Search Results (11556 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-18464 2 Wordpress, Wp Maps Pro 2 Wordpress, Wp Maps Pro 2026-08-10 7.5 High
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service.
CVE-2026-14224 2 Easy-appointments, Wordpress 2 Easy Appointments, Wordpress 2026-08-10 5.4 Medium
The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment's edit form. A subscriber-level user with an appointment of their own can therefore reuse that nonce to overwrite the customer metadata (email, name, phone, description) of another user's appointment. Because the Easy Appointments WordPress plugin before 3.12.28 then treats that metadata as the appointment's contact data, a subsequent administrator status change with customer notifications enabled delivers the victim's appointment notification to the attacker-controlled email address.
CVE-2026-14221 2 Easy-appointments, Wordpress 2 Easy Appointments, Wordpress 2026-08-10 3.8 Low
The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and delete bookings.
CVE-2026-14188 2 Easy-appointments, Wordpress 2 Easy Appointments, Wordpress 2026-08-10 2.7 Low
The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information.
CVE-2026-14223 2 Easy-appointments, Wordpress 2 Easy Appointments, Wordpress 2026-08-10 4.3 Medium
The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier.
CVE-2026-14222 2 Easy-appointments, Wordpress 2 Easy Appointments, Wordpress 2026-08-10 3.8 Low
The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.
CVE-2026-14226 2 Easy-appointments, Wordpress 2 Easy Appointments, Wordpress 2026-08-10 4.3 Medium
The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookings on the site, including customer names, schedules, and statuses.
CVE-2026-66662 2 Shabti, Wordpress 2 Frontend Admin By Dynamapps, Wordpress 2026-08-08 9.8 Critical
Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
CVE-2026-66664 2 Squirrly, Wordpress 2 Seo Plugin By Squirrly Seo, Wordpress 2026-08-08 7.1 High
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.
CVE-2026-66694 2 Thrive Themes Coupon, Wordpress 2 Thrive Architect, Wordpress 2026-08-08 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
CVE-2026-66705 2 Facebook, Wordpress 2 Facebook For Wordpress, Wordpress 2026-08-08 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
CVE-2026-66707 2 Facebook, Wordpress 2 Facebook For Woocommerce, Wordpress 2026-08-08 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
CVE-2026-12801 2 Themefic, Wordpress 2 Ultimate Addons For Contact Form 7, Wordpress 2026-08-08 6.4 Medium
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slider 'data-label' and 'data-separator' attributes in all versions up to, and including, 3.5.43 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-14331 2 Subscribe2 Project, Wordpress 2 Subscribe2, Wordpress 2026-08-08 6.1 Medium
The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a public subscription form, leading to Reflected Cross-Site Scripting that executes in the browser of an unauthenticated visitor who interacts with the form through a crafted link.
CVE-2026-15361 2 Contentviewspro, Wordpress 2 Content Views, Wordpress 2026-08-08 8.1 High
The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks.
CVE-2026-11907 2 Wordpress, Xwp 2 Wordpress, Stream – Activity Log & Audit Trail 2026-08-08 6.5 Medium
The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to access all Stream activity records via the Heartbeat API.
CVE-2026-66701 2 Cozmoslabs, Wordpress 2 Profile Builder, Wordpress 2026-08-08 5.3 Medium
Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
CVE-2026-66692 2 Colissimo, Wordpress 2 Colissimo Officiel : Méthodes De Livraison Pour Woocommerce, Wordpress 2026-08-08 4.3 Medium
Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
CVE-2026-66684 2 Akshaymenariya, Wordpress 2 Export Import Menus, Wordpress 2026-08-08 5.3 Medium
Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.
CVE-2026-66452 2 It-recht Kanzlei, Wordpress 2 Legal Text Connector Of The It-recht Kanzlei, Wordpress 2026-08-08 6.5 Medium
Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.