Search
Search Results (14262 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-61949 | 2 Bookly, Wordpress | 2 Bookly, Wordpress | 2026-07-23 | 9.3 Critical |
| Unauthenticated SQL Injection in Bookly <= 27.7 versions. | ||||
| CVE-2026-65498 | 2 Complianz, Wordpress | 2 Complianz, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions. | ||||
| CVE-2026-65526 | 2 Themeisle, Wordpress | 2 Visualizer, Wordpress | 2026-07-23 | 8.5 High |
| Contributor SQL Injection in Visualizer <= 4.0.6 versions. | ||||
| CVE-2026-65532 | 2 Persianscript, Wordpress | 2 Persian Woocommerce Sms, Wordpress | 2026-07-23 | 7.6 High |
| Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions. | ||||
| CVE-2026-65475 | 2 Wordpress, Wpchill | 2 Wordpress, Modula Image Gallery | 2026-07-23 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30. | ||||
| CVE-2026-65455 | 2 Mapsvg, Wordpress | 2 Mapsvg, Wordpress | 2026-07-23 | 9.1 Critical |
| Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions. | ||||
| CVE-2026-65489 | 2 Lastudio, Wordpress | 2 La-studio Element Kit For Elementor, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions. | ||||
| CVE-2026-65495 | 2 Dokan Multivendor Plugin, Wordpress | 2 Dokan Pro, Wordpress | 2026-07-23 | 7.5 High |
| Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions. | ||||
| CVE-2026-65503 | 2 Bdthemes, Wordpress | 2 Utlimate Store Kit Elementor Addons, Wordpress | 2026-07-23 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | ||||
| CVE-2026-65529 | 2 Iqonicdesign, Wordpress | 2 Graphina, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions. | ||||
| CVE-2026-57626 | 2 Mailpoet, Wordpress | 2 Mailpoet, Wordpress | 2026-07-23 | 7.1 High |
| Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0. | ||||
| CVE-2026-65531 | 2 Themeum, Wordpress | 2 Qubely, Wordpress | 2026-07-23 | 4.8 Medium |
| Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions. | ||||
| CVE-2026-65505 | 2 Bdthemes, Wordpress | 2 Utlimate Store Kit Elementor Addons, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | ||||
| CVE-2026-57704 | 2 Storeapps, Wordpress | 2 Smart Manager, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions. | ||||
| CVE-2026-59547 | 2 Easy Payment, Wordpress | 2 Payment Gateway For Paypal On Woo Commerce, Wordpress | 2026-07-23 | 7.5 High |
| Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions. | ||||
| CVE-2026-65484 | 2 Analogwp, Wordpress | 2 Style Kits, Wordpress | 2026-07-23 | 6.3 Medium |
| Contributor Broken Access Control in Style Kits <= 2.6.5 versions. | ||||
| CVE-2026-65496 | 2 Complianz, Wordpress | 2 Complianz, Wordpress | 2026-07-23 | 4.4 Medium |
| Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions. | ||||
| CVE-2026-65497 | 2 Complianz, Wordpress | 2 Complianz, Wordpress | 2026-07-23 | 7.2 High |
| Administrator PHP Object Injection in Complianz <= 7.5.0 versions. | ||||
| CVE-2026-15646 | 2 Berocket, Wordpress | 2 Brands For Woocommerce, Wordpress | 2026-07-23 | 6.4 Medium |
| The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-25424 | 2 Mediavine, Wordpress | 2 Mediavine Control Panel, Wordpress | 2026-07-23 | 4.3 Medium |
| Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. | ||||