Export limit exceeded: 14471 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14471 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-14488 | 2 Metabox, Wordpress | 2 Meta Box, Wordpress | 2026-07-30 | 9.1 Critical |
| The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This is due to the handle_request() function routing the mbfs_delete action without any capability or ownership check, and the nonce verification in check_ajax() being gated behind is_ajax() which is false for template_redirect requests, making it bypassable. This makes it possible for unauthenticated attackers to delete arbitrary posts and pages by supplying an attacker-controlled post ID via the rwmb_frontend_field_object_id GET parameter on any page that hosts a frontend submission form regardless of whether allow_delete is enabled. | ||||
| CVE-2026-11782 | 2 Wordpress, Wpswings | 2 Wordpress, Points And Rewards For Woocommerce | 2026-07-30 | 5.9 Medium |
| The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being changed, allowing unauthenticated attackers to arbitrarily modify or corrupt (including driving it negative) the stored wallet balance and loyalty points of any user. Modifying the wallet balance additionally requires the companion Wallet System for WooCommerce Points and Rewards for WooCommerce WordPress plugin before 2.10.1 to be active. | ||||
| CVE-2026-15382 | 2 Unitecms, Wordpress | 2 Unlimited Addons For Wpbakery Page Builder, Wordpress | 2026-07-30 | 6.5 Medium |
| The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request. | ||||
| CVE-2026-15252 | 2 Search Atlas Group, Wordpress | 2 Search Atlas Seo, Wordpress | 2026-07-30 | 5.4 Medium |
| The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX handlers, allowing any authenticated user such as a Subscriber to invoke the site's Google Indexing API integration, submitting or removing the site's URLs from Google's index and consuming its indexing quota. | ||||
| CVE-2026-15250 | 2 Appointment Booking Plugin, Wordpress | 2 Appointment Booking Plugin, Wordpress | 2026-07-30 | 5.3 Medium |
| The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and thereby bypass the site's booking approval workflow. | ||||
| CVE-2026-15240 | 2 Customer Switching, Wordpress | 2 Customer Switching, Wordpress | 2026-07-30 | 7.5 High |
| The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowing a lower-privileged account that an operator is currently switched into to be resolved as that operator and to switch into any permitted account, including an administrator, resulting in full account takeover. | ||||
| CVE-2026-14318 | 2 Givewp, Wordpress | 2 Givewp, Wordpress | 2026-07-30 | 6.8 Medium |
| The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an HTML attribute, allowing users with the GiveWP Worker role and above to inject arbitrary web scripts that execute on the public donation form viewed by any visitor. | ||||
| CVE-2026-14231 | 2 Lifterlms, Wordpress | 2 Lifterlms, Wordpress | 2026-07-30 | 4.3 Medium |
| The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX handlers, only verifying that the user is logged in, allowing any authenticated user with subscriber-level access to read the titles of internal post types such as coupon codes by supplying the post type. | ||||
| CVE-2026-14221 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-07-30 | 3.8 Low |
| The Easy Appointments WordPress plugin through 3.12.26 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and delete bookings. | ||||
| CVE-2026-14188 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-07-30 | 2.7 Low |
| The Easy Appointments WordPress plugin through 3.12.26 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information. | ||||
| CVE-2026-14923 | 2 Syncpostwithothersite, Wordpress | 2 Sync Post With Other Site, Wordpress | 2026-07-30 | 6.5 Medium |
| The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the post-editing capability (such as a Contributor) can create, publish, and overwrite arbitrary Pages, including modifying content authored by higher-privileged users. | ||||
| CVE-2026-12687 | 2 Profilegrid, Wordpress | 2 Profilegrid, Wordpress | 2026-07-30 | 7.5 High |
| The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's configured role, up to Administrator when such a group exists, leading to privilege escalation. | ||||
| CVE-2026-16092 | 2 Labelblanc, Wordpress | 2 Improved Save Button, Wordpress | 2026-07-30 | 6.5 Medium |
| The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field via 'Save and Duplicate' Action in all versions up to, and including, 1.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-1982 | 2 Mohammadr3z, Wordpress | 2 المنتور فارسی, Wordpress | 2026-07-30 | 5.3 Medium |
| The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to the plugin trusting a user-supplied payment amount without server-side validation against the configured ZarinPal widget price. This makes it possible for unauthenticated attackers to submit arbitrary payment amounts to the ZarinPal gateway via the 'amount' parameter. | ||||
| CVE-2026-14356 | 2 Fleekdash, Wordpress | 2 Fleekdash V2, Wordpress | 2026-07-30 | 8.8 High |
| The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the email address and password of any WordPress user, including administrators, enabling full account takeover and complete site compromise. The public /wp-json/fleekdash/v1/register endpoint auto-provisions a Subscriber-role account and returns a valid REST nonce regardless of the site's users_can_register setting, enabling unauthenticated attackers to self-provision the required credentials and nonce in a single prior request. | ||||
| CVE-2026-1360 | 2 Buddypress, Wordpress | 2 Buddypress, Wordpress | 2026-07-30 | 7.5 High |
| The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary PHP objects via XProfile textbox fields, which could lead to remote code execution if a suitable POP chain is available in the WordPress environment. | ||||
| CVE-2026-14592 | 2 Hitoy, Wordpress | 2 Wp Real Ip-based Access Control, Wordpress | 2026-07-30 | 6.1 Medium |
| The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks before storing one of its option values, and does not escape that value on output on its settings page, allowing unauthenticated users to store arbitrary JavaScript that executes in the context of any administrator who views the page. | ||||
| CVE-2026-14602 | 2 Thorsten Ott, Wordpress | 2 Remote Api, Wordpress | 2026-07-30 | N/A |
| The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget chain is present through another installed Remote API WordPress plugin through 0.2. | ||||
| CVE-2026-15054 | 2 Bit Form, Wordpress | 2 Bit Form, Wordpress | 2026-07-30 | N/A |
| The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries to, and fire the configured workflows (such as email notifications) of forms the site owner has deactivated or unpublished. | ||||
| CVE-2026-15235 | 2 Motopress Hotel Booking, Wordpress | 2 Motopress Hotel Booking, Wordpress | 2026-07-30 | N/A |
| The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking's full customer details in one of its AJAX actions, allowing any authenticated user with a low-privileged account (Subscriber and above) to read the personal data, including name, email, phone, and address, of any customer. | ||||