Search Results (103234 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-96341 2026-10-11 8.2 High
Incorrect Privilege Assignment vulnerability in WPMU DEV Forminator forminator allows Privilege Escalation.This issue affects Forminator: from n/a through 1.57.3.
CVE-2026-96336 2026-10-11 7.5 High
Authentication Bypass by Spoofing vulnerability in WPMU DEV Forminator forminator allows Identity Spoofing.This issue affects Forminator: from n/a through 1.57.2.
CVE-2026-96278 2026-10-11 7.2 High
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Session History in all versions up to, and including, 9.3.03.002 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The bypass works because esc_url_raw() strips literal angle brackets but retains HTML entities, which wppaEntityDecode() silently converts back to live HTML tags before jQuery('#wppa-modal-container').html() renders them.
CVE-2026-95684 2026-10-11 7.2 High
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'attachments[name]' Parameter in all versions up to, and including, 1.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-94676 2026-10-11 7.2 High
Deserialization of Untrusted Data vulnerability in Tainacan Community Tainacan tainacan allows Object Injection.This issue affects Tainacan: from n/a through 1.3.0.
CVE-2026-94666 2026-10-11 7.5 High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7 allows Path Traversal.This issue affects Generate PDF using Contact Form 7: from n/a through 4.2.1.
CVE-2026-94065 2026-10-11 8.8 High
Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio colorit allows Object Injection.This issue affects ColorFolio: from n/a through 1.3.
CVE-2026-94064 2026-10-11 8.8 High
Deserialization of Untrusted Data vulnerability in BuddhaThemes Neo | Barber Shop WordPress Theme neocut allows Object Injection.This issue affects Neo | Barber Shop WordPress Theme: from n/a through 3.5.
CVE-2026-93950 2026-10-11 7.5 High
Missing Authorization vulnerability in StylemixThemes Motors motors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through 1.4.108.
CVE-2026-93949 2026-10-11 7.1 High
Authentication Bypass Using an Alternate Path or Channel vulnerability in Omegathemes Grocery Shopping Store grocery-shopping-store allows Password Recovery Exploitation.This issue affects Grocery Shopping Store: from n/a through 1.3.3.
CVE-2026-93775 2026-10-11 7.2 High
The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Auphonic Webhook in all versions up to, and including, 4.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injection is triggered by submitting a request to the Auphonic webhook endpoint with any POST body where the status_string field is not the literal string 'Done', causing the full raw POST superglobal to be stored in the plugin log before any authentication key validation is performed.
CVE-2026-78530 2026-10-11 7.7 High
Subscriber Arbitrary File Deletion in FoodBakery <= 4.6 versions.
CVE-2026-65459 2026-10-11 7.5 High
Unauthenticated Arbitrary Content Deletion in Forminator <= 1.57.3 versions.
CVE-2026-62130 2026-10-11 7.2 High
Shop manager PHP Object Injection in WooCommerce Multilingual & Multicurrency <= 5.5.8 versions.
CVE-2026-62118 2026-10-11 7.3 High
Unauthenticated Broken Access Control in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.
CVE-2026-62044 2026-10-11 7.2 High
Deserialization of Untrusted Data vulnerability in bPlugins Super Video Player super-video-player allows Object Injection.This issue affects Super Video Player: from n/a through 1.8.13.
CVE-2026-62038 2026-10-11 7.3 High
Unauthenticated Broken Authentication in eRoom <= 1.7.1 versions.
CVE-2026-62033 2026-10-11 7.6 High
Subscriber Settings Change in uListing <= 2.2.0 versions.
CVE-2026-62021 2026-10-11 8.8 High
Subscriber PHP Object Injection in Angio <= 1.1.1 versions.
CVE-2026-42706 2026-10-11 7.5 High
Unauthenticated Broken Access Control in DK <= 3.2.1 versions.