Search Results (11547 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-15453 2 Iqonicdesign, Wordpress 2 Kivicare – Clinic & Patient Management System (ehr), Wordpress 2026-08-15 6.5 Medium
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'searchTerm' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a KiviCare custom role with the 'settings_view' permission (e.g., Doctor or Receptionist), meaning standard WordPress subscribers cannot exploit this without a KiviCare-assigned role.
CVE-2026-13610 2 Iqonic, Wordpress 2 Kivicare, Wordpress 2026-08-14 7.5 High
The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.
CVE-2026-66426 2 Lesterchan, Wordpress 2 Wp-stats, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions.
CVE-2026-66454 2 Maruti Mohanty, Wordpress 2 Wp Social Avatar, Wordpress 2026-08-14 6.5 Medium
Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.
CVE-2026-28154 2 Snstheme, Wordpress 3 M.anh - Fashion Woocoommerce Wordpress Theme, Samex - Clean, Minimal Shop Woocommerce Wordpress Theme, Wordpress 2026-08-14 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS. This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress Theme: from n/a through 2.5; M.Anh - Fashion WooCoommerce WordPress Theme: from n/a through 1.7.
CVE-2026-19050 2 Prosolution, Wordpress 2 Prosolution Wp Client, Wordpress 2026-08-14 6.4 Medium
The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requester, before performing a server-side HTTP request with it, allowing any authenticated user, such as a subscriber, to make the site issue arbitrary requests to internal hosts and services, including requests with an attacker-chosen method, headers and body.
CVE-2026-27345 2 Magepeople, Wordpress 2 Taxi Booking Manager For Woocommerce, Wordpress 2026-08-14 7.5 High
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
CVE-2026-27537 2 Supsysticcom, Wordpress 2 Smart Popup By Supsystic, Wordpress 2026-08-14 6.5 Medium
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions.
CVE-2026-28004 2 Strategy11team, Wordpress 2 Business Directory Plugin, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions.
CVE-2026-28149 2 Miniorange, Wordpress 2 Headless Single Sign On, Wordpress 2026-08-14 9.8 Critical
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
CVE-2026-28189 2 Rolandbarkerxnauwebdesign, Wordpress 2 Participants Database, Wordpress 2026-08-14 7.4 High
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions.
CVE-2026-61965 2 Ahmad, Wordpress 2 Geekybot, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions.
CVE-2026-61967 2 Miniorange, Wordpress 2 Otp Verification, Wordpress 2026-08-14 9.8 Critical
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
CVE-2026-66424 2 Cozyvision, Wordpress 2 Sms Alert Order Notifications, Wordpress 2026-08-14 9.8 Critical
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
CVE-2026-66429 2 Codepress It Solutions Llc, Wordpress 2 Visitor Traffic Real Time Statistics Pro, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
CVE-2026-66430 2 Codepress It Solutions Llc, Wordpress 2 Visitor Traffic Real Time Statistics Pro, Wordpress 2026-08-14 8.5 High
Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
CVE-2026-66456 2 Bestwebsoft, Wordpress 2 Profile Extra Fields, Wordpress 2026-08-14 6.5 Medium
Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
CVE-2026-66461 2 Smepay, Wordpress 2 Smepay:upi Gateway For Woocommerce, Wordpress 2026-08-14 7.5 High
Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.
CVE-2026-66467 2 Wordpress, Wpmanageninja 2 Wordpress, Fluentcommunity 2026-08-14 6.5 Medium
Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.
CVE-2026-66653 2 Edge-themes, Wordpress 2 Barista, Wordpress 2026-08-14 8.1 High
Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions.