| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-84771 | Med | 0.34 | 5.3 | 0.00 | Sep 2, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions. | ||
| CVE-2026-84770 | Hig | 0.57 | 8.8 | 0.00 | Sep 2, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions. | ||
| CVE-2026-84764 | Hig | 0.50 | 8.8 | 0.00 | Sep 2, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions. | ||
| CVE-2026-84760 | Med | 0.34 | 5.3 | 0.00 | Sep 2, 2026 | Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions. | ||
| CVE-2026-84759 | Hig | 0.39 | 7.1 | 0.00 | Sep 2, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions. | ||
| CVE-2026-84217 | Med | 0.35 | 5.4 | 0.00 | Sep 2, 2026 | Missing Authorization vulnerability in Mamunur Rashid Classified Listing classified-listing allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Classified Listing: from n/a through 6.1.3. | ||
| CVE-2026-83562 | Med | 0.42 | 6.5 | 0.00 | Sep 2, 2026 | Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions. | ||
| CVE-2026-82223 | Med | 0.42 | 6.5 | 0.00 | Sep 2, 2026 | Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions. | ||
| CVE-2026-81775 | Hig | 0.46 | 7.1 | 0.00 | Sep 2, 2026 | Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions. | ||
| CVE-2026-81774 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2026 | Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions. | ||
| CVE-2026-81772 | Hig | 0.57 | 8.8 | 0.00 | Sep 2, 2026 | Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions. | ||
| CVE-2026-81771 | Hig | 0.46 | 7.1 | 0.00 | Sep 2, 2026 | Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions. | ||
| CVE-2026-81770 | Hig | 0.46 | 7.1 | 0.00 | Sep 2, 2026 | Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions. | ||
| CVE-2026-81769 | Hig | 0.57 | 8.8 | 0.00 | Sep 2, 2026 | Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1. | ||
| CVE-2026-81294 | Cri | 0.64 | 9.8 | 0.00 | Sep 2, 2026 | Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions. | ||
| CVE-2026-81289 | Hig | 0.46 | 7.1 | 0.00 | Sep 2, 2026 | Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions. | ||
| CVE-2026-81288 | Hig | 0.46 | 7.1 | 0.00 | Sep 2, 2026 | Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions. | ||
| CVE-2026-81286 | Cri | 0.60 | 9.3 | 0.00 | Sep 2, 2026 | Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions. | ||
| CVE-2026-81283 | Hig | 0.57 | 8.8 | 0.01 | Sep 2, 2026 | Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions. | ||
| CVE-2026-66652 | Med | 0.35 | 5.4 | 0.00 | Sep 2, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery. This issue affects Grand Tour: from n/a through 5.5.1. | ||
| CVE-2026-82958 | Hig | 0.42 | — | 0.00 | Sep 2, 2026 | In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a CreateThing command by substituting placeholder values (e.g. {{ header:device_id }}) resolved from inbound message headers into a pre-configured JSON "thing"… | ||
| CVE-2026-32773 | Med | 0.33 | 6.1 | 0.01 | Sep 2, 2026 | There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later. … | ||
| CVE-2026-19219 | Hig | 0.53 | 8.1 | 0.00 | Sep 2, 2026 | In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser… | ||
| CVE-2026-18672 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2026 | In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image… | ||
| CVE-2026-84175 | Med | 0.27 | — | 0.00 | Sep 2, 2026 | In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs supplied by API users in the definition field of a Thing or Feature, without validating the target host, and follows HTTP redirects without re-validating the… | ||
| CVE-2026-53683 | — | Med | 0.28 | 4.3 | 0.00 | Sep 2, 2026 | reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect… | |
| CVE-2026-75528 | Hig | 0.47 | 7.2 | 0.01 | Sep 2, 2026 | The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author URL / Link Log in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | ||
| CVE-2026-23591 | — | 0.00 | — | — | Sep 2, 2026 | Rejected reason: Withdrawn by requester. | ||
| CVE-2026-23590 | — | 0.00 | — | — | Sep 2, 2026 | Rejected reason: Withdrawn by requester. | ||
| CVE-2026-23589 | — | 0.00 | — | — | Sep 2, 2026 | Rejected reason: Withdrawn by requester. | ||
