpress | 2026-08-27 | 9.8 Critical |
| Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions. | ||||
| CVE-2026-78262 | 2 Wedevs, Wordpress | 2 Wp Project Manager, Wordpress | 2026-08-27 | 9.8 Critical |
| Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions. | ||||
| CVE-2026-19454 | 2 Jetbackup, Wordpress | 2 Jetbackup, Wordpress | 2026-08-27 | 4.4 Medium |
| The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network, including every site's data and the shared webroot. | ||||
| CVE-2026-76549 | 2 Updraftplus, Wordpress | 2 Updraftplus, Wordpress | 2026-08-27 | 5.9 Medium |
| The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier state, via a crafted link. | ||||
| CVE-2026-32564 | 2 Acpt, Wordpress | 2 Acpt (pro) - Custom Post Types Plugin For Wordpress, Wordpress | 2026-08-27 | 8.5 High |
| Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | ||||
| CVE-2026-81274 | 2 Metaphorcreations, Wordpress | 2 Ditty, Wordpress | 2026-08-27 | 5.3 Medium |
| Subscriber Broken Access Control in Ditty <= 3.1.67 versions. | ||||
| CVE-2026-78293 | 2 Axew3, Wordpress | 2 Wp W3all Phpbb, Wordpress | 2026-08-27 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions. | ||||
| CVE-2026-78289 | 2 Loftocean, Wordpress | 2 Cozystay, Wordpress | 2026-08-27 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions. | ||||
| CVE-2026-78285 | 2 Likebtn, Wordpress | 2 Like Button Rating, Wordpress | 2026-08-27 | 8.5 High |
| Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions. | ||||
| CVE-2026-78286 | 2 Infinitumform, Wordpress | 2 Geo Controller, Wordpress | 2026-08-27 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions. | ||||
| CVE-2026-81276 | 2 Wordpress, Wp Chill | 2 Wordpress, Kali Forms | 2026-08-27 | 5.3 Medium |
| Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions. | ||||
| CVE-2026-19632 | 2 Cozmoslabs, Wordpress | 2 Translatepress – Translate Multilingual Sites With Ai Translation, Wordpress | 2026-08-26 | 9.8 Critical |
| The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated attackers to extract the raw administrator password-reset URL — including the plaintext reset key and login parameters stored in the translation dictionary table — enabling full administrator account takeover. This vulnerability is only exploitable when automatic string saving is enabled (the default setting) and the target administrator's profile locale is set to a published secondary language, as these conditions cause the password-reset URL to be persisted as a translatable string in the secondary-language dictionary table. | ||||
| CVE-2026-3424 | 2 Properfraction, Wordpress | 2 Kk Star Ratings – Rate Post & Collect User Feedbacks, Wordpress | 2026-08-26 | 5.3 Medium |
| The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3. This is due to the software allowing users to execute an action that does not properly validate the 'payload' value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. | ||||
| CVE-2026-77694 | 2 Eventin, Wordpress | 2 Eventin, Wordpress | 2026-08-26 | 5.3 Medium |
| The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed to authorise on an order, allowing unauthenticated users to mark their own unpaid order as completed and be issued a valid paid ticket with no payment taken. | ||||
| CVE-2026-77754 | 2 Kirki, Wordpress | 2 Kirki, Wordpress | 2026-08-26 | 5.3 Medium |
| The Kirki WordPress plugin before 6.0.14 does not perform a capability check on some endpoints of one of its public AJAX actions, allowing unauthenticated users to retrieve the email addresses of registered users and comment authors, as well as non-public page content and settings. | ||||
| CVE-2026-13172 | 2 Eventin, Wordpress | 2 Eventin, Wordpress | 2026-08-26 | 5.3 Medium |
| The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and private posts belonging to other users, along with the passwords and contents of password-protected ones. | ||||