Search Results (15259 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-18464 2 Wordpress, Wp Maps Pro 2 Wordpress, Wp Maps Pro 2026-08-10 7.5 High
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service.
CVE-2026-16535 2 Link Library Project, Wordpress 2 Link Library, Wordpress 2026-08-10 6.1 Medium
The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who can be tricked into performing an action.
CVE-2026-14224 2 Easy-appointments, Wordpress 2 Easy Appointments, Wordpress 2026-08-10 5.4 Medium
The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment's edit form. A subscriber-level user with an appointment of their own can therefore reuse that nonce to overwrite the customer metadata (email, name, phone, description) of another user's appointment. Because the Easy Appointments WordPress plugin before 3.12.28 then treats that metadata as the appointment's contact data, a subsequent administrator status change with customer notifications enabled delivers the victim's appointment notification to the attacker-controlled email address.
CVE-2026-14221 2 Easy-appointments, Wordpress 2 Easy Appointments, Wordpress 2026-08-10 3.8 Low
The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and delete bookings.
CVE-2026-14188 2 Easy-appointments, Wordpress 2 Easy Appointments, Wordpress 2026-08-10 2.7 Low
The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information.
CVE-2026-13692 2 Payu, Wordpress 2 Payu Commercepro Plugin, Wordpress 2026-08-10 5.3 Medium
The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.
CVE-2026-14223 2 Easy-appointments, Wordpress 2 Easy Appointments, Wordpress 2026-08-10 4.3 Medium
The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier.
CVE-2026-14222 2 Easy-appointments, Wordpress 2 Easy Appointments, Wordpress 2026-08-10 3.8 Low
The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.
CVE-2026-48093 2 Davidartiss, Wordpress 2 Code Embed, Wordpress 2026-08-10 6.5 Medium
The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the external URL embed feature in post content. The vulnerable code scans rendered content for URL embed tokens, fetches the remote URL, and inserts the remote response body into the page without output sanitization or an `unfiltered_html` capability check. This allows a Contributor attacker to submit a pending post containing an inert-looking URL token that executes attacker-controlled JavaScript when an Administrator or Editor previews or reviews the post. This is distinct from CVE-2026-2512, which affected custom field meta values up to version 2.5.1. This vector affects version 2.6 and uses the documented external URL embed feature in post content. This particular issue is patched in version 2.6.1.
CVE-2026-18933 2 Wordpress, Wpdownloadmanager 2 Wordpress, Download Manager 2026-08-10 7.2 High
The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no wp_check_filetype_and_ext, no validate_file, and no extension blocklist exist anywhere in the upload handler.
CVE-2026-14226 2 Easy-appointments, Wordpress 2 Easy Appointments, Wordpress 2026-08-10 4.3 Medium
The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookings on the site, including customer names, schedules, and statuses.
CVE-2026-66470 2 Shabti, Wordpress 2 Frontend Admin By Dynamapps, Wordpress 2026-08-08 7.1 High
Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
CVE-2026-66662 2 Shabti, Wordpress 2 Frontend Admin By Dynamapps, Wordpress 2026-08-08 9.8 Critical
Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
CVE-2026-66664 2 Squirrly, Wordpress 2 Seo Plugin By Squirrly Seo, Wordpress 2026-08-08 7.1 High
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.
CVE-2026-66694 2 Thrive Themes Coupon, Wordpress 2 Thrive Architect, Wordpress 2026-08-08 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
CVE-2026-66705 2 Facebook, Wordpress 2 Facebook For Wordpress, Wordpress 2026-08-08 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
CVE-2026-66707 2 Facebook, Wordpress 2 Facebook For Woocommerce, Wordpress 2026-08-08 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
CVE-2026-11361 2 Formidableforms, Wordpress 2 Formidable, Wordpress 2026-08-08 5.9 Medium
The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without being charged.
CVE-2026-13399 2 Payment Plugins, Wordpress 2 Payment Plugins For Paypal Woocommerce, Wordpress 2026-08-08 7.5 High
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments
CVE-2026-14936 2 Simple-membership-plugin, Wordpress 2 Simple Membership, Wordpress 2026-08-08 5.3 Medium
The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's own configured merchant account before activating a membership, allowing unauthenticated users to activate or extend a membership using a payment made to an arbitrary PayPal account they control.