Search Results (227 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-89003 1 Wordpress-extensions 1 Wpematico Rss Feed Fetcher 2026-09-28 4.1 Medium
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses back.
CVE-2026-89006 1 Wordpress-extensions 1 Wpematico Rss Feed Fetcher 2026-09-28 6.8 Medium
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2026-92436 1 Wordpress-extensions 1 Mailchimp For Woocommerce 2026-09-28 5.3 Medium
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents.
CVE-2026-96895 1 Wordpress-extensions 1 Wp Youtube Lyte 2026-09-28 6.8 Medium
The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
CVE-2026-96897 1 Wordpress-extensions 1 Optima Express Idx 2026-09-28 5.3 Medium
The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that is available to logged-out users, allowing unauthenticated attackers to force the creation of a fixed author-role account and to repeatedly rotate its application password on any connected install.
CVE-2026-96899 1 Wordpress-extensions 1 Optima Express Idx 2026-09-28 6.8 Medium
The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it and echoing it into the document head when the post is rendered, allowing users with a role as low as author to perform Stored Cross-Site Scripting attacks.
CVE-2026-97319 1 Wordpress-extensions 1 Powerpress 2026-09-28 6.8 Medium
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2026-86785 1 Wordpress-extensions 1 Social Commerce For Woocommerce 2026-09-27 5.3 Medium
The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its REST API endpoints, allowing unauthenticated users to update Social Commerce for WooCommerce WordPress plugin through 2.5.4 configuration and product synchronisation state.
CVE-2022-4997 1 Wordpress-extensions 1 Jet Form Builder Stripe Gateway 2026-09-27 8.6 High
The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes.
CVE-2025-15696 1 Wordpress-extensions 1 Real3d Flipbook Lite 2026-09-27 6.8 Medium
The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any user who later opens the affected flipbook for editing, including administrators.
CVE-2026-14321 1 Wordpress-extensions 1 Divi Dash 2026-09-27 8.2 High
The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated attackers to spoof arbitrary IP addresses in order to bypass rate limiting, ban chosen addresses from the feature, and grow a stored option without bound, resulting in denial of service.
CVE-2026-16264 1 Wordpress-extensions 1 Newsletters 2026-09-27 6.5 Medium
The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subscriber's personal data and overwrite any subscriber's record including their email address.
CVE-2026-18364 1 Wordpress-extensions 1 Zportals 2026-09-27 4.3 Medium
The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on several of its AJAX actions, allowing users with a subscriber-level account to modify the zportals WordPress plugin before 6.4.2's stored integration settings.
CVE-2026-18365 1 Wordpress-extensions 1 Zportals 2026-09-27 4.3 Medium
The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on one of its AJAX actions, allowing users with a subscriber-level account to disclose the display name and email address of every registered user, including administrators.
CVE-2026-75799 1 Wordpress-extensions 1 Yahman Add-ons 2026-09-27 9 Critical
The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.
CVE-2026-84091 1 Wordpress-extensions 1 Sumit Payment Gateway For Woocommerce 2026-09-27 5.3 Medium
The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to mark a pending order paid without completing payment.
CVE-2026-88974 2 Wordpress-extensions, Wpgraphql 2 Wpgraphql, Wpgraphql 2026-09-27 5.4 Medium
WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the object-level edit_post capability or require publish_posts for public status transitions. An authenticated Contributor can therefore publish the Contributor's own draft without editorial approval or modify the Contributor's previously published post despite lacking edit_published_posts, while posts owned by other authors remain protected. This issue is fixed in version 2.22.2.
CVE-2026-93620 2 Payplus, Wordpress-extensions 2 Payplus Payment Gateway, Payplus Payment Gateway 2026-09-27 6.5 Medium
Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions.
CVE-2026-93773 2 Wobbie, Wordpress-extensions 2 Mollie Forms, Mollie Forms 2026-09-27 8.5 High
Contributor SQL Injection in Mollie Forms <= 2.11.0 versions.
CVE-2026-94079 2 Wordpress-extensions, Wpusermanager 2 Wp User Manager, Wp User Manager 2026-09-27 5.3 Medium
Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions.