Search Results (10499 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-57425 2 Wordpress, Wpdesk 2 Wordpress, Autopay Dla Woocommerce 2026-07-23 6.5 Medium
Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.
CVE-2026-61954 2 Payu India, Wordpress 2 Payu India, Wordpress 2026-07-23 7.5 High
Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
CVE-2026-61972 2 Woolentor, Wordpress 2 Shoplentor Pro, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
CVE-2026-61973 2 Woolentor, Wordpress 2 Shoplentor Pro, Wordpress 2026-07-23 4.3 Medium
Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
CVE-2026-65457 2 Wordpress, Yoomoney 2 Wordpress, Юkassa Для Woocommerce 2026-07-23 4.3 Medium
Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
CVE-2026-65472 2 Kit, Wordpress 2 Kit (formerly Convertkit), Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
CVE-2026-65479 2 Mvp Themes, Wordpress 2 Reviewer, Wordpress 2026-07-23 5.4 Medium
Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
CVE-2026-65485 2 Daniel Iser, Wordpress 2 Content Control, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
CVE-2026-65486 2 Bastien Ho, Wordpress 2 Event Post, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
CVE-2026-65500 2 Pixelacehq, Wordpress 2 Manual - Documentation, Knowledge Base & Education Wordpress Theme, Wordpress 2026-07-23 7.5 High
Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
CVE-2026-65524 2 Themefusion, Wordpress 2 Avada Custom Branding, Wordpress 2026-07-23 4.3 Medium
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
CVE-2026-65525 2 Uxper, Wordpress 2 Civi Framework, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
CVE-2026-65537 2 Themeisle, Wordpress 2 Cyr To Lat Reloaded – Transliteration Of Links And File Names, Wordpress 2026-07-23 4.3 Medium
Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
CVE-2026-13061 1 Mongodb 2 Mongodb, Mongodb Server 2026-07-23 4.3 Medium
An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally restricted to users with cluster-level administrative privileges, and includes active session identifiers, associated usernames, and activity timestamps.
CVE-2026-65050 2 Ninjaforms, Wordpress 2 Ninja Forms, Wordpress 2026-07-23 6.5 Medium
Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding the block with an arbitrary formID on a published post. Attackers can retrieve the signed bearer token injected into every page visitor's browser via `wp_localize_script` and use it against the REST API submissions endpoint to access all saved form submission field values, including sensitive personally identifiable information such as names, email addresses, and phone numbers.
CVE-2026-65452 2 Motovnet, Wordpress 2 Ebook Store, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
CVE-2026-27418 2 Epsiloncool, Wordpress 2 Wp Fast Total Search, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.
CVE-2026-59522 2 Wedevs, Wordpress 2 Wp Erp, Wordpress 2026-07-23 6.5 Medium
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
CVE-2026-65489 2 Lastudio, Wordpress 2 La-studio Element Kit For Elementor, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
CVE-2026-65495 2 Dokan Multivendor Plugin, Wordpress 2 Dokan Pro, Wordpress 2026-07-23 7.5 High
Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.