Search Results (16296 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-71895 1 Apache 1 Dolphinscheduler 2026-10-08 N/A
An authorization vulnerability in Apache DolphinScheduler allows authenticated non-admin users to retrieve Kubernetes configuration data intended for administrator-managed cluster configuration. The exposed kubeconfig data contains credentials that may allow users to authenticate directly to the Kubernetes API outside DolphinScheduler. The impact depends on the permissions granted to the disclosed credentials. If the kubeconfig provides cluster-admin or broadly privileged service-account access, an attacker may read Kubernetes Secrets, create pods, and establish persistent access to the cluster. This issue affects Apache DolphinScheduler: from 3.2.0 before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
CVE-2026-103517 2026-10-08 5.3 Medium
The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated attackers to forge one and mark orders as paid without paying.
CVE-2026-104671 2026-10-08 5.3 Medium
The TutorStarter WordPress theme before 4.0.4 does not respect the site's user registration setting in one of its AJAX registration handlers, allowing unauthenticated visitors to create WordPress user accounts even when user registration is disabled.
CVE-2026-105190 2026-10-08 5.3 Medium
The Easy Digital Downloads WordPress plugin before 3.7.1 does not consult the site's user registration setting before creating a WordPress account, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled. The created account receives the site's default role.
CVE-2026-94275 2026-10-08 5.3 Medium
The Track Orders for WooCommerce WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing unauthenticated attackers to obtain a customer's name, email address, phone number, postal address and order history by supplying that customer's email address.
CVE-2026-94258 2026-10-08 2.7 Low
The SMS Alert WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning their stored billing phone numbers, allowing an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network. This affects multisite only, and requires the SMS Alert WordPress plugin before 4.0.1's gateway credentials to be stored on the acting administrator's own site.
CVE-2026-94246 2026-10-08 6.3 Medium
The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the wallet account named in a withdrawal submission belongs to the user making it, allowing any authenticated user, such as a subscriber, to file a withdrawal request against another user's wallet for an amount and a payout destination of their choosing, and to indefinitely prevent that user from submitting withdrawals of their own.
CVE-2026-94245 2026-10-08 6.5 Medium
The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the user submitting a wallet transfer owns the wallet being debited, allowing any authenticated user, including one with only the Subscriber role, to move an arbitrary user's wallet balance, including an administrator's, into an account they control.
CVE-2026-94244 2026-10-08 4.3 Medium
The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not perform any capability check, and relies on a token any authenticated user can obtain from a front-end page, before generating a report containing every customer's wallet transaction history, allowing any authenticated user, such as a subscriber, to disclose all users' names, email addresses, roles, transaction amounts, payment methods and dates.
CVE-2026-86827 2026-10-08 5.3 Medium
The BackWPup WordPress plugin before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress's internal scheduled-event dispatch, allowing unauthenticated attackers to force any existing backup job to run immediately, independent of its configured trigger type or schedule.
CVE-2026-105260 2026-10-08 4.3 Medium
The Database Addon For WPForms ( wpforms entries ) WordPress plugin before 1.1.1 does not verify the CSRF nonce when the field is omitted and performs no capability check of its own, allowing attackers to delete arbitrary stored form entries by tricking a logged-in administrator into loading a crafted page.
CVE-2026-105197 2026-10-08 2.7 Low
The Appointment Booking Plugin WordPress plugin before 5.6.5 does not verify that a backend staff user is authorized to act on the specific record targeted for deletion, allowing an authenticated user with a record-scoped staff role to irreversibly delete any order, customer, or transaction on the site, including records belonging to other staff and outside their assigned scope.
CVE-2026-105196 2026-10-08 3.3 Low
The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, allowing an authenticated user holding the LatePoint Agent role, normally restricted to their own records, to read and modify other agents' profile data and read other agents' bookings and associated customer details when the Abilities API feature is enabled.
CVE-2026-105195 2026-10-08 2.7 Low
The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.
CVE-2026-105194 2026-10-08 4.3 Medium
The Easy Digital Downloads WordPress plugin before 3.7.1 does not restrict a block's order data to the current user, allowing users with subscriber-level access to view other customers' recent order products and obtain signed download links that grant access to paid digital files without purchase.
CVE-2026-103646 2026-10-08 9.8 Critical
The Ultimate Multisite WordPress plugin before 2.17.0 does not require authentication before a logged-out checkout is linked to, and logged in as, an existing WordPress account matching the submitted email address, and its duplicate-account check normalizes that address differently from the lookup used to create the customer, so an unauthenticated attacker can log in as any existing user, including a Network Super Admin, whose email address they know. This bypass is not addressed by the 2.15.1 fix for CVE-2026-75957 and remains exploitable in all versions up to and including 2.16.1, the releases that fix was expected to cover. Exploitation requires a checkout form configured without a password field (auto-generated password) and a target account that has no existing customer record in the Ultimate Multisite WordPress plugin before 2.17.0.
CVE-2026-103309 2026-10-08 7.5 High
The GPTranslate WordPress plugin before 2.34.14 does not properly restrict who can store translations, and does not escape them when outputting them in translated pages, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks when server-side translations are enabled.
CVE-2026-94585 1 Brocade 1 Fabric Os 2026-10-08 N/A
An authentication bypass vulnerability exists in the web management interface of Brocade Fabric OS versions before 9.2.2d running on the MXG610 platform. An unauthenticated, network-adjacent attacker can exploit an unauthenticated endpoint within the Single Sign-On (SSO) workflow to gain administrative access to the device management interface.
CVE-2026-105611 1 Chillzhuang 1 Springblade 2026-10-08 2.7 Low
A vulnerability was determined in chillzhuang SpringBlade up to 5.0.1. This affects an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/RoleController.java of the component User Detail Endpoint. This manipulation of the argument ID causes improper authorization. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-105571 2 Pickmall, Pickmall Lilishop 2 Lilishop, Pickmall Lilishop 2026-10-08 7.3 High
A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.