Export limit exceeded: 402110 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402110 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-97300 | 2026-10-06 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions. | ||||
| CVE-2026-97275 | 2026-10-06 | 5.3 Medium | ||
| Improper Validation of Specified Quantity in Input vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Input Data Manipulation.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28. | ||||
| CVE-2026-97257 | 2026-10-06 | 8.8 High | ||
| Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7. | ||||
| CVE-2026-97071 | 2026-10-06 | 5.3 Medium | ||
| Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17. | ||||
| CVE-2026-95594 | 2026-10-06 | 8.1 High | ||
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions. | ||||
| CVE-2026-95526 | 2026-10-06 | 7.3 High | ||
| Unauthenticated Broken Access Control in BEAR <= 1.2.2 versions. | ||||
| CVE-2026-94675 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack <= 6.2.13 versions. | ||||
| CVE-2026-94299 | 2026-10-06 | 6.5 Medium | ||
| The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers to forge payment confirmations and change the status of arbitrary orders on any installation where that secret has been left at its default empty value. | ||||
| CVE-2026-94278 | 2026-10-06 | 5.5 Medium | ||
| The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belonging to other users, including administrators, and to corrupt unrelated stored site data that referenced the old file path. | ||||
| CVE-2026-94271 | 2026-10-06 | 5.3 Medium | ||
| The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the payment with the payment provider when handling the return from the hosted checkout, and does not check the payment status or amount, allowing unauthenticated users to have orders marked as paid without any payment being taken. | ||||
| CVE-2026-94270 | 2026-10-06 | 5.3 Medium | ||
| The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the authenticity of incoming payment provider notifications, and ships with that verification disabled by default, allowing unauthenticated attackers to mark an unpaid order as paid, or to cancel or refund an existing order. | ||||
| CVE-2026-93617 | 2026-10-06 | 7.2 High | ||
| Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1. | ||||
| CVE-2026-89289 | 2026-10-06 | 5.3 Medium | ||
| The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its id. | ||||
| CVE-2026-86786 | 2026-10-06 | 5.3 Medium | ||
| The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including drafts, pending, scheduled, private and trashed posts, as well as post revisions and media metadata. | ||||
| CVE-2026-66588 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in The7 <= 14.2.2 versions. | ||||
| CVE-2026-62072 | 2026-10-06 | 8.8 High | ||
| Subscriber Broken Access Control in Progress Planner <= 1.10.0 versions. | ||||
| CVE-2026-48199 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in Sermon'e <= 1.0.2 versions. | ||||
| CVE-2026-48197 | 2026-10-06 | 7.2 High | ||
| Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0. | ||||
| CVE-2026-42638 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.7.1 versions. | ||||
| CVE-2026-42637 | 2026-10-06 | 6.5 Medium | ||
| Unauthenticated Settings Change in PayPlug for WooCommerce (Official) <= 3.1.0 versions. | ||||