Export limit exceeded: 15986 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (15986 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-14326 2 Timetics, Wordpress 2 Timetics, Wordpress 2026-09-03 3.8 Low
The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members.
CVE-2026-77793 2 Registrationmagic, Wordpress 2 Registrationmagic, Wordpress 2026-09-03 5.3 Medium
The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account.
CVE-2026-77794 2 Registrationmagic, Wordpress 2 Registrationmagic, Wordpress 2026-09-03 5.3 Medium
The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the form grants.
CVE-2026-81571 2 Brave, Wordpress 2 Brave, Wordpress 2026-09-03 4.8 Medium
The Brave WordPress plugin before 0.8.8 does not prevent a URL parameter used to pre-fill a form field from being passed to WordPress's shortcode engine, allowing unauthenticated attackers to have arbitrary shortcodes registered on the site executed server-side.
CVE-2026-84771 2 Publishpress, Wordpress 2 Publishpress Permissions, Wordpress 2026-09-02 5.3 Medium
Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions.
CVE-2026-82182 2 Wordpress, Wpvividplugins 2 Wordpress, Wpvivid — Backup, Migration & Staging 2026-09-02 4.1 Medium
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied list of identifiers before using it in a SQL query, allowing administrators to perform SQL injection attacks.
CVE-2026-81289 2 Sonaar, Wordpress 2 Mp3 Audio Player For Music, Radio & Podcast, Wordpress 2026-09-02 7.1 High
Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions.
CVE-2026-81294 2 Paul Ryan, Wordpress 2 Authorizer, Wordpress 2026-09-02 9.8 Critical
Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
CVE-2026-81770 2 Mapgeo, Wordpress 2 Interactive Geo Maps, Wordpress 2026-09-02 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.
CVE-2026-81771 2 Trustedsite, Wordpress 2 Trustedsite, Wordpress 2026-09-02 7.1 High
Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions.
CVE-2026-81774 2 Dotstore, Wordpress 2 Woocommerce Product Attachment, Wordpress 2026-09-02 7.5 High
Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.
CVE-2026-84835 2 Dimafreund, Wordpress 2 Rentsyst, Wordpress 2026-09-02 5.3 Medium
Missing Authorization vulnerability in DimaFreund Rentsyst allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rentsyst: from n/a through 2.1.2.
CVE-2026-84770 2 Kitae-park, Wordpress 2 Mang Board Wp, Wordpress 2026-09-02 8.8 High
Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.
CVE-2026-82223 2 Arraytics, Wordpress 2 Wp Event Solution, Wordpress 2026-09-02 6.5 Medium
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions.
CVE-2026-81288 2 Wordpress, Wp Swings 2 Wordpress, Upsell Order Bump Offer For Woocommerce 2026-09-02 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.
CVE-2026-66652 2 Themegoods, Wordpress 2 Grand Tour, Wordpress 2026-09-02 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery. This issue affects Grand Tour: from n/a through 5.5.1.
CVE-2026-66047 2 Properfraction, Wordpress 2 Profilepress, Wordpress 2026-09-02 8.1 High
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the ppress_connect_process AJAX handler. Attackers can supply a caller-controlled URL through the file request parameter to trigger silent plugin installation and activation, achieving PHP code execution as the web-server user.
CVE-2026-74927 2 Multivendorx, Wordpress 2 Multivendorx, Wordpress 2026-09-02 5.3 Medium
The MultiVendorX WordPress plugin before 5.0.15 does not have proper authorisation controls on one of its REST API listing routes, allowing unauthenticated users to retrieve vendor contact and payout details, pending payout amounts, and administrative notes attached to store applications.
CVE-2026-83562 2 Wclovers, Wordpress 2 Wcfm Marketplace, Wordpress 2026-09-02 6.5 Medium
Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.
CVE-2026-19251 2 Ultimatemember, Wordpress 2 Ultimate Member, Wordpress 2026-09-02 5.3 Medium
The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whether the profile it belongs to is private, before returning profile activity to unauthenticated visitors, allowing them to read the content of comments still awaiting moderation.