Export limit exceeded: 16390 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (16390 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-95525 | 2 Wedevs, Wordpress | 2 Wp User Frontend, Wordpress | 2026-09-23 | 6.5 Medium |
| Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions. | ||||
| CVE-2026-94080 | 2 Webwizards, Wordpress | 2 Marketking, Wordpress | 2026-09-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions. | ||||
| CVE-2026-95529 | 2 Codepeople, Wordpress | 2 Calculated Fields Form, Wordpress | 2026-09-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions. | ||||
| CVE-2026-95515 | 2 Ninjaforms, Wordpress | 2 Ninja Forms, Wordpress | 2026-09-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. | ||||
| CVE-2026-95522 | 2 Syed Balkhi, Wordpress | 2 Easy Digital Downloads, Wordpress | 2026-09-23 | 7.6 High |
| Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions. | ||||
| CVE-2026-95523 | 2 Wedevs, Wordpress | 2 Wp User Frontend, Wordpress | 2026-09-23 | 6.5 Medium |
| Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. | ||||
| CVE-2026-95524 | 2 Wedevs, Wordpress | 2 Wp User Frontend, Wordpress | 2026-09-23 | 5.3 Medium |
| Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. | ||||
| CVE-2026-95527 | 2 Conekta Group, Wordpress | 2 Conekta Payment Gateway, Wordpress | 2026-09-23 | 6.5 Medium |
| Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions. | ||||
| CVE-2026-95590 | 2 Tainacan, Wordpress | 2 Tainacan, Wordpress | 2026-09-23 | 7.1 High |
| Subscriber SQL Injection in Tainacan <= 1.2.0 versions. | ||||
| CVE-2026-95604 | 2 Tangible, Wordpress | 2 Loops & Logic, Wordpress | 2026-09-23 | 7.5 High |
| Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions. | ||||
| CVE-2026-93526 | 2 Nexcess, Wordpress | 2 Event Tickets, Wordpress | 2026-09-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions. | ||||
| CVE-2026-93772 | 2 Tomdever, Wordpress | 2 Wpforo Forum, Wordpress | 2026-09-23 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions. | ||||
| CVE-2026-93513 | 2 Siteskite, Wordpress | 2 Siteskite, Wordpress | 2026-09-23 | 4.3 Medium |
| Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions. | ||||
| CVE-2026-94168 | 2 Leap13, Wordpress | 2 Premium Addons For Elementor, Wordpress | 2026-09-23 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. | ||||
| CVE-2026-94124 | 2 Levelfourdevelopment, Wordpress | 2 Wp-easycart, Wordpress | 2026-09-23 | 8.5 High |
| Contributor SQL Injection in WP EasyCart <= 5.9.4 versions. | ||||
| CVE-2026-95601 | 2 Wbw Plugins, Wordpress | 2 Product Filter By Wbw, Wordpress | 2026-09-23 | 9.3 Critical |
| Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions. | ||||
| CVE-2026-95586 | 2 Themefic, Wordpress | 2 Ultimate Addons For Contact Form 7, Wordpress | 2026-09-23 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions. | ||||
| CVE-2026-93368 | 2 Travispluse, Wordpress | 2 Rename Wp-login.php To Anything You Want, Wordpress | 2026-09-23 | 7.5 High |
| The Rename wp-login.php to anything you want plugin for WordPress is vulnerable to time-based SQL Injection via 'log' (Username) Parameter in all versions up to, and including, 2.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. WordPress core applies wp_unslash() to the 'log' POST value before dispatching the wp_login_failed action, stripping magic-quotes backslash escaping and allowing a raw single quote to reach the plugin's handler unimpeded. | ||||
| CVE-2026-91092 | 2 Tomdever, Wordpress | 2 Wpforo Forum, Wordpress | 2026-09-23 | 4.3 Medium |
| The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to take over another guest author's forum post and modify its title, body, author name, and stored owner email address. This requires that guest posting and editing are enabled on the forum, and that the attacker knows the target guest author's email address. | ||||
| CVE-2026-89412 | 2 Cozmoslabs, Wordpress | 2 Translatepress – Translate Multilingual Sites With Ai Translation, Wordpress | 2026-09-23 | 7.2 High |
| The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Translation Memory Suggestion Panel (v-html on suggestion.original) in all versions up to, and including, 3.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Unauthenticated attackers can seed the translation dictionary's original column with executable HTML because the front-end rendering pipeline decodes entity-encoded payloads via html_entity_decode() before persistence, and the original column is deliberately exempt from kses filtering — meaning no save-time sanitizer neutralizes the stored payload before it is later rendered in an administrator's session. | ||||