Export limit exceeded: 15347 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (15347 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-66439 2 Berocket, Wordpress 2 Advanced Ajax Product Filters, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.
CVE-2026-65545 2 Jordy Meow, Wordpress 2 Ai-engine, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.
CVE-2026-66678 2 Justinkruit, Wordpress 2 Advanced Custom Fields:font Awesome Field, Wordpress 2026-08-06 4.3 Medium
Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
CVE-2026-66688 2 Brainstormforce, Wordpress 2 Ultimate Addons For Elementor, Wordpress 2026-08-06 6.5 Medium
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
CVE-2026-28146 2 Unlimited-elements, Wordpress 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Wordpress 2026-08-06 6.5 Medium
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
CVE-2026-66702 2 Rank Math Seo, Wordpress 2 Rank Math Seo, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
CVE-2026-66695 2 Boldgrid, Wordpress 2 W3 Total Cache, Wordpress 2026-08-06 6.5 Medium
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
CVE-2026-66703 2 Properfraction, Wordpress 2 Mailoptin, Wordpress 2026-08-06 6.5 Medium
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
CVE-2026-6235 2 Sendmachine, Wordpress 2 Sendmachine For Wordpress, Wordpress 2026-08-06 9.8 Critical
The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the plugin's SMTP configuration, which can be leveraged to intercept all outbound emails from the site (including password reset emails).
CVE-2025-14843 3 Wizit, Woocommerce, Wordpress 3 Gateway For Woocommerce, Woocommerce, Wordpress 2026-08-06 5.3 Medium
The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in all versions up to, and including, 1.3.1. This is due to a lack of authentication and authorization checks in the 'handle_checkout_redirecturl_response' function. This makes it possible for unauthenticated attackers to cancel arbitrary WooCommerce orders by sending a crafted request with a valid order ID.
CVE-2026-65559 2 Tychesoftwares, Wordpress 2 Order Delivery Date For Woocommerce, Wordpress 2026-08-06 7.2 High
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
CVE-2026-65513 2 Nsquared, Wordpress 2 Simply Schedule Appointments, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
CVE-2026-65515 2 Affiliatewp, Wordpress 2 Affiliatewp, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
CVE-2026-65520 2 Miniorange, Wordpress 2 Wp Oauth Server, Wordpress 2026-08-06 9.3 Critical
Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
CVE-2026-65547 2 Constantcontact, Wordpress 2 Creative Mail, Wordpress 2026-08-06 8.5 High
Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.
CVE-2026-65552 2 Qlstudio, Wordpress 2 Export User Data, Wordpress 2026-08-06 9.8 Critical
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
CVE-2026-65508 2 Nsquared, Wordpress 2 Simply Schedule Appointments, Wordpress 2026-08-06 9.3 Critical
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
CVE-2026-65565 2 Ays-pro, Wordpress 2 Survey Maker, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions.
CVE-2026-65569 2 Wordpress, Wpjobportal 2 Wordpress, Wp Job Portal 2026-08-06 8.5 High
Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.
CVE-2026-61964 2 Wordpress, Wpmanageninja 2 Wordpress, Ninja Tables 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.