Export limit exceeded: 15990 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (15990 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-78125 2 Learnpress, Wordpress 2 Learnpress, Wordpress 2026-08-27 5.3 Medium
The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in all versions up to, and including, 4.0.2, allowing unauthenticated attackers to disclose the payment status of arbitrary orders by enumerating order identifiers.
CVE-2021-47983 3 Checkoutplugins, Mra13, Wordpress 3 Stripe Payments For Woocommerce, Accept Stripe Payments, Wordpress 2026-08-27 6.4 Medium
WordPress Plugin Stripe Payments before 2.0.40 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the AcceptStripePayments-settings[currency_code] parameter. Attackers can submit POST requests to /wp-admin/options.php with script payloads in the currency_code field to execute arbitrary JavaScript in administrator browsers when settings are viewed.
CVE-2026-78292 2 Hashthemes, Wordpress 2 Hash Form, Wordpress 2026-08-27 9.8 Critical
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
CVE-2026-32566 2 Acpt, Wordpress 2 Acpt (pro) - Custom Post Types Plugin For Wordpress, Wordpress 2026-08-27 9.8 Critical
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
CVE-2026-19892 2 Infused Addons, Wordpress 2 Infusedwoo Pro, Wordpress 2026-08-27 8.8 High
The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due to a missing capability check in the `ajax_iwar_preview_email()` function, which uses `is_admin()` as its only authorization check and allows low-privilege users to render email preview merge fields for an arbitrary email address. This makes it possible for authenticated attackers, with subscriber-level access and above, to generate and retrieve a valid password reset link for any WordPress user, including administrators, enabling account takeover.
CVE-2026-81271 2 Paolo, Wordpress 2 Geodirectory, Wordpress 2026-08-27 8.8 High
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
CVE-2026-78261 2 Realtyna, Wordpress 2 Realtyna Organic Idx Plugin, Wordpress 2026-08-27 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.
CVE-2026-78267 2 Cozmoslabs, Wordpress 2 Translatepress, Wordpress 2026-08-27 9.8 Critical
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
CVE-2026-78262 2 Wedevs, Wordpress 2 Wp Project Manager, Wordpress 2026-08-27 9.8 Critical
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
CVE-2026-19454 2 Jetbackup, Wordpress 2 Jetbackup, Wordpress 2026-08-27 4.4 Medium
The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network, including every site's data and the shared webroot.
CVE-2026-76549 2 Updraftplus, Wordpress 2 Updraftplus, Wordpress 2026-08-27 5.9 Medium
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier state, via a crafted link.
CVE-2026-32564 2 Acpt, Wordpress 2 Acpt (pro) - Custom Post Types Plugin For Wordpress, Wordpress 2026-08-27 8.5 High
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
CVE-2026-81274 2 Metaphorcreations, Wordpress 2 Ditty, Wordpress 2026-08-27 5.3 Medium
Subscriber Broken Access Control in Ditty <= 3.1.67 versions.
CVE-2026-78293 2 Axew3, Wordpress 2 Wp W3all Phpbb, Wordpress 2026-08-27 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
CVE-2026-78289 2 Loftocean, Wordpress 2 Cozystay, Wordpress 2026-08-27 7.1 High
Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
CVE-2026-78285 2 Likebtn, Wordpress 2 Like Button Rating, Wordpress 2026-08-27 8.5 High
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
CVE-2026-78286 2 Infinitumform, Wordpress 2 Geo Controller, Wordpress 2026-08-27 9.8 Critical
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
CVE-2026-81276 2 Wordpress, Wp Chill 2 Wordpress, Kali Forms 2026-08-27 5.3 Medium
Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.
CVE-2026-19632 2 Cozmoslabs, Wordpress 2 Translatepress – Translate Multilingual Sites With Ai Translation, Wordpress 2026-08-26 9.8 Critical
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated attackers to extract the raw administrator password-reset URL — including the plaintext reset key and login parameters stored in the translation dictionary table — enabling full administrator account takeover. This vulnerability is only exploitable when automatic string saving is enabled (the default setting) and the target administrator's profile locale is set to a published secondary language, as these conditions cause the password-reset URL to be persisted as a translatable string in the secondary-language dictionary table.
CVE-2026-3424 2 Properfraction, Wordpress 2 Kk Star Ratings – Rate Post & Collect User Feedbacks, Wordpress 2026-08-26 5.3 Medium
The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3. This is due to the software allowing users to execute an action that does not properly validate the 'payload' value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.