Search

Search Results (400176 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-94120 2026-09-30 7.5 High
Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.
CVE-2026-94115 2026-09-30 8.5 High
Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions.
CVE-2026-94082 2026-09-30 7.6 High
Author SQL Injection in Quiz Cat <= 3.1.1 versions.
CVE-2026-94081 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.
CVE-2026-94078 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions.
CVE-2026-94077 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions.
CVE-2026-94076 2026-09-30 8.8 High
Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.
CVE-2026-94074 2026-09-30 6.5 Medium
Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.
CVE-2026-93771 2026-09-30 7.2 High
Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.
CVE-2026-93770 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions.
CVE-2026-93651 2026-09-30 7.2 High
Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.
CVE-2026-93624 2026-09-30 7.2 High
Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.
CVE-2026-93621 2026-09-30 8.2 High
Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions.
CVE-2026-93580 2026-09-30 5.3 Medium
The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an IP check that is not enforced, allowing unauthenticated attackers who know a target order's parcel tracking number to forge its shipment status and prematurely mark the order completed.
CVE-2026-93514 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions.
CVE-2026-93512 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.
CVE-2026-92994 2026-09-30 8.8 High
The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it.
CVE-2026-92424 2026-09-30 6.8 Medium
The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary web scripts unfiltered under a privileged user's account, executing in the context of anyone who later views that content.
CVE-2026-91832 2026-09-30 7.1 High
The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting.
CVE-2026-91072 2026-09-30 4.4 Medium
The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an attacker with Administrator-level access rename or delete existing WebP-derivative image files outside that scope, including, on a multisite network, files belonging to a different site they have no access to.