Search Results (9953 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-74004 2 Wordpress, Wpmonks 2 Wordpress, Gravity Booster – Styles & Layouts For Gravity Forms 2026-08-21 5.4 Medium
Subscriber Broken Access Control in Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms <= 6.0 versions.
CVE-2026-74006 2 Wordpress, Wptablebuilder 2 Wordpress, Wp Table Builder 2026-08-21 4.3 Medium
Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
CVE-2026-74007 2 Iberezansky, Wordpress 2 3d Flipbook – Pdf Embedder, Pdf Flipbook Viewer, Flipbook Image Gallery, Wordpress 2026-08-21 5.3 Medium
Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.
CVE-2026-27365 2 Publishpress, Wordpress 2 Publishpress Series, Wordpress 2026-08-21 5.9 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress PublishPress Series allows Stored XSS. This issue affects PublishPress Series: from n/a through 2.17.0.
CVE-2026-73388 2 Teconcetheme, Wordpress 2 Nikstore Core, Wordpress 2026-08-21 9.3 Critical
Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.
CVE-2026-66581 2 Crocoblock. Jetimpex Inc., Wordpress 2 Jetengine, Wordpress 2026-08-21 7.1 High
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.
CVE-2026-66603 2 Dartiss, Wordpress 2 Draft List, Wordpress 2026-08-21 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Artiss Draft List simple-draft-list allows Stored XSS. This issue affects Draft List: from n/a through 2.6.4.
CVE-2026-14287 2 10web, Wordpress 2 10web Booster, Wordpress 2026-08-21 4.7 Medium
The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated request handler and does not escape attacker-supplied stylesheet content before rendering it into the page head, allowing an unauthenticated attacker to store markup that executes as JavaScript in the browser of anonymous visitors to an affected page.
CVE-2026-14334 2 Wordpress, Wpdevart 2 Wordpress, Booking Calendar, Appointment Booking System 2026-08-21 8.8 High
The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary JavaScript when the SVG is opened, including in the session of an administrator who reviews the submitted booking.
CVE-2026-14825 2 Quizandsurveymaster, Wordpress 2 Quiz And Survey Master, Wordpress 2026-08-21 2.7 Low
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users.
CVE-2026-14826 2 Quizandsurveymaster, Wordpress 2 Quiz And Survey Master, Wordpress 2026-08-21 2.7 Low
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient addresses, of quizzes created by other users.
CVE-2026-19709 2 Wordpress, Wpswings 2 Wordpress, Membership For Woocommerce 2026-08-21 5.3 Medium
The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated attackers to reach its REST routes and disclose any user's membership plan details on sites where the API has been enabled but no keys were ever generated.
CVE-2026-66613 2 Crocoblock, Wordpress 2 Jetengine, Wordpress 2026-08-21 9.8 Critical
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
CVE-2026-73363 2 Magepeople, Wordpress 2 Taxi Booking Manager For Woocommerce, Wordpress 2026-08-21 6.5 Medium
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions.
CVE-2026-18315 2 Themetechmount, Wordpress 2 Truebooker-appointment-booking, Wordpress 2026-08-21 9.8 Critical
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including, 1.2.6. This is due to the admin_user_create_cus AJAX handler lacking any authentication or capability check before passing the attacker-supplied truebooker_wp_user_id parameter directly to wp_update_user. This makes it possible for unauthenticated attackers to overwrite the email address of any WordPress user — including an administrator — and then complete the standard WordPress lost-password flow to fully take over the targeted account.
CVE-2026-19615 2 Bowo, Wordpress 2 Admin And Site Enhancements Ase, Wordpress 2026-08-21 6.8 Medium
The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users with a role the site owner granted upload access to store a file containing JavaScript which then executes in the browser of anyone who opens it.
CVE-2026-66583 2 Wordpress, Wpmudev 2 Wordpress, Forminator Forms 2026-08-21 9.8 Critical
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
CVE-2026-66586 2 Themewinter, Wordpress 2 Wpcafe, Wordpress 2026-08-21 6.6 Medium
Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
CVE-2026-16650 2 Wordpress, Wpcharitable 2 Wordpress, Charitable 2026-08-21 5.3 Medium
The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to forge webhook notifications that mark donations as paid without any real payment.
CVE-2026-17559 2 Passster Project, Wordpress 2 Passster, Wordpress 2026-08-21 5.3 Medium
The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which REST API requests may bypass global password protection, comparing them as an unanchored substring of the request URI rather than against the resolved route, allowing an unauthenticated attacker to read the content of globally password-protected posts and pages.