Export limit exceeded: 380574 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 380574 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (15230 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-66429 2 Codepress It Solutions Llc, Wordpress 2 Visitor Traffic Real Time Statistics Pro, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
CVE-2026-66430 2 Codepress It Solutions Llc, Wordpress 2 Visitor Traffic Real Time Statistics Pro, Wordpress 2026-08-14 8.5 High
Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
CVE-2026-66444 2 Kendysond, Wordpress 2 Payment Forms For Paystack, Wordpress 2026-08-14 6.5 Medium
Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.
CVE-2026-66456 2 Bestwebsoft, Wordpress 2 Profile Extra Fields, Wordpress 2026-08-14 6.5 Medium
Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
CVE-2026-66461 2 Smepay, Wordpress 2 Smepay:upi Gateway For Woocommerce, Wordpress 2026-08-14 7.5 High
Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.
CVE-2026-66467 2 Wordpress, Wpmanageninja 2 Wordpress, Fluentcommunity 2026-08-14 6.5 Medium
Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.
CVE-2026-66653 2 Edge-themes, Wordpress 2 Barista, Wordpress 2026-08-14 8.1 High
Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions.
CVE-2026-66656 2 Mikado-themes, Wordpress 2 Foton Core, Wordpress 2026-08-14 8.1 High
Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions.
CVE-2026-66657 2 Mikado-themes, Wordpress 2 Biagiotti, Wordpress 2026-08-14 8.1 High
Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions.
CVE-2026-66658 2 Mvp Themes, Wordpress 2 Reviewer, Wordpress 2026-08-14 8.5 High
Subscriber SQL Injection in Reviewer <= 3.14.2 versions.
CVE-2026-66704 2 Jegstudio, Wordpress 2 Gutenverse, Wordpress 2026-08-14 7.2 High
Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.
CVE-2026-73188 2 Iqonic, Wordpress 2 Kivicare, Wordpress 2026-08-14 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-13610.
CVE-2026-73340 2 Fifu, Wordpress 2 Featured Image From Url, Wordpress 2026-08-14 6.5 Medium
Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions.
CVE-2026-73346 2 Mailchimp, Wordpress 2 Mailchimp For Woocommerce, Wordpress 2026-08-14 7.6 High
Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
CVE-2026-73353 2 Revolut, Wordpress 2 Revolut Gateway For Woocommerce, Wordpress 2026-08-14 5.3 Medium
Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
CVE-2026-57804 2 Codexthemes, Wordpress 2 Thegem Theme Elements (for Elementor), Wordpress 2026-08-14 7.5 High
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows PHP Local File Inclusion. This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.12.1.1.
CVE-2026-19794 2 Gamerz, Wordpress 2 Wp-stats, Wordpress 2026-08-14 7.2 High
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-18109 2 Boldgrid, Wordpress 2 W3 Total Cache, Wordpress 2026-08-14 7.2 High
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the Lazy Load Images feature of W3 Total Cache is enabled, as the unsafe re-emission occurs exclusively within the LazyLoad mutator's img tag rewriting step.
CVE-2026-65480 2 Codexthemes, Wordpress 2 Thegem, Wordpress 2026-08-14 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem allows DOM-Based XSS. This issue affects TheGem: from n/a before 5.12.1.1.
CVE-2026-73532 2 Wordpress, Wpmanageninja 2 Wordpress, Fluent Forms 2026-08-14 9.8 Critical
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.