Export limit exceeded: 15190 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15190 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16746 | 2 Multivendorx, Wordpress | 2 Multivendorx, Wordpress | 2026-08-06 | 2.7 Low |
| The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-level user to read other vendors' commission and financial data. | ||||
| CVE-2026-28180 | 2 Mercadopago, Wordpress | 2 Mercado Pago Payments For Woocommerce, Wordpress | 2026-08-06 | 5.3 Medium |
| Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions. | ||||
| CVE-2026-28183 | 2 Publishpress, Wordpress | 2 Capabilities, Wordpress | 2026-08-06 | N/A |
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||||
| CVE-2026-66712 | 2 Wordpress, Wp.insider | 2 Wordpress, Simple Membership | 2026-08-06 | 7.5 High |
| Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions. | ||||
| CVE-2026-66440 | 2 Wordpress, Xplodedthemes | 2 Wordpress, Wpide - File Manager & Code Editor | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions. | ||||
| CVE-2026-14240 | 2 Tourmaster, Wordpress | 2 Tourmaster, Wordpress | 2026-08-06 | 5.3 Medium |
| The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its publicly accessible directory with no access control, allowing unauthenticated users to download the exported customers' personal information once an administrator has run an export. | ||||
| CVE-2026-16290 | 2 Profilegrid, Wordpress | 2 Profilegrid, Wordpress | 2026-08-06 | 5.3 Medium |
| The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin before 6.0.0.0's member-visibility setting. | ||||
| CVE-2026-61961 | 2 Wordpress, Wpdeveloper | 2 Wordpress, Embedpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. | ||||
| CVE-2026-66708 | 2 Boldgrid, Wordpress | 2 Total Upkeep, Wordpress | 2026-08-06 | 8.2 High |
| Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions. | ||||
| CVE-2026-66709 | 2 Webappick, Wordpress | 2 Ctx Feed, Wordpress | 2026-08-06 | 9.1 Critical |
| Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions. | ||||
| CVE-2026-66710 | 2 E2pdf, Wordpress | 2 E2pdf, Wordpress | 2026-08-06 | 8.1 High |
| Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions. | ||||
| CVE-2026-28178 | 2 Codesupplyco, Wordpress | 2 Powerkit, Wordpress | 2026-08-06 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions. | ||||
| CVE-2026-32548 | 2 Surecart, Wordpress | 2 Surecart, Wordpress | 2026-08-06 | 5.3 Medium |
| Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions. | ||||
| CVE-2026-61982 | 2 Jp-secure, Wordpress | 2 Siteguard Wp Plugin, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. | ||||
| CVE-2026-65509 | 2 Wordpress, Wpdatatables | 2 Wordpress, Wpdatatables | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. | ||||
| CVE-2026-65502 | 2 Bdthemes, Wordpress | 2 Element Pack Elementor Addons, Wordpress | 2026-08-06 | 5.3 Medium |
| Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions. | ||||
| CVE-2026-65573 | 2 Themerex, Wordpress | 2 Abelle, Wordpress | 2026-08-06 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. | ||||
| CVE-2026-66439 | 2 Berocket, Wordpress | 2 Advanced Ajax Product Filters, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions. | ||||
| CVE-2026-65545 | 2 Jordy Meow, Wordpress | 2 Ai-engine, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions. | ||||
| CVE-2026-66678 | 2 Justinkruit, Wordpress | 2 Advanced Custom Fields:font Awesome Field, Wordpress | 2026-08-06 | 4.3 Medium |
| Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions. | ||||