Search Results (15949 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-84812 2 Wordplus, Wordpress 2 Better Messages, Wordpress 2026-09-07 7.1 High
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.
CVE-2026-85303 2 Magepeople, Wordpress 2 Booking & Rental Manager, Wordpress 2026-09-07 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking and Rental Manager: from n/a through 2.7.7.
CVE-2026-15984 2 Themovation, Wordpress 2 Quickcal, Wordpress 2026-09-07 7.2 High
The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and including, 1.0.20 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce guarding the unauthenticated booked_add_appt AJAX action is publicly embedded on any page rendering the booking calendar shortcode, making it trivially obtainable by unauthenticated attackers without any prior account or privilege.
CVE-2025-15693 2 Jch Optimize Project, Wordpress 2 Jch Optimize, Wordpress 2026-09-07 2.7 Low
The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and sub-site administrators on multisite, to enumerate directories and file names outside the web root.
CVE-2025-15694 2 Wordpress, Wpjoli 2 Wordpress, Joli Table Of Contents 2026-09-07 3.5 Low
The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed, for example in a multisite setup.
CVE-2026-15247 2 Search Atlas Group, Wordpress 2 Search Atlas Seo, Wordpress 2026-09-07 5.4 Medium
The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials.
CVE-2026-19858 2 Jetmonsters, Wordpress 2 Jetformbuilder — Dynamic Blocks Form Builder, Wordpress 2026-09-07 7.5 High
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft content, and secrets other JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 store in metadata.
CVE-2026-82846 2 Masteriyo, Wordpress 2 Masteriyo, Wordpress 2026-09-07 6.8 Medium
The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of anyone viewing the course, including a logged-in administrator.
CVE-2026-84745 2 Theeventscalendar, Wordpress 2 The Events Calendar, Wordpress 2026-09-07 2.7 Low
The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with a low-privilege role such as contributor to read the full contents of every unpublished record on the site, including other users'.
CVE-2026-84931 2 Wordpress, Wpjoli 2 Wordpress, Joli Table Of Contents 2026-09-07 6.8 Medium
The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, allowing users with the Author role and above to inject arbitrary HTML attributes and JavaScript that execute in the browser of any user who views the post, including higher-privileged users such as administrators. This crosses a privilege boundary even on multisite, where such users are not permitted to post unfiltered HTML.
CVE-2026-84934 2 Jch Optimize Project, Wordpress 2 Jch Optimize, Wordpress 2026-09-07 8 High
The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 settings and store a script that executes in the browser of any visitor or administrator viewing the site.
CVE-2026-84901 2 Eventin, Wordpress 2 Eventin, Wordpress 2026-09-06 4.9 Medium
The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage.
CVE-2026-82304 2 Musicstore, Wordpress 2 Music Store, Wordpress 2026-09-06 8.6 High
The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
CVE-2026-80439 2 Redirection-for-contact-form7, Wordpress 2 Redirection For Contact Form 7, Wordpress 2026-09-06 4.8 Medium
The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticated users to run any shortcode registered on the site and read its output.
CVE-2026-80437 2 Ninjaforms, Wordpress 2 Ninja Forms, Wordpress 2026-09-06 4.8 Medium
The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.
CVE-2026-18480 2 Surecart, Wordpress 2 Surecart, Wordpress 2026-09-06 8.8 High
The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password reset. It further allows an attacker-controlled customer record to be associated with an arbitrary user, and discloses customer identifiers and email addresses to any authenticated user, which together make the takeover reachable from a subscriber-level account alone.
CVE-2026-84898 2 Eventin, Wordpress 2 Eventin, Wordpress 2026-09-06 6.6 Medium
The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute arbitrary local PHP files.
CVE-2026-84225 2 Kirki, Wordpress 2 Kirki, Wordpress 2026-09-06 2.2 Low
The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open.
CVE-2026-84221 2 Kirki, Wordpress 2 Kirki, Wordpress 2026-09-06 6.8 Medium
The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read the contents of the database, including user credentials.
CVE-2026-84219 2 Kirki, Wordpress 2 Kirki, Wordpress 2026-09-06 7.5 High
The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an administrator, and on every page of the site when its header or footer is built to show comments.