Search Results (11570 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-15906 2 Codename065, Wordpress 2 Premium Packages – Sell Digital Products Securely, Wordpress 2026-08-02 6.5 Medium
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with admin-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-15794 2 Berocket, Wordpress 2 Grid/list View For Woocommerce, Wordpress 2026-08-02 6.4 Medium
The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The shortcode's all_page="1" attribute can be used to force the widget to render on any page, expanding the attack surface beyond shop and category pages.
CVE-2026-15348 2 Codename065, Wordpress 2 Premium Packages – Sell Digital Products Securely, Wordpress 2026-08-02 6.3 Medium
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via the `wpdmppdl` parameter. This is due to the `download()` function — hooked to the unauthenticated WordPress `wp` action — decoding the attacker-controlled `wpdmppdl` parameter using only `base64_decode()` and `json_decode()` with no HMAC, cryptographic signature, or nonce verification, and then issuing WordPress authentication cookies after a domain check that is trivially bypassed because both sides of the comparison are attacker-supplied values. This makes it possible for unauthenticated attackers to authenticate as any non-administrator WordPress user, including subscribers, customers, contributors, authors, editors, and shop managers, who owns an order, gaining full session-level access to that account.
CVE-2026-57373 2 Wisetr, Wordpress 2 Funnel Kit Funnel Builder Pro, Wordpress 2026-08-02 6.5 Medium
Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.
CVE-2026-57374 2 Wisetr, Wordpress 2 Funnel Kit Funnel Builder Pro, Wordpress 2026-08-02 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.
CVE-2026-59554 2 Wordpress, Ziina 2 Wordpress, Ziina 2026-08-02 7.5 High
Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
CVE-2026-65477 2 Select-themes, Wordpress 2 Tonda Core, Wordpress 2026-08-02 7.5 High
Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.
CVE-2026-65481 2 Elated-themes, Wordpress 2 Vino, Wordpress 2026-08-02 7.5 High
Contributor Local File Inclusion in Vino <= 1.9 versions.
CVE-2026-65491 2 Jonathan Daggerhart, Wordpress 2 Query Wrangler, Wordpress 2026-08-02 4.3 Medium
Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
CVE-2026-65514 2 Codepeople, Wordpress 2 Appointment Hour Booking, Wordpress 2026-08-02 6.5 Medium
Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
CVE-2026-65518 2 Scott Paterson, Wordpress 2 Accept Donations With Paypal & Stripe, Wordpress 2026-08-02 6.5 Medium
Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.
CVE-2026-15665 2 Wordpress, Wpmanageninja 2 Wordpress, Fluent Support – Helpdesk & Customer Support Ticket System 2026-08-02 6.4 Medium
The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The XSS payload is in a hidden attribute so it only fires in specific browsers when specific access keys are used making exploitation unlikely.
CVE-2026-15739 2 Widgetpack, Wordpress 2 Rich Showcase For Google Reviews, Wordpress 2026-08-02 6.4 Medium
The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and including, 6.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-13605 2 Photoswipe, Wordpress 2 Photoswipe, Wordpress 2026-08-02 6.8 Medium
The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping. Because the title attribute survives the post-content sanitization applied to users who lack the unfiltered_html capability, an authenticated user with Author-level access can store a JavaScript payload that executes in the browser of any visitor, including an administrator, who clicks the link.
CVE-2026-18437 2 Mailerpress, Wordpress 2 Mailerpress – Newsletter, Email Marketing & Ai Automation, Wordpress 2026-08-02 5.3 Medium
The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details.
CVE-2026-11961 2 Wordpress, Wpuserregistration 2 Wordpress, User Registration \& Membership 2026-08-02 8.1 High
The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user role, allowing unauthenticated users to register into an arbitrary published membership tier and obtain its role — up to administrator when such a tier exists.
CVE-2026-11966 2 Wordpress, Wpuserregistration 2 Wordpress, User Registration \& Membership 2026-08-02 5.3 Medium
The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membership payment actions and acts on a caller-supplied user identifier, allowing unauthenticated attackers to delete recently-registered, payment-pending user accounts.
CVE-2026-8825 2 Elementor, Wordpress 2 Elementor Website Builder, Wordpress 2026-08-02 4.9 Medium
The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators).
CVE-2026-7232 2 Formcrafts, Wordpress 2 Formcraft, Wordpress 2026-08-02 7.2 High
The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit chain combines a server-side gap — where composite matrix sub-field keys such as field2_0 and field2_1 are never passed through the sanitization loop and are stored raw via $wpdb->insert() — with a client-side gap where DOMPurify is only invoked when typeof field.value === 'string', but matrix values arrive from the server as arrays, bypassing the check before being mapped to strings and injected into the DOM. Additionally, the same sink is reachable via a second attack vector: array-typed field values are passed through htmlentities() on submission but later reversed by html_entity_decode() at formcraft-main.php:2608 and :2122, restoring the malicious payload before storage and rendering.
CVE-2026-24537 2 Alex Volkov, Wordpress 2 Wp Accessibility Helper, Wordpress 2026-08-02 4.3 Medium
Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.