Search

Search Results (374312 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-63823 2026-08-06 9.8 Critical
My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values.
CVE-2026-14313 2026-08-06 5.3 Medium
PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is vulnerable to unauthenticated missing-authorization / IDOR write. Requires WooCommerce.
CVE-2026-14314 2026-08-06 5.3 Medium
The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated attackers to forge a token and disclose image attachments, including other customers' uploaded payment receipts, that they do not own.
CVE-2026-14240 2 Tourmaster, Wordpress 2 Tourmaster, Wordpress 2026-08-06 5.3 Medium
The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its publicly accessible directory with no access control, allowing unauthenticated users to download the exported customers' personal information once an administrator has run an export.
CVE-2026-16290 2 Profilegrid, Wordpress 2 Profilegrid, Wordpress 2026-08-06 5.3 Medium
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin before 6.0.0.0's member-visibility setting.
CVE-2026-18050 2026-08-06 7.5 High
The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The identifier is high-entropy, is disclosed only to the uploader, and the file is removed on submission or by a scheduled cleanup, so a cross-user read is not achievable by guessing alone.
CVE-2026-61961 2 Wordpress, Wpdeveloper 2 Wordpress, Embedpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
CVE-2026-66708 2 Boldgrid, Wordpress 2 Total Upkeep, Wordpress 2026-08-06 8.2 High
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
CVE-2026-66709 2 Webappick, Wordpress 2 Ctx Feed, Wordpress 2026-08-06 9.1 Critical
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
CVE-2026-66710 2 E2pdf, Wordpress 2 E2pdf, Wordpress 2026-08-06 8.1 High
Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.
CVE-2026-28178 2 Codesupplyco, Wordpress 2 Powerkit, Wordpress 2026-08-06 6.5 Medium
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
CVE-2026-32548 2 Surecart, Wordpress 2 Surecart, Wordpress 2026-08-06 5.3 Medium
Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
CVE-2026-61982 2 Jp-secure, Wordpress 2 Siteguard Wp Plugin, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
CVE-2026-65509 2 Wordpress, Wpdatatables 2 Wordpress, Wpdatatables 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
CVE-2026-65502 2 Bdthemes, Wordpress 2 Element Pack Elementor Addons, Wordpress 2026-08-06 5.3 Medium
Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
CVE-2026-65573 2 Themerex, Wordpress 2 Abelle, Wordpress 2026-08-06 9.8 Critical
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
CVE-2026-66439 2 Berocket, Wordpress 2 Advanced Ajax Product Filters, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.
CVE-2026-65545 2 Jordy Meow, Wordpress 2 Ai-engine, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.
CVE-2026-65560 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.
CVE-2026-65577 2026-08-06 9.8 Critical
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.