Export limit exceeded: 15552 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15552 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73392 | 2 Highwarden, Wordpress | 2 Super Store Finder, Wordpress | 2026-08-21 | 9.3 Critical |
| Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions. | ||||
| CVE-2026-73397 | 2 Wordpress, Youzify | 2 Wordpress, Youzify | 2026-08-21 | 9.8 Critical |
| Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. | ||||
| CVE-2026-73399 | 2 Flutterwave, Wordpress | 2 Flutterwave Woocommerce, Wordpress | 2026-08-21 | 6.5 Medium |
| Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. | ||||
| CVE-2026-73994 | 2 Syed Balkhi, Wordpress | 2 Charitable, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. | ||||
| CVE-2026-73997 | 2 Nexcess, Wordpress | 2 Starter Templates By Kadence Wp, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. | ||||
| CVE-2026-74015 | 2 Merkulove, Wordpress | 2 Readabler, Wordpress | 2026-08-21 | 9.3 Critical |
| Unauthenticated SQL Injection in Readabler < 2.0.18 versions. | ||||
| CVE-2026-66602 | 2 Devitems, Wordpress | 2 Hashbar – Wordpress Notification Bar, Wordpress | 2026-08-21 | 8.8 High |
| Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0. | ||||
| CVE-2026-15421 | 2 Siteground, Wordpress | 2 Speed Optimizer – The All-in-one Performance-boosting Plugin, Wordpress | 2026-08-21 | 6.4 Medium |
| The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Image Tag Attributes in all versions up to, and including, 7.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the site administrator has enabled the Lazy Load Media option in the plugin settings. | ||||
| CVE-2026-19942 | 2 Wordpress, Wpfeedback | 2 Wordpress, Atarim – Ai Agency For Wordpress: Edit Pages, Fix Code, Update Plugins, Seo & Client Feedback | 2026-08-21 | 8.1 High |
| The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the AVCF_Abilities_Media::register (replace-media-file execute_callback) function in all versions up to, and including, 5.1.1. This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). This is exploitable by first using the atarim/update-post-field ability to overwrite the _wp_attached_file meta of an attacker-owned attachment with a directory-traversal path, then invoking atarim/replace-media-file to cause get_attached_file() to resolve and unlink the targeted file. | ||||
| CVE-2026-15446 | 2 Nosilver4u, Wordpress | 2 Ewww Image Optimizer, Wordpress | 2026-08-21 | 6.4 Medium |
| The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit is achieved by embedding a crafted img element with class='lazyload' and a data-script attribute pointing to an attacker-controlled URL in post content, which the plugin's bundled lazysizes ls.unveilhooks addon then uses to dynamically create and insert a script element into the DOM at page view time. | ||||
| CVE-2026-73394 | 2 Stitchexpress, Wordpress | 2 Stitch Express, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions. | ||||
| CVE-2026-32552 | 2 Wordpress, Yith | 2 Wordpress, Yith Woocommerce Membership Premium | 2026-08-21 | 8.5 High |
| Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions. | ||||
| CVE-2026-73182 | 2 Jeff Starr, Wordpress | 2 Bbq Pro, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions. | ||||
| CVE-2026-73183 | 2 Get Maps Marker Pro, Wordpress | 2 Maps Marker Pro, Wordpress | 2026-08-21 | 9.3 Critical |
| Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. | ||||
| CVE-2026-73354 | 2 Reichertbrothers, Wordpress | 2 Simplyrets Real Estate Idx, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions. | ||||
| CVE-2026-73364 | 2 Wordpress, Wpdesk | 2 Wordpress, Flexible Subscriptions | 2026-08-21 | 9.8 Critical |
| Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. | ||||
| CVE-2026-73384 | 2 Cmsminds, Wordpress | 2 Pay With Contact Form 7, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions. | ||||
| CVE-2026-73385 | 2 Outanking Team, Wordpress | 2 Outranking Plugin Options, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions. | ||||
| CVE-2026-73387 | 2 Smartdatasoft, Wordpress | 2 Resido, Wordpress | 2026-08-21 | 8.1 High |
| Unauthenticated Local File Inclusion in Resido <= 1.5 versions. | ||||
| CVE-2026-73389 | 2 The4, Wordpress | 2 Kalles Addons, Wordpress | 2026-08-21 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. | ||||