Search

Search Results (404305 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-86717 2026-10-11 N/A
The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to delete arbitrary WordPress options, which can take the site offline and strip every user of their role.
CVE-2026-86706 2026-10-11 N/A
The Quick quotes WordPress plugin through 1.0.0 does not perform any capability or nonce check on one of its AJAX actions and lets the caller choose which option is written, allowing unauthenticated users to alter arbitrary site settings and to make the site unavailable.
CVE-2026-85126 2026-10-11 N/A
The Crowdfundly WordPress plugin through 2.2.2 does not have capability checks on some of its AJAX actions, allowing users holding one of its own low privileged roles to grant themselves the administrator role or arbitrary capabilities, leading to a full site takeover.
CVE-2026-85121 2026-10-11 N/A
The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to create and overwrite arbitrary WordPress options with request data, which can take the site offline and deactivate all of its Insurify WordPress plugin through 1.0.
CVE-2026-85118 2026-10-11 N/A
The AI Content Generator Marketing WordPress plugin through 1.0.0 does not enforce a nonce or capability check on some of its AJAX actions, allowing unauthenticated users to update and delete arbitrary WordPress options, which can be used to gain administrator access to the site.
CVE-2026-84737 2026-10-11 N/A
The Freeton WP WordPress plugin through 1.0.0 does not correctly validate the activation code when authenticating a user, allowing unauthenticated attackers to log in as any user whose email address they know, including administrators.
CVE-2026-84734 2026-10-11 N/A
The Mindstien Quick Login WordPress plugin through 1.0 does not correctly validate a value supplied in the request against the visitor's own session before authenticating them, allowing unauthenticated attackers to obtain a session as the administrator account the Mindstien Quick Login WordPress plugin through 1.0 is configured with.
CVE-2026-84261 2026-10-11 N/A
The click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin.
CVE-2026-84260 2026-10-11 N/A
The click5 CRM add-on to Gravity Forms WordPress plugin through 1.0.3 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin.
CVE-2026-84259 2026-10-11 N/A
The click5 CRM add-on to WPForms WordPress plugin through 1.0.3 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin.
CVE-2026-84258 2026-10-11 N/A
The click5 CRM add-on to Ninja Forms WordPress plugin through 1.0.1 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin.
CVE-2026-84254 2026-10-11 N/A
The click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4. As a result, unauthenticated attackers could change arbitrary blog options, allowing them to create a new administrator account and take over the site.
CVE-2026-84253 2026-10-11 N/A
The click5 CRM add-on to Gravity Forms WordPress plugin through 1.0.3 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the click5 CRM add-on to Gravity Forms WordPress plugin through 1.0.3. As a result, unauthenticated attackers could change arbitrary blog options, allowing them to create a new administrator account and take over the site.
CVE-2026-84252 2026-10-11 N/A
The click5 CRM add-on to WPForms WordPress plugin through 1.0.3 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the click5 CRM add-on to WPForms WordPress plugin through 1.0.3. As a result, unauthenticated attackers could change arbitrary blog options, allowing them to create a new administrator account and take over the site.
CVE-2026-84251 2026-10-11 N/A
The click5 CRM add-on to Ninja Forms WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the click5 CRM add-on to Ninja Forms WordPress plugin through 1.0.1. As a result, unauthenticated attackers could change arbitrary blog options, allowing them to create a new administrator account and take over the site.
CVE-2026-81649 2026-10-11 N/A
The Fundiin cho WooCommerce WordPress plugin through 3.4.0 does not have proper authorisation on several of its REST API routes, relying instead on a credential that is identical on every installation, allowing unauthenticated attackers to disclose the store's payment credentials and customer order data, overwrite the payment gateway configuration so that payments are credited elsewhere, and mark unpaid orders as paid. The same missing authorisation also allows arbitrary script to be stored in a field which is output unescaped on the classic checkout, leading to unauthenticated stored XSS on stores that do not use the block-based checkout.
CVE-2026-81420 2026-10-11 N/A
The Tcard WP WordPress plugin through 1.8.0 does not sanitise and escape a parameter before using it in a SQL statement in one of its unauthenticated AJAX actions, allowing unauthenticated users to perform SQL injection attacks.
CVE-2026-108606 1 Jeecg 2 Jeecg-boot, Jeecg Boot 2026-10-11 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController deleteById handler that allows any authenticated user to delete OCR records. Low-privileged attackers can obtain record ids from the unguarded GET /airag/ocr/list endpoint and repeatedly delete every shared OCR prompt record stored in Redis.
CVE-2026-81156 2026-10-11 N/A
The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape some of its gallery settings before outputting them on the gallery edit screen, allowing users with the Contributor role and above to store JavaScript that executes in the context of an administrator who opens the gallery for editing.
CVE-2026-81155 2026-10-11 N/A
The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape a gallery setting before outputting it on a frontend page, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing a gallery, including administrators.