Search

Search Results (404423 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-93941 2 Themerex Group, Wordpress-extensions 2 Edema, Edema 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.
CVE-2026-93940 2 Themerex Group, Wordpress-extensions 2 Greeny, Greeny 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.
CVE-2026-93938 2 Themerex Group, Wordpress-extensions 2 Hogwords, Hogwords 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.
CVE-2026-93937 2 Themerex Group, Wordpress-extensions 2 Hygia, Hygia 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0.
CVE-2026-93936 2 Themerex Group, Wordpress-extensions 2 Ipharm, Ipharm 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4.
CVE-2026-93935 2 Themerex Group, Wordpress-extensions 2 Let's Play, Let's Play 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play playhockey allows Object Injection.This issue affects Let's Play: from n/a through 1.1.15.
CVE-2026-93934 2 Themerex Group, Wordpress-extensions 2 Partiso, Partiso 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Partiso partiso allows Object Injection.This issue affects Partiso: from n/a through 1.1.13.
CVE-2026-93933 2 Themerex Group, Wordpress-extensions 2 Rosalinda, Rosalinda 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Rosalinda rosalinda allows Object Injection.This issue affects Rosalinda: from n/a through 1.2.4.
CVE-2026-93932 2 Themerex Group, Wordpress-extensions 2 Smart Casa, Smart Casa 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Smart Casa smart-casa allows Object Injection.This issue affects Smart Casa: from n/a through 1.0.12.
CVE-2026-93931 2 Themerex Group, Wordpress-extensions 2 Smash, Smash 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Smash smash allows Object Injection.This issue affects Smash: from n/a through 1.12.0.
CVE-2026-93930 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Tantra tantra allows Object Injection.This issue affects Tantra: from n/a through 2.9.0.
CVE-2026-93929 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Travesia travesia allows Object Injection.This issue affects Travesia: from n/a through 1.1.16.
CVE-2026-93927 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in Axiomthemes Veto veto allows Object Injection.This issue affects Veto: from n/a through 1.6.0.
CVE-2026-93883 2026-10-11 6.4 Medium
The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone' parameter in all versions up to, and including, 3.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable on sites where the 'Force Bootstrap' miscellaneous setting (acadp_misc_settings['force_bootstrap']) is enabled and the 'ACADP Listing Address' widget is placed on a sidebar displayed on single listing pages; both conditions are non-default.
CVE-2026-93775 2026-10-11 7.2 High
The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Auphonic Webhook in all versions up to, and including, 4.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injection is triggered by submitting a request to the Auphonic webhook endpoint with any POST body where the status_string field is not the literal string 'Done', causing the full raw POST superglobal to be stored in the plugin log before any authentication key validation is performed.
CVE-2026-91862 2026-10-11 6.4 Medium
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-image-points' parameter in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-89100 2026-10-11 6.1 Medium
The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '#response' URL Fragment in all versions up to, and including, 4.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that the 'Generic Errors' setting is unchecked, causing getErrorMessage() to return the raw Stripe error string unchanged rather than substituting a mapped safe message.
CVE-2026-87869 2026-10-11 6.1 Medium
The Filter Everything — WordPress & WooCommerce Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9.6. This is due to insufficient input sanitization and output escaping in the flrt_elementor_load_more_anchor() function. The function reads query parameters from $_SERVER['REQUEST_URI'] via getFormActionOrFullPageUrl(true), which URL-decodes them through parse_str() and re-assembles them using build_query() — a WordPress core function that does NOT re-encode values ($urlencode=false). The resulting URL, containing unescaped special characters, is injected into a data-next-page HTML attribute via preg_replace() without esc_attr() or esc_url(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.
CVE-2026-78530 2026-10-11 7.7 High
Subscriber Arbitrary File Deletion in FoodBakery <= 4.6 versions.
CVE-2026-78068 2026-10-11 6.4 Medium
The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell Content in all versions up to, and including, 1.3.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.