Search Results (16160 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-86447 2 Learnpress, Wordpress 2 Learnpress, Wordpress 2026-09-18 5.3 Medium
The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative course tools, allowing unauthenticated attackers to list every enrolled student's display name and user identifier against the course they are enrolled on, and to recover their email addresses through the same handler's search filter.
CVE-2026-87965 2 Easy-appointments, Wordpress 2 Easy Appointments, Wordpress 2026-09-18 N/A
The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointment cancellation and confirmation action, deriving the token from a hardcoded source-embedded salt and the appointment's creation timestamp, so unauthenticated attackers who know or guess that timestamp can cancel or confirm arbitrary appointments.
CVE-2026-84906 2 Eventin, Wordpress 2 Eventin, Wordpress 2026-09-18 5.3 Medium
The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or which order it belongs to, allowing unauthenticated visitors to mark unpaid orders of any value as paid by replaying the transaction of a single genuine low-value payment.
CVE-2026-87966 2 Easy-appointments, Wordpress 2 Easy Appointments, Wordpress 2026-09-18 N/A
The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied id, allowing unauthenticated attackers to overwrite, and through a follow-on cleanup delete, arbitrary appointments.
CVE-2026-86824 2 Newsletter, Wordpress 2 Newsletter, Wordpress 2026-09-18 4.8 Medium
The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed hash, allowing an unauthenticated attacker who recovers that key offline to forge tracking links, obtain any subscriber's session token, and read and modify that subscriber's stored personal data.
CVE-2026-87796 2 Sh1zen, Wordpress 2 Multi Uploader For Gravity Forms, Wordpress 2026-09-18 9.8 Critical
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
CVE-2026-86446 2 Learnpress, Wordpress 2 Learnpress, Wordpress 2026-09-18 3.7 Low
The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is checked, allowing unauthenticated attackers to obtain the correct answer to every option of a question, along with the instructor's explanation, on courses configured to be taken without enrolling.
CVE-2026-86311 2 10web, Wordpress 2 Photo Gallery By 10web – Mobile-friendly Image Gallery, Wordpress 2026-09-17 6.4 Medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-66580 2 Rextheme, Wordpress 2 Product Feed Manager, Wordpress 2026-09-17 8.5 High
Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.
CVE-2026-66630 2 Publishpress, Wordpress 2 Publishpress Series, Wordpress 2026-09-17 7.6 High
Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.
CVE-2026-66574 2 Bdthemes, Wordpress 2 Element Pack Elementor Addons, Wordpress 2026-09-17 6.5 Medium
Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.
CVE-2026-74005 2 Publishpress, Wordpress 2 Publishpress Series, Wordpress 2026-09-17 5.4 Medium
Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.
CVE-2026-90887 2 Wordpress, Wpinventory 2 Wordpress, Wp Inventory Manager 2026-09-17 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.
CVE-2026-62108 2 Miniorange, Wordpress 2 Headless Single Sign On, Wordpress 2026-09-17 9.8 Critical
Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.
CVE-2026-66617 2 Publishpress, Wordpress 2 Publishpress Series, Wordpress 2026-09-17 6.5 Medium
Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.
CVE-2026-74002 2 Wordpress, Wpdevelop 2 Wordpress, Booking Calendar 2026-09-17 5.3 Medium
Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.
CVE-2026-78294 2 Dylan Kuhn, Wordpress 2 Geo Mashup, Wordpress 2026-09-17 6.5 Medium
Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
CVE-2026-66625 2 Wcvendors, Wordpress 2 Wc Vendors Marketplace, Wordpress 2026-09-17 7.6 High
Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.
CVE-2026-66676 2 Matrixaddons, Wordpress 2 Easy Invoice, Wordpress 2026-09-17 5.3 Medium
Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.
CVE-2026-66573 2 Crocoblock. Jetimpex Inc., Wordpress 2 Jettabs, Wordpress 2026-09-17 6.5 Medium
Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.