Search Results (623 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-85009 1 Wordpress-extensions 1 Restropress 2026-09-29 6.5 Medium
The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverable state and to write notes to another customer's order.
CVE-2026-85122 1 Wordpress-extensions 1 Easy Form Builder 2026-09-29 8.8 High
The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unescaped in an admin page, leading to Stored XSS.
CVE-2026-85123 1 Wordpress-extensions 1 Easy Form Builder 2026-09-29 5.3 Medium
The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to create WordPress accounts on a site whose owner has disabled registration.
CVE-2026-85127 2 Vikwp, Wordpress-extensions 2 Vikbooking Hotel Booking Engine & Pms, Vikbooking 2026-09-29 8.8 High
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.
CVE-2026-85350 1 Wordpress-extensions 1 Upsellwp 2026-09-29 5.3 Medium
The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, allowing unauthenticated users to buy arbitrary products at the campaign's discounted price.
CVE-2026-87767 1 Wordpress-extensions 1 Wp Shortcut Link 2026-09-29 8.6 High
The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter before using it in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
CVE-2026-87770 1 Wordpress-extensions 1 Price Drop Alert For Woo Commerce 2026-09-29 8.6 High
The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using them in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
CVE-2026-87771 1 Wordpress-extensions 1 Product Question And Answer 2026-09-29 8.6 High
The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them in SQL queries on AJAX actions available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
CVE-2026-87774 1 Wordpress-extensions 1 Tz Weekly Radio Schedule 2026-09-29 8.6 High
The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
CVE-2026-87775 1 Wordpress-extensions 1 Tz Weekly Radio Schedule 2026-09-29 8.6 High
The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
CVE-2026-88825 1 Wordpress-extensions 1 Igms Direct Booking 2026-09-29 8.8 High
The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowing unauthenticated users to store arbitrary web scripts that execute in the context of an administrator viewing the iGMS Direct Booking WordPress plugin before 2.0 settings, and in the browser of any visitor to a page displaying the booking widget.
CVE-2026-97227 1 Wordpress-extensions 1 Nextscripts Social Networks Auto-poster 2026-09-29 5.9 Medium
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials, delete arbitrary posts and reset the NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8's configuration.
CVE-2026-11871 1 Wordpress-extensions 1 Team Showcase Supreme 2026-09-29 5.3 Medium
The Team Members WordPress plugin before 9.3 does not perform any authorization or visibility check in an unauthenticated AJAX action that returns full team member records by ID, allowing unauthenticated attackers to enumerate and disclose details, including email addresses and phone numbers, of team members the administrator has not published publicly.
CVE-2026-88993 2 Areoi, Wordpress-extensions 2 All Bootstrap Blocks, All Bootstrap Blocks 2026-09-28 6.8 Medium
The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with Contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.
CVE-2026-89007 1 Wordpress-extensions 1 Bookit 2026-09-28 2.7 Low
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users with its low-privileged custom Staff role to delete arbitrary appointments.
CVE-2026-89008 1 Wordpress-extensions 1 Bookit 2026-09-28 2.7 Low
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-retrieval actions, allowing users with a low-privilege Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5-specific role to read other users' appointment records, including customer names, email addresses, phone numbers and private booking comments.
CVE-2026-90978 1 Wordpress-extensions 1 Filter Gallery 2026-09-28 7.1 High
The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonce field is omitted, and applies no capability check, allowing low-privileged users to overwrite the content of arbitrary posts and delete the Filter Gallery WordPress plugin before 1.1.5's stored gallery options.
CVE-2026-90984 1 Wordpress-extensions 1 Generate Pdf Using Contact Form 7 2026-09-28 5.8 Medium
The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its PDF renderer performs on submitted form content, allowing unauthenticated users to make the server request internal resources and read the response back through the generated PDF.
CVE-2026-79713 1 Wordpress-extensions 1 Breeze Cache 2026-09-28 6.5 Medium
The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have a page rendered under their own request context stored under, and served from, the clean URL's cache entry to every subsequent visitor.
CVE-2026-86796 1 Wordpress-extensions 1 Wp Ghost 2026-09-28 5.3 Medium
The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attacker-suppliable request parameter as sufficient, which allows unauthenticated attackers to disable those protections and re-expose the concealed login and admin URLs on any request.