| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions. |
| Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions. |
| The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Content in all versions up to, and including, 3.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
| Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions. |
| Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions. |
| Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions. |
| Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions. |
| Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions. |
| Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions. |
| Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions. |
| Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions. |
| Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions. |
| import_contacts Path Traversal in Groundhogg <= 4.7.1 versions. |
| Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions. |
| Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions. |
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-12965. |
| The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires "Embed images" option in AcyMailing configuration being enabled. |
| The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_group_section' parameter in all versions up to, and including, 2.3.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. |