Search Results (623 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-39796 2 Flipper Code, Wordpress-extensions 2 Advanced Posts Listing – Show Post List Easily, Advanced Posts Listing–show Post List Easily 2026-10-06 7.5 High
Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions.
CVE-2026-39797 2 Data443, Wordpress-extensions 2 Gdpr Framework By Data443, Gdpr Framework By Data443 2026-10-06 9.8 Critical
Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions.
CVE-2026-39798 2 Themetechmount, Wordpress-extensions 2 Truebooker, Truebooker 2026-10-06 6.5 Medium
Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions.
CVE-2026-40806 2 Plugin-devs, Wordpress-extensions 2 Blog, Posts And Category Filter For Elementor, Blog Posts And Category Filter For Elementor 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions.
CVE-2026-40807 2 Aman, Wordpress-extensions 2 Cf7 Views – Complete Entry Management For Contact Form 7, Cf7 Views 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in CF7 Views &#8211; Complete Entry Management for Contact Form 7 <= 3.2.6 versions.
CVE-2026-41555 2 Weblizar, Wordpress-extensions 2 Newsletter Subscription Form – User Subscriptions Form, Capture Email, Newsletter Subscription Form – User Subscriptions Form, Capture Email 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions.
CVE-2026-41559 2 Pluginjoy, Wordpress-extensions 2 Safesnap – Verified Wordpress Backup & Restore, Safesnap 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in SafeSnap – Verified WordPress Backup &amp; Restore <= 2.1.2 versions.
CVE-2026-41560 2 Wordpress-extensions, Wxdlabs 2 Wxd Backup Lite, Wxd Backup Lite 2026-10-06 7.5 High
Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions.
CVE-2026-41561 2 Adrian Lin, Wordpress-extensions 2 Museder Restoreone, Museder Restoreone 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Museder RestoreOne <= 2.7.276 versions.
CVE-2026-41562 2 Norvisgabriel, Wordpress-extensions 2 Norvis Backup, Norvis Backup 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions.
CVE-2026-42413 2 Daftplug, Wordpress-extensions 2 Snapshotify, Snapshotify 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Snapshotify &#8211; All-in-One Backup &amp; Restore &amp; Migrate <= 1.3.2 versions.
CVE-2014-125130 2 Damjan, Wordpress-extensions 2 Codeart Google Mp3 Audio Player, Codeart Google Mp3 Audio Player 2026-10-06 7.5 High
CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-traversal payload in the file parameter of direct_download.php. Attackers can request paths ../../wp-config.php without authentication to download configuration files containing database credentials and secret keys, leading to full site compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-19.
CVE-2026-95865 2 Beaverbuilder, Wordpress-extensions 2 Beaver Builder Page Builder – Drag And Drop Website Builder, Beaver Builder Page Builder 2026-10-06 6.5 Medium
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all versions up to, and including, 2.11.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable get_autosuggest_values AJAX endpoint is reachable by any Contributor who owns a draft post, as the required fl_ajax_update nonce is emitted into the block editor for any user who can edit a Beaver Builder post type.
CVE-2026-84169 1 Wordpress-extensions 1 Upi Qr Code Payment Gateway 2026-10-06 5.3 Medium
The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary order as paid without making any payment.
CVE-2026-39763 2 Deepak Anand, Wordpress-extensions 2 Wp Dummy Content Generator, Wp Dummy Content Generator 2026-10-06 4.3 Medium
Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through 4.0.0.
CVE-2026-94669 2 Wordpress-extensions, Wpmanageninja 2 Fluent Forms Pro Add On Pack, Fluent Forms Pro Add On Pack 2026-10-06 5.3 Medium
Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13.
CVE-2026-105073 2 Arraytics, Wordpress-extensions 2 Wp Event Solution, Wp Event Solution 2026-10-06 5.3 Medium
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Arraytics WP Event Solution wp-event-solution allows Retrieve Embedded Sensitive Data.This issue affects WP Event Solution: from n/a through 4.1.25.
CVE-2026-103684 2 Arraytics, Wordpress-extensions 2 Wp Event Solution, Wp Event Solution 2026-10-06 5.3 Medium
Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through 4.1.25.
CVE-2026-39783 2 Wordpress-extensions, Wp Syntex 2 Polylang, Polylang 2026-10-06 4.3 Medium
Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a through 3.8.7.
CVE-2026-105421 2 Nathanbarry, Wordpress-extensions 2 Kit (formerly Convertkit) For Woocommerce, Kit (formerly Convertkit) For Woocommerce 2026-10-06 5.3 Medium
Missing Authorization vulnerability in Kit Kit (formerly ConvertKit) for WooCommerce convertkit-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kit (formerly ConvertKit) for WooCommerce: from n/a through 2.2.0.