Export limit exceeded: 15295 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15295 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73355 | 2 Wordpress, Wp.insider | 2 Wordpress, Affiliates Manager | 2026-08-18 | 9.3 Critical |
| Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions. | ||||
| CVE-2026-73348 | 2 Nexcess, Wordpress | 2 Givewp, Wordpress | 2026-08-18 | 6.5 Medium |
| Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. | ||||
| CVE-2026-73351 | 2 Miniorange, Wordpress | 2 Wordpress Social Login And Register, Wordpress | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions. | ||||
| CVE-2026-73356 | 2 Cloudways, Wordpress | 2 Breeze, Wordpress | 2026-08-18 | 8.2 High |
| Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions. | ||||
| CVE-2026-73361 | 2 Wordpress, Wpzoom | 2 Wordpress, Recipe Card Blocks For Gutenberg & Elementor | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions. | ||||
| CVE-2026-73362 | 2 Kaizencoders, Wordpress | 2 Url Shortify, Wordpress | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions. | ||||
| CVE-2026-73393 | 2 Wedevs, Wordpress | 2 Subscribe2, Wordpress | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions. | ||||
| CVE-2026-73400 | 2 Jetmonsters, Wordpress | 2 Restaurant Menu By Motopress, Wordpress | 2026-08-18 | 8.1 High |
| Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. | ||||
| CVE-2026-66637 | 2 Alex, Wordpress | 2 Featured Video Plus, Wordpress | 2026-08-18 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions. | ||||
| CVE-2026-66629 | 2 Themeum, Wordpress | 2 Kirki, Wordpress | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions. | ||||
| CVE-2026-65640 | 1 Wordpress | 1 Wordpress | 2026-08-18 | N/A |
| WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. | ||||
| CVE-2026-32553 | 2 Brainstorm Force, Wordpress | 2 Ottokit, Wordpress | 2026-08-18 | 7.2 High |
| Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions. | ||||
| CVE-2026-15748 | 2 Wordpress, Wpmudev | 2 Wordpress, Forminator Forms – Contact Form, Payment Form & Custom Form Builder | 2026-08-18 | 9.8 Critical |
| The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. | ||||
| CVE-2026-68565 | 2 Paolo, Wordpress | 2 Geodirectory, Wordpress | 2026-08-18 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions. | ||||
| CVE-2026-73189 | 2 Themeum, Wordpress | 2 Wp Crowdfunding, Wordpress | 2026-08-18 | 6.5 Medium |
| Subscriber Insecure Direct Object References (IDOR) in WP Crowdfunding < 2.2.1 versions. | ||||
| CVE-2026-32465 | 2 G5theme, Wordpress | 2 Essential Real Estate, Wordpress | 2026-08-18 | 8.8 High |
| Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions. | ||||
| CVE-2026-32481 | 2 Ezoic, Wordpress | 2 Ezoic, Wordpress | 2026-08-18 | 7.5 High |
| Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions. | ||||
| CVE-2026-32549 | 2 Codexpert, Wordpress | 2 Thumbpress, Wordpress | 2026-08-18 | 7.5 High |
| Unauthenticated Broken Access Control in ThumbPress < 6.5 versions. | ||||
| CVE-2026-28571 | 2 Wordpress, Wppool | 2 Wordpress, Formychat | 2026-08-18 | 7.5 High |
| Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions. | ||||
| CVE-2026-15384 | 2 Manual Image Crop Project, Wordpress | 2 Manual Image Crop, Wordpress | 2026-08-18 | 5.7 Medium |
| The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that crops attachment images; its only guard passes for any logged-in user. A subscriber-level user can therefore supply an arbitrary attachment ID and overwrite that attachment's generated intermediate-size image (for example its thumbnail) and mutate its stored metadata, regardless of who owns the media. This is a cross-user integrity/defacement issue over the Media Library. The action also has no nonce, so it is additionally susceptible to CSRF. | ||||