Search Results (14262 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-61949 2 Bookly, Wordpress 2 Bookly, Wordpress 2026-07-23 9.3 Critical
Unauthenticated SQL Injection in Bookly <= 27.7 versions.
CVE-2026-65498 2 Complianz, Wordpress 2 Complianz, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.
CVE-2026-65526 2 Themeisle, Wordpress 2 Visualizer, Wordpress 2026-07-23 8.5 High
Contributor SQL Injection in Visualizer <= 4.0.6 versions.
CVE-2026-65532 2 Persianscript, Wordpress 2 Persian Woocommerce Sms, Wordpress 2026-07-23 7.6 High
Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.
CVE-2026-65475 2 Wordpress, Wpchill 2 Wordpress, Modula Image Gallery 2026-07-23 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.
CVE-2026-65455 2 Mapsvg, Wordpress 2 Mapsvg, Wordpress 2026-07-23 9.1 Critical
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
CVE-2026-65489 2 Lastudio, Wordpress 2 La-studio Element Kit For Elementor, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
CVE-2026-65495 2 Dokan Multivendor Plugin, Wordpress 2 Dokan Pro, Wordpress 2026-07-23 7.5 High
Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
CVE-2026-65503 2 Bdthemes, Wordpress 2 Utlimate Store Kit Elementor Addons, Wordpress 2026-07-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
CVE-2026-65529 2 Iqonicdesign, Wordpress 2 Graphina, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.
CVE-2026-57626 2 Mailpoet, Wordpress 2 Mailpoet, Wordpress 2026-07-23 7.1 High
Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0.
CVE-2026-65531 2 Themeum, Wordpress 2 Qubely, Wordpress 2026-07-23 4.8 Medium
Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
CVE-2026-65505 2 Bdthemes, Wordpress 2 Utlimate Store Kit Elementor Addons, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
CVE-2026-57704 2 Storeapps, Wordpress 2 Smart Manager, Wordpress 2026-07-23 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.
CVE-2026-59547 2 Easy Payment, Wordpress 2 Payment Gateway For Paypal On Woo Commerce, Wordpress 2026-07-23 7.5 High
Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.
CVE-2026-65484 2 Analogwp, Wordpress 2 Style Kits, Wordpress 2026-07-23 6.3 Medium
Contributor Broken Access Control in Style Kits <= 2.6.5 versions.
CVE-2026-65496 2 Complianz, Wordpress 2 Complianz, Wordpress 2026-07-23 4.4 Medium
Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.
CVE-2026-65497 2 Complianz, Wordpress 2 Complianz, Wordpress 2026-07-23 7.2 High
Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
CVE-2026-15646 2 Berocket, Wordpress 2 Brands For Woocommerce, Wordpress 2026-07-23 6.4 Medium
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-25424 2 Mediavine, Wordpress 2 Mediavine Control Panel, Wordpress 2026-07-23 4.3 Medium
Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.