Export limit exceeded: 15553 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (15553 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-73347 2 Themetechmount, Wordpress 2 Truebooker, Wordpress 2026-08-20 9.8 Critical
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.
CVE-2026-73185 2 Wordpress, Wpo-hr 2 Wordpress, Ngg Smart Image Search 2026-08-20 9.3 Critical
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
CVE-2026-66680 2 Plainwaire, Wordpress 2 Locatoraid Store Locator, Wordpress 2026-08-20 9.3 Critical
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
CVE-2026-66668 2 Peepso, Wordpress 2 Community By Peepso, Wordpress 2026-08-20 8.5 High
Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.
CVE-2026-66604 2 Paolo, Wordpress 2 Geodirectory, Wordpress 2026-08-20 7.1 High
Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.
CVE-2026-66595 2 Passionate Programmer Peter, Wordpress 2 Wp Data Access, Wordpress 2026-08-20 5.9 Medium
Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.
CVE-2026-17153 2 Siteground, Wordpress 2 Ai Agent By Siteground, Wordpress 2026-08-20 5.3 Medium
The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to upload images to the WordPress media library, bypassing the upload_files capability restriction that Contributors are normally subject to, as authenticated attackers with Contributor-level access or above can satisfy the endpoint's nonce and permission checks. The sg_ai_studio_gutenberg_nonce required by the endpoint is emitted to any user with block editor access — including Contributors — making the absent upload_files check the sole barrier to exploitation.
CVE-2026-66601 2 Davidlingren, Wordpress 2 Media Library Assistant, Wordpress 2026-08-20 6.5 Medium
Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
CVE-2026-73402 2 Hakan Ozevin, Wordpress 2 Wp Base Booking, Wordpress 2026-08-20 6.5 Medium
Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
CVE-2026-66612 2 Thembay, Wordpress 2 Aora, Wordpress 2026-08-20 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.
CVE-2025-15689 2 Themegoods, Wordpress 2 Capella, Wordpress 2026-08-20 9.8 Critical
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
CVE-2025-53999 2 Themegoods, Wordpress 2 Altair, Wordpress 2026-08-20 6.5 Medium
Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.
CVE-2026-66592 2 Rtcamp, Wordpress 2 Rtmedia For Wordpress, Buddypress And Bbpress, Wordpress 2026-08-20 9.3 Critical
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
CVE-2026-18778 2 Truebooker, Wordpress 2 Truebooker, Wordpress 2026-08-20 5.3 Medium
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to retrieve the personal information of customers who booked an appointment, including their name, email address, phone number and postal address.
CVE-2026-28164 2 Hashthemes, Wordpress 2 Easy Elementor Addons, Wordpress 2026-08-20 9.6 Critical
Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.
CVE-2026-74992 2 Kirki, Wordpress 2 Kirki, Wordpress 2026-08-20 6.8 Medium
The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not remove all unwanted files after extracting them, allowing such users to upload arbitrary files to a web accessible directory, leading to Stored XSS as well as RCE on some server configurations.
CVE-2026-75963 2 Liedekef, Wordpress 2 Events Made Easy, Wordpress 2026-08-20 7.5 High
The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal payload is triggered passively when any visitor loads the affected single-event page, meaning post-submission execution does not require additional attacker interaction.
CVE-2026-11565 2 Advancedfilemanager, Wordpress 2 Advanced File Manager, Wordpress 2026-08-20 8.5 High
The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server — including sensitive configuration files — and to overwrite existing non-PHP files, which can be leveraged to compromise administrator accounts and the whole site.
CVE-2026-73184 2 Lcweb, Wordpress 2 Global Gallery, Wordpress 2026-08-19 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions.
CVE-2026-66596 2 Stefanno Lissa, Wordpress 2 Newsletter, Wordpress 2026-08-19 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.