Search Results (14429 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-15962 2 Techjewel, Wordpress 2 Fluent Forms Pro Add On Pack, Wordpress 2026-07-27 8.8 High
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a user meta field is mapped.
CVE-2026-12987 2 Events Manager Project, Wordpress 2 Events Manager, Wordpress 2026-07-27 7.5 High
The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP object injection. The resulting gadget chain reaches a database query that is built without parameterisation, so an unauthenticated attacker can read arbitrary database data (e.g. user password hashes, secret keys) when the booking is later loaded.
CVE-2026-65564 2 Chrisrichardson, Wordpress 2 Mappress Maps For Wordpress, Wordpress 2026-07-27 5.3 Medium
Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.
CVE-2026-10818 2 Wordpress, Wpforms 2 Wordpress, Wpforms Pro 2026-07-27 8.1 High
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not being deleted upon validation failure. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.
CVE-2026-9830 2 Repute Infosystems, Wordpress 2 Bookingpress Appointment Booking Pro, Wordpress 2026-07-27 8.2 High
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
CVE-2026-14827 2 Calendar, Wordpress 2 Calendar, Wordpress 2026-07-27 6.8 Medium
The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar.
CVE-2026-14820 2 Quizandsurveymaster, Wordpress 2 Quiz And Survey Master, Wordpress 2026-07-27 5.3 Medium
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.
CVE-2026-65436 2 Themeum, Wordpress 2 Kirki, Wordpress 2026-07-27 6.8 Medium
Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.
CVE-2026-65562 2 Wordpress, Wpdeveloper 2 Wordpress, Betterdocs 2026-07-27 6.5 Medium
Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.
CVE-2026-65557 2 Tychesoftwares, Wordpress 2 Abandoned Cart Lite For Woocommerce, Wordpress 2026-07-27 5.9 Medium
Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
CVE-2026-59539 2 Cozmoslabs, Wordpress 2 Paid Member Subscriptions, Wordpress 2026-07-27 7.5 High
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
CVE-2026-59556 2 Acowebs, Wordpress 2 Dynamic Pricing With Discount Rules For Woocommerce, Wordpress 2026-07-27 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
CVE-2026-66445 2 100plugins, Wordpress 2 Open User Map, Wordpress 2026-07-27 6.5 Medium
Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.
CVE-2026-59538 2 Ruben Garcia, Wordpress 2 Gamipress, Wordpress 2026-07-27 9.3 Critical
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
CVE-2026-59551 2 Rtcamp, Wordpress 2 Rtmedia For Wordpress, Buddypress And Bbpress, Wordpress 2026-07-27 8.5 High
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
CVE-2026-59529 2 Motovnet, Wordpress 2 Ebook Store, Wordpress 2026-07-27 7.5 High
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
CVE-2026-66428 2 Jgwhite33, Wordpress 2 Wp Google Review Slider, Wordpress 2026-07-27 4.3 Medium
Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
CVE-2026-59527 2 Romancode, Wordpress 2 Mapsvg, Wordpress 2026-07-27 9.3 Critical
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-59533 2 Christoph Vielgrader, Wordpress 2 Relevanssi Light, Wordpress 2026-07-27 9.3 Critical
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
CVE-2026-59560 2 Roxnor, Wordpress 2 Fundengine, Wordpress 2026-07-27 6.5 Medium
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.