Export limit exceeded: 14558 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14558 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-12500 | 2 Wordpress, Wptravelengine | 2 Wordpress, Wp Travel Engine | 2026-07-30 | 7.5 High |
| The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before 6.8.2 option (the public nonce that gates the action is served to anonymous visitors). | ||||
| CVE-2026-13145 | 2 Wordpress, Wp Travel | 2 Wordpress, Wp Travel | 2026-07-30 | 4.3 Medium |
| The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address information, by supplying an arbitrary booking identifier. | ||||
| CVE-2026-13143 | 2 Wordpress, Wp Travel | 2 Wordpress, Wp Travel | 2026-07-30 | 5.3 Medium |
| The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips an arbitrary pending booking to a paid and booked state at an attacker-chosen amount. | ||||
| CVE-2026-11867 | 2 Dynamiapps, Wordpress | 2 Frontend Admin, Wordpress | 2026-07-30 | 6.5 Medium |
| The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename, and delete arbitrary taxonomy terms. | ||||
| CVE-2026-1982 | 2 Mohammadr3z, Wordpress | 2 المنتور فارسی, Wordpress | 2026-07-30 | 5.3 Medium |
| The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to the plugin trusting a user-supplied payment amount without server-side validation against the configured ZarinPal widget price. This makes it possible for unauthenticated attackers to submit arbitrary payment amounts to the ZarinPal gateway via the 'amount' parameter. | ||||
| CVE-2026-16610 | 2 Wordpress, Wpase | 2 Wordpress, Admin And Site Enhancements | 2026-07-30 | 9.8 Critical |
| The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no authentication check, CAPTCHA validation is bypassable by omitting an attacker-supplied key, and repeater row keys from cfgroup[input] are stored verbatim and later spliced into an eval() call in recursive_html without any sanitization or identifier validation. This makes it possible for unauthenticated attackers to execute code on the server. This requires the [post_cf_form] shortcode to be present on at least one publicly accessible page, as the nonce and session ID needed to reach the vulnerable save handler are emitted to unauthenticated visitors by that shortcode. | ||||
| CVE-2026-14488 | 2 Metabox, Wordpress | 2 Meta Box, Wordpress | 2026-07-30 | 9.1 Critical |
| The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This is due to the handle_request() function routing the mbfs_delete action without any capability or ownership check, and the nonce verification in check_ajax() being gated behind is_ajax() which is false for template_redirect requests, making it bypassable. This makes it possible for unauthenticated attackers to delete arbitrary posts and pages by supplying an attacker-controlled post ID via the rwmb_frontend_field_object_id GET parameter on any page that hosts a frontend submission form regardless of whether allow_delete is enabled. | ||||
| CVE-2026-11782 | 2 Wordpress, Wpswings | 2 Wordpress, Points And Rewards For Woocommerce | 2026-07-30 | 5.9 Medium |
| The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being changed, allowing unauthenticated attackers to arbitrarily modify or corrupt (including driving it negative) the stored wallet balance and loyalty points of any user. Modifying the wallet balance additionally requires the companion Wallet System for WooCommerce Points and Rewards for WooCommerce WordPress plugin before 2.10.1 to be active. | ||||
| CVE-2026-15382 | 2 Unitecms, Wordpress | 2 Unlimited Addons For Wpbakery Page Builder, Wordpress | 2026-07-30 | 6.5 Medium |
| The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request. | ||||
| CVE-2026-15255 | 2 Registrationmagic, Wordpress | 2 Registrationmagic, Wordpress | 2026-07-30 | 5.3 Medium |
| The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users' form submission data, including personal information. | ||||
| CVE-2026-15257 | 2 Registrationmagic, Wordpress | 2 Registrationmagic, Wordpress | 2026-07-30 | 5.3 Medium |
| The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users' form submissions and the profile fields of the associated non-administrator WordPress accounts. | ||||
| CVE-2026-15252 | 2 Search Atlas Group, Wordpress | 2 Search Atlas Seo, Wordpress | 2026-07-30 | 5.4 Medium |
| The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX handlers, allowing any authenticated user such as a Subscriber to invoke the site's Google Indexing API integration, submitting or removing the site's URLs from Google's index and consuming its indexing quota. | ||||
| CVE-2026-15250 | 2 Appointment Booking Plugin, Wordpress | 2 Appointment Booking Plugin, Wordpress | 2026-07-30 | 5.3 Medium |
| The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and thereby bypass the site's booking approval workflow. | ||||
| CVE-2026-15240 | 2 Customer Switching, Wordpress | 2 Customer Switching, Wordpress | 2026-07-30 | 7.5 High |
| The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowing a lower-privileged account that an operator is currently switched into to be resolved as that operator and to switch into any permitted account, including an administrator, resulting in full account takeover. | ||||
| CVE-2026-14318 | 2 Givewp, Wordpress | 2 Givewp, Wordpress | 2026-07-30 | 6.8 Medium |
| The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an HTML attribute, allowing users with the GiveWP Worker role and above to inject arbitrary web scripts that execute on the public donation form viewed by any visitor. | ||||
| CVE-2026-14231 | 2 Lifterlms, Wordpress | 2 Lifterlms, Wordpress | 2026-07-30 | 4.3 Medium |
| The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX handlers, only verifying that the user is logged in, allowing any authenticated user with subscriber-level access to read the titles of internal post types such as coupon codes by supplying the post type. | ||||
| CVE-2026-14221 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-07-30 | 3.8 Low |
| The Easy Appointments WordPress plugin through 3.12.26 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and delete bookings. | ||||
| CVE-2026-14188 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-07-30 | 2.7 Low |
| The Easy Appointments WordPress plugin through 3.12.26 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information. | ||||
| CVE-2026-14923 | 2 Syncpostwithothersite, Wordpress | 2 Sync Post With Other Site, Wordpress | 2026-07-30 | 6.5 Medium |
| The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the post-editing capability (such as a Contributor) can create, publish, and overwrite arbitrary Pages, including modifying content authored by higher-privileged users. | ||||
| CVE-2026-12687 | 2 Profilegrid, Wordpress | 2 Profilegrid, Wordpress | 2026-07-30 | 7.5 High |
| The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's configured role, up to Administrator when such a group exists, leading to privilege escalation. | ||||