Export limit exceeded: 15553 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15553 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73347 | 2 Themetechmount, Wordpress | 2 Truebooker, Wordpress | 2026-08-20 | 9.8 Critical |
| Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions. | ||||
| CVE-2026-73185 | 2 Wordpress, Wpo-hr | 2 Wordpress, Ngg Smart Image Search | 2026-08-20 | 9.3 Critical |
| Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions. | ||||
| CVE-2026-66680 | 2 Plainwaire, Wordpress | 2 Locatoraid Store Locator, Wordpress | 2026-08-20 | 9.3 Critical |
| Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions. | ||||
| CVE-2026-66668 | 2 Peepso, Wordpress | 2 Community By Peepso, Wordpress | 2026-08-20 | 8.5 High |
| Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions. | ||||
| CVE-2026-66604 | 2 Paolo, Wordpress | 2 Geodirectory, Wordpress | 2026-08-20 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions. | ||||
| CVE-2026-66595 | 2 Passionate Programmer Peter, Wordpress | 2 Wp Data Access, Wordpress | 2026-08-20 | 5.9 Medium |
| Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions. | ||||
| CVE-2026-17153 | 2 Siteground, Wordpress | 2 Ai Agent By Siteground, Wordpress | 2026-08-20 | 5.3 Medium |
| The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to upload images to the WordPress media library, bypassing the upload_files capability restriction that Contributors are normally subject to, as authenticated attackers with Contributor-level access or above can satisfy the endpoint's nonce and permission checks. The sg_ai_studio_gutenberg_nonce required by the endpoint is emitted to any user with block editor access — including Contributors — making the absent upload_files check the sole barrier to exploitation. | ||||
| CVE-2026-66601 | 2 Davidlingren, Wordpress | 2 Media Library Assistant, Wordpress | 2026-08-20 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions. | ||||
| CVE-2026-73402 | 2 Hakan Ozevin, Wordpress | 2 Wp Base Booking, Wordpress | 2026-08-20 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions. | ||||
| CVE-2026-66612 | 2 Thembay, Wordpress | 2 Aora, Wordpress | 2026-08-20 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions. | ||||
| CVE-2025-15689 | 2 Themegoods, Wordpress | 2 Capella, Wordpress | 2026-08-20 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. | ||||
| CVE-2025-53999 | 2 Themegoods, Wordpress | 2 Altair, Wordpress | 2026-08-20 | 6.5 Medium |
| Unauthenticated Broken Access Control in Altair <= 5.2.2 versions. | ||||
| CVE-2026-66592 | 2 Rtcamp, Wordpress | 2 Rtmedia For Wordpress, Buddypress And Bbpress, Wordpress | 2026-08-20 | 9.3 Critical |
| Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. | ||||
| CVE-2026-18778 | 2 Truebooker, Wordpress | 2 Truebooker, Wordpress | 2026-08-20 | 5.3 Medium |
| The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to retrieve the personal information of customers who booked an appointment, including their name, email address, phone number and postal address. | ||||
| CVE-2026-28164 | 2 Hashthemes, Wordpress | 2 Easy Elementor Addons, Wordpress | 2026-08-20 | 9.6 Critical |
| Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7. | ||||
| CVE-2026-74992 | 2 Kirki, Wordpress | 2 Kirki, Wordpress | 2026-08-20 | 6.8 Medium |
| The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not remove all unwanted files after extracting them, allowing such users to upload arbitrary files to a web accessible directory, leading to Stored XSS as well as RCE on some server configurations. | ||||
| CVE-2026-75963 | 2 Liedekef, Wordpress | 2 Events Made Easy, Wordpress | 2026-08-20 | 7.5 High |
| The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal payload is triggered passively when any visitor loads the affected single-event page, meaning post-submission execution does not require additional attacker interaction. | ||||
| CVE-2026-11565 | 2 Advancedfilemanager, Wordpress | 2 Advanced File Manager, Wordpress | 2026-08-20 | 8.5 High |
| The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server — including sensitive configuration files — and to overwrite existing non-PHP files, which can be leveraged to compromise administrator accounts and the whole site. | ||||
| CVE-2026-73184 | 2 Lcweb, Wordpress | 2 Global Gallery, Wordpress | 2026-08-19 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions. | ||||
| CVE-2026-66596 | 2 Stefanno Lissa, Wordpress | 2 Newsletter, Wordpress | 2026-08-19 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions. | ||||