| CVE-2026-23588 | — | 0.00 | — | — | Sep 2, 2026 | Rejected reason: Withdrawn by requester. | ||
| CVE-2026-23587 | — | 0.00 | — | — | Sep 2, 2026 | Rejected reason: Withdrawn by requester. | ||
| CVE-2026-23586 | — | 0.00 | — | — | Sep 2, 2026 | Rejected reason: Withdrawn by requester. | ||
| CVE-2026-23585 | — | 0.00 | — | — | Sep 2, 2026 | Rejected reason: Withdrawn by requester. | ||
| CVE-2026-23584 | — | 0.00 | — | — | Sep 2, 2026 | Rejected reason: Withdrawn by requester. | ||
| CVE-2026-23583 | — | 0.00 | — | — | Sep 2, 2026 | Rejected reason: Withdrawn by requester. | ||
| CVE-2026-14828 | Hig | 0.57 | 8.8 | 0.01 | Sep 2, 2026 | Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability. | ||
| CVE-2025-7963 | Med | 0.42 | 6.4 | 0.00 | Sep 2, 2026 | The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer() function in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for… | ||
| CVE-2026-82883 | Hig | 0.46 | 7.1 | 0.00 | Sep 2, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS. This issue affects Login With Ajax: from n/a through 4.5.1. | ||
| CVE-2026-3850 | Med | 0.42 | 6.4 | 0.00 | Sep 2, 2026 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_contact_form` shortcode in all versions up to, and including, 4.27.6. This is due to the `redirect_url` attribute being sanitized with `esc_attr()` instead of… | ||
| CVE-2026-82183 | Hig | 0.53 | 8.1 | 0.00 | Sep 2, 2026 | The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts. | ||
| CVE-2026-82182 | Med | 0.27 | 4.1 | 0.00 | Sep 2, 2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied list of identifiers before using it in a SQL query, allowing administrators to perform SQL injection attacks. | ||
| CVE-2026-81807 | Hig | 0.57 | 8.8 | 0.01 | Sep 2, 2026 | The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and run scripts in the browser of anyone viewing the chat, including administrators. | ||
| CVE-2026-81737 | Hig | 0.57 | 8.8 | 0.00 | Sep 2, 2026 | The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in an admin area page, and the escaping it does apply is undone by a subsequent decoding step, leading to Stored XSS… | ||
| CVE-2026-81583 | Med | 0.35 | 5.4 | 0.00 | Sep 2, 2026 | The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and unauthenticated users on some networks, to create new sites and be granted… | ||
| CVE-2026-81432 | Med | 0.28 | 4.3 | 0.00 | Sep 2, 2026 | The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on some of its AJAX actions, allowing attackers to make a logged-in user with the edit_posts capability (Contributor and above) delete or modify custom widget skins via a crafted… | ||
| CVE-2026-81428 | Med | 0.42 | 6.5 | 0.00 | Sep 2, 2026 | The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownership or the object type of user-supplied IDs when saving product variations, allowing authenticated users with the vendor role to modify product variations belonging to other vendors, and to change the status… | ||
| CVE-2026-81427 | Med | 0.28 | 4.3 | 0.00 | Sep 2, 2026 | The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment status change owns the referenced order, allowing any authenticated vendor to mark another vendor's order as shipped, add an order note falsely attributed to the… | ||
| CVE-2026-81426 | Med | 0.28 | 4.3 | 0.00 | Sep 2, 2026 | The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order shipment status actions, which could allow attackers to make a logged-in vendor change the shipment status of their own orders via a crafted request. | ||
| CVE-2026-81199 | Med | 0.34 | 5.3 | 0.00 | Sep 2, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to disclose the course counts, points, certificates, quiz and assignment totals of… |
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions.
- risk 0.57cvss 8.8epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.
- risk 0.50cvss 8.8epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
- risk 0.39cvss 7.1epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.
- risk 0.35cvss 5.4epss 0.00
Missing Authorization vulnerability in Mamunur Rashid Classified Listing classified-listing allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Classified Listing: from n/a through 6.1.3.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.
