Search

Search Results (398654 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-84069 1 Wordpress-extensions 1 Webfacing 2026-09-28 5.3 Medium
The WebFacing™ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate a user-supplied path before using it to include a local file, allowing unauthenticated users to perform Local File Inclusion.
CVE-2026-81655 1 Wordpress-extensions 1 Ad Inserter 2026-09-28 7.5 High
The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making it reachable by every logged in user under a configuration its own settings allow, and does not filter the content saved there, allowing users with a role as low as subscriber to store code which is then executed as PHP or served unescaped to site visitors.
CVE-2026-82841 1 Wordpress-extensions 1 Updraftplus 2026-09-28 5.3 Medium
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration state, allowing any authenticated user, such as a subscriber, to retrieve the credentials of the configured backup destinations, such as passwords and secret keys.
CVE-2026-85002 1 Wordpress-extensions 1 Embedpress 2026-09-28 6.8 Medium
The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post.
CVE-2026-86609 1 Wordpress-extensions 1 Download Manager Pro 2026-09-28 8.8 High
The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature.
CVE-2026-86839 1 Wordpress-extensions 1 Bookly 2026-09-28 3.8 Low
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information.
CVE-2026-86841 1 Wordpress-extensions 1 Bookly 2026-09-28 4.7 Medium
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly assign, to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets.
CVE-2026-89000 1 Wordpress-extensions 1 Wpematico Rss Feed Fetcher 2026-09-28 4.1 Medium
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to internal-only resources and read the responses back.
CVE-2026-89001 1 Wordpress-extensions 1 Wpematico Rss Feed Fetcher 2026-09-28 4.9 Medium
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing users with contributor-level access and above to publish posts live and set any registered user, including an administrator, as the post author.
CVE-2026-89003 1 Wordpress-extensions 1 Wpematico Rss Feed Fetcher 2026-09-28 4.1 Medium
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses back.
CVE-2026-89006 1 Wordpress-extensions 1 Wpematico Rss Feed Fetcher 2026-09-28 6.8 Medium
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2026-92436 1 Wordpress-extensions 1 Mailchimp For Woocommerce 2026-09-28 5.3 Medium
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents.
CVE-2026-92995 1 Wordpress-extensions 1 Verge3d 2026-09-28 5.3 Medium
The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization.
CVE-2026-96895 1 Wordpress-extensions 1 Wp Youtube Lyte 2026-09-28 6.8 Medium
The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
CVE-2026-96896 1 Wordpress-extensions 1 Malcure Malware Shield 2026-09-28 7.2 High
The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.
CVE-2026-96897 1 Wordpress-extensions 1 Optima Express Idx 2026-09-28 5.3 Medium
The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that is available to logged-out users, allowing unauthenticated attackers to force the creation of a fixed author-role account and to repeatedly rotate its application password on any connected install.
CVE-2026-96899 1 Wordpress-extensions 1 Optima Express Idx 2026-09-28 6.8 Medium
The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it and echoing it into the document head when the post is rendered, allowing users with a role as low as author to perform Stored Cross-Site Scripting attacks.
CVE-2026-97227 2026-09-28 5.9 Medium
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials, delete arbitrary posts and reset the NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8's configuration.
CVE-2026-97319 1 Wordpress-extensions 1 Powerpress 2026-09-28 6.8 Medium
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2026-100893 1 Privoce 1 Vocechat Server 2026-09-28 7.3 High
A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.