Search Results (15551 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-16149 2 Marc4, Wordpress 2 Security Hardener, Wordpress 2026-08-24 8.8 High
The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled by default, hooks the rest_endpoints filter via secure_user_endpoints() and overwrites every registered handler's permission_callback on both the /wp/v2/users and /wp/v2/users/(?P<id>[\d]+) routes — including POST, PUT, PATCH, and DELETE handlers — with a bare closure that returns only is_user_logged_in(), completely stripping WordPress Core's original capability checks such as create_users, promote_user, edit_users, and delete_users that WP_REST_Users_Controller normally enforces. This makes it possible for authenticated attackers with Subscriber-level access and above to create new Administrator accounts by sending POST request to /wp/v2/users with administrator role, or to reset an existing Administrator's password by issuing a PUT/POST request to /wp/v2/users/<id>. Because the block_user_enum option defaults to enabled, no special plugin configuration is required — the overwrite is active on every request as soon as the plugin is installed.
CVE-2026-28152 2 Select-themes, Wordpress 2 Tonda Core, Wordpress 2026-08-24 8.1 High
Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.
CVE-2026-74019 2 Paulepro2019, Wordpress 2 Eprolo Dropshipping, Wordpress 2026-08-24 7.1 High
Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions.
CVE-2026-66607 2 Themehunk, Wordpress 2 Advance Product Search, Wordpress 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions.
CVE-2026-4703 2 Westguard, Wordpress 2 Ws Form Lite – Drag & Drop Contact Form Builder, Wordpress 2026-08-24 9.8 Critical
The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
CVE-2026-28165 2 Unitedover, Wordpress 2 Digits, Wordpress 2026-08-24 9.8 Critical
Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
CVE-2026-28166 2 Goodlayers, Wordpress 2 Tour Master, Wordpress 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.
CVE-2026-66610 2 Thembay, Wordpress 2 Urna, Wordpress 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.
CVE-2026-28162 2 Franky, Wordpress 2 Events Made Easy, Wordpress 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.
CVE-2026-28167 2 Super-forms, Wordpress 2 Super Forms, Wordpress 2026-08-24 7.5 High
Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.
CVE-2026-78291 2 Webful Creations, Wordpress 2 Repairbuddy, Wordpress 2026-08-24 5.3 Medium
Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.
CVE-2026-78290 2 Themegrill, Wordpress 2 Magazine Blocks, Wordpress 2026-08-24 6.5 Medium
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.
CVE-2026-78280 2 Hashthemes, Wordpress 2 Hash Form, Wordpress 2026-08-24 4.3 Medium
Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.
CVE-2026-66623 2 Inisev, Wordpress 2 Social Media & Share Icons, Wordpress 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.
CVE-2026-78269 2 Tammersoft, Wordpress 2 Shared Files, Wordpress 2026-08-24 6.4 Medium
Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.
CVE-2026-19883 2 Etruel, Wordpress 2 Wpematico Rss Feed Fetcher, Wordpress 2026-08-24 8.8 High
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and including, 2.8.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access.
CVE-2026-76057 2 Rubengc, Wordpress 2 Automatorwp – Automator Plugin For No-code Automations, Webhooks & Custom Integrations In Wordpress, Wordpress 2026-08-24 4.3 Medium
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve all ConvertKit form data configured by the site's manager account, exposing integration details intended to be restricted to plugin managers. The required nonce is localized on every admin page load, making it accessible to any authenticated user who can reach /wp-admin.
CVE-2026-76074 2 Rubengc, Wordpress 2 Automatorwp – Automator Plugin For No-code Automations, Webhooks & Custom Integrations In Wordpress, Wordpress 2026-08-24 4.3 Medium
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve the site's configured Campaign Monitor mailing list catalog, including all list IDs and names, that should be restricted to users with the plugin's manager capability. The required nonce is emitted unconditionally on every WordPress admin page via wp_localize_script, meaning any subscriber visiting /wp-admin/profile.php can obtain it without any elevated access.
CVE-2026-4244 2 Metaphorcreations, Wordpress 2 Post Duplicator, Wordpress 2026-08-24 4.3 Medium
The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `duplicate_post()` function in all versions up to, and including, 3.0.11. This is due to the function not verifying that the user has `edit_others_posts` capability before accepting a `selectedAuthorId` parameter via the `duplicate-post` REST endpoint. This makes it possible for authenticated attackers, with Contributor-level access and above, to create duplicated posts attributed to any user, including administrators.
CVE-2026-2996 2 Maartenbelmans, Wordpress 2 Advanced Product Fields Product Addons For Woocommerce, Wordpress 2026-08-24 7.5 High
The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid addons and complete purchases at the base product price only, effectively stealing products by paying a fraction of the intended total. The vulnerability was partially patched in version 1.6.19.