- risk 0.57cvss 8.8epss 0.00
Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.
- risk 0.57cvss 8.8epss 0.00
Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.
- risk 0.57cvss 8.8epss 0.01
Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.
- risk 0.35cvss 5.4epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery. This issue affects Grand Tour: from n/a through 5.5.1.
- risk 0.42cvss —epss 0.00
In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a CreateThing command by substituting placeholder values (e.g. {{ header:device_id }}) resolved from inbound message headers into a pre-configured JSON "thing"…
- risk 0.33cvss 6.1epss 0.01
There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later. …
- risk 0.53cvss 8.1epss 0.00
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser…
- risk 0.49cvss 7.5epss 0.00
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image…
- risk 0.27cvss —epss 0.00
In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs supplied by API users in the definition field of a Thing or Feature, without validating the target host, and follows HTTP redirects without re-validating the…
- risk 0.28cvss 4.3epss 0.00
reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect…
- risk 0.47cvss 7.2epss 0.01
The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author URL / Link Log in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
- CVE-2026-23591Sep 2, 2026risk 0.00cvss —epss —
Rejected reason: Withdrawn by requester.
- CVE-2026-23590Sep 2, 2026risk 0.00cvss —epss —
Rejected reason: Withdrawn by requester.
- CVE-2026-23589Sep 2, 2026risk 0.00cvss —epss —
Rejected reason: Withdrawn by requester.
- CVE-2026-23588Sep 2, 2026risk 0.00cvss —epss —
Rejected reason: Withdrawn by requester.
- CVE-2026-23587Sep 2, 2026risk 0.00cvss —epss —
Rejected reason: Withdrawn by requester.
- CVE-2026-23586Sep 2, 2026risk 0.00cvss —epss —
Rejected reason: Withdrawn by requester.
- CVE-2026-23585Sep 2, 2026risk 0.00cvss —epss —
Rejected reason: Withdrawn by requester.
- CVE-2026-23584Sep 2, 2026risk 0.00cvss —epss —
Rejected reason: Withdrawn by requester.
- CVE-2026-23583Sep 2, 2026risk 0.00cvss —epss —
Rejected reason: Withdrawn by requester.
- risk 0.57cvss 8.8epss 0.01
Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.
- risk 0.42cvss 6.4epss 0.00
The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer() function in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for…
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS. This issue affects Login With Ajax: from n/a through 4.5.1.
- risk 0.42cvss 6.4epss 0.00
The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_contact_form` shortcode in all versions up to, and including, 4.27.6. This is due to the `redirect_url` attribute being sanitized with `esc_attr()` instead of…
- risk 0.53cvss 8.1epss 0.00
The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts.
- risk 0.27cvss 4.1epss 0.00
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied list of identifiers before using it in a SQL query, allowing administrators to perform SQL injection attacks.
- risk 0.57cvss 8.8epss 0.01
The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and run scripts in the browser of anyone viewing the chat, including administrators.
- risk 0.57cvss 8.8epss 0.00
The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in an admin area page, and the escaping it does apply is undone by a subsequent decoding step, leading to Stored XSS…
- risk 0.35cvss 5.4epss 0.00
The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and unauthenticated users on some networks, to create new sites and be granted…
- risk 0.28cvss 4.3epss 0.00
The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on some of its AJAX actions, allowing attackers to make a logged-in user with the edit_posts capability (Contributor and above) delete or modify custom widget skins via a crafted…
- risk 0.42cvss 6.5epss 0.00
The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownership or the object type of user-supplied IDs when saving product variations, allowing authenticated users with the vendor role to modify product variations belonging to other vendors, and to change the status…
- risk 0.28cvss 4.3epss 0.00
The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment status change owns the referenced order, allowing any authenticated vendor to mark another vendor's order as shipped, add an order note falsely attributed to the…
- risk 0.28cvss 4.3epss 0.00
The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order shipment status actions, which could allow attackers to make a logged-in vendor change the shipment status of their own orders via a crafted request.
- risk 0.34cvss 5.3epss 0.00
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to disclose the course counts, points, certificates, quiz and assignment totals of…