VYPR

Vendor CVEs

WordPress

All CVEs

36,919 total · sorted by risk
  • CVE-2006-6937Jan 17, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in displaypic.asp in Xtreme ASP Photo Gallery allows remote attackers to inject arbitrary SQL commands via the sortorder parameter.

  • CVE-2006-1694Apr 11, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in members.php in XBrite Members 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2006-0733Feb 16, 2006
    risk 0.03cvss epss 0.05

    Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the "author's website" field. NOTE: followup comments to the researcher's web log suggest…

  • CVE-2021-4428LowJul 18, 2023
    risk 0.01cvss 2.7epss 0.16

    A vulnerability has been found in what3words Autosuggest Plugin up to 4.0.0 on WordPress and classified as problematic. Affected by this vulnerability is the function enqueue_scripts of the file w3w-autosuggest/public/class-w3w-autosuggest-public.php of the component Setting…

  • CVE-2021-24666CriSep 27, 2021
    risk 0.01cvss 9.8epss 0.09

    The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P[\d]+), takes an 'id' and 'category' parameters as arguments. Both parameters can be used for…

  • CVE-2020-28037CriNov 2, 2020
    risk 0.01cvss 9.8epss 0.08

    is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old…

  • CVE-2020-28032CriNov 2, 2020
    risk 0.01cvss 9.8epss 0.16

    WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

  • CVE-2019-6112MedAug 14, 2020
    risk 0.01cvss 6.1epss 0.09

    A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the keyword parameter (aka $search_term or the Search field).

  • CVE-2018-14028HigAug 10, 2018
    risk 0.01cvss 7.2epss 0.15

    In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP file is uploaded, the plugin extraction fails, but the PHP file remains in a predictable wp-content/uploads location, allowing for an…

  • CVE-2015-2807Sep 1, 2015
    risk 0.01cvss epss 0.07

    Cross-site scripting (XSS) vulnerability in js/window.php in the Navis DocumentCloud plugin before 0.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wpbase parameter.

  • CVE-2014-8799Nov 28, 2014
    risk 0.01cvss epss 0.68

    Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter to lib/dp_image.php.

  • CVE-2014-4725Jul 27, 2014
    risk 0.01cvss epss 0.60

    The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in…

  • CVE-2026-77790Aug 26, 2026
    risk 0.00cvss epss 0.00

    The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.

  • CVE-2026-16646Aug 25, 2026
    risk 0.00cvss epss 0.00

    Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.

  • CVE-2026-16640Aug 25, 2026
    risk 0.00cvss epss 0.00

    Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete versions: from 0.0.0 to 1.12.0.

  • CVE-2026-15916Aug 25, 2026
    risk 0.00cvss epss 0.00

    Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.

  • CVE-2026-16249Aug 24, 2026
    risk 0.00cvss epss

    Rejected reason: This CVE ID is a duplicate of CVE-2026-15303 and was never published. Both IDs were assigned to the same vulnerability in the 6Storage Rentals WordPress plugin. All CVE users should reference CVE-2026-15303 instead of this ID.

  • CVE-2026-13598Aug 23, 2026
    risk 0.00cvss epss 0.00

    The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full site takeover.

  • CVE-2026-73189Aug 18, 2026
    risk 0.00cvss epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-14858

  • CVE-2026-73188Aug 13, 2026
    risk 0.00cvss epss

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-13610.

  • CVE-2026-28183Aug 6, 2026
    risk 0.00cvss epss

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-5582MedJul 30, 2026
    risk 0.00cvss 4.3epss 0.00

    The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24.2. This is due to missing nonce verification on the toggle_sync_status() function. This makes it possible for unauthenticated attackers to toggle the status…

  • CVE-2026-15397HigJul 30, 2026
    risk 0.00cvss 7.2epss 0.00

    The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration…

  • CVE-2026-15382MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a…

  • CVE-2026-15257MedJul 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users' form submissions and the profile fields of the associated…

  • CVE-2026-15255MedJul 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users' form…

  • CVE-2026-15252MedJul 30, 2026
    risk 0.00cvss 5.4epss 0.00

    The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX handlers, allowing any authenticated user such as a Subscriber to invoke the site's Google Indexing API integration, submitting or removing the site's URLs from…

  • CVE-2026-15250MedJul 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and…

  • CVE-2026-15240HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowing a lower-privileged account that an operator is currently switched into to be resolved as that operator and to switch into any…

  • CVE-2026-15235MedJul 30, 2026
    risk 0.00cvss 4.3epss 0.00

    The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking's full customer details in one of its AJAX actions, allowing any authenticated user with a low-privileged account (Subscriber and above) to read the personal…

  • CVE-2026-15153MedJul 30, 2026
    risk 0.00cvss 6.8epss 0.00

    The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a SQL query, allowing users holding the WP Hotel Booking WordPress plugin before 2.3.2's booking-management roles to perform SQL…

  • CVE-2026-15054LowJul 30, 2026
    risk 0.00cvss 3.7epss 0.00

    The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries to, and fire the configured workflows (such as email notifications) of forms the site owner has…

  • CVE-2026-14923MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the…

  • CVE-2026-14602CriJul 30, 2026
    risk 0.00cvss 9.0epss 0.01

    The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget chain is present through…

  • CVE-2026-14592MedJul 30, 2026
    risk 0.00cvss 6.1epss 0.00

    The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks before storing one of its option values, and does not escape that value on output on its settings page, allowing unauthenticated users to store arbitrary JavaScript…

  • CVE-2026-14318MedJul 30, 2026
    risk 0.00cvss 6.8epss 0.00

    The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an HTML attribute, allowing users with the GiveWP Worker role and above to inject arbitrary web scripts that execute on the public donation form viewed by any…

  • CVE-2026-14310MedJul 30, 2026
    risk 0.00cvss 5.4epss 0.00

    The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread belongs to before returning or writing to that thread, allowing authenticated users with subscriber-level access and above who can access any single course to…

  • CVE-2026-14305MedJul 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to modify limited post metadata (a like counter and an associated identifier list) on arbitrary posts, including inflating the…

  • CVE-2026-14239HigJul 30, 2026
    risk 0.00cvss 7.1epss 0.00

    The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken from a request parameter, and does not escape that label when echoing it on the filter admin page, allowing an unauthenticated attacker to trick a logged-in…

  • CVE-2026-14231MedJul 30, 2026
    risk 0.00cvss 4.3epss 0.00

    The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX handlers, only verifying that the user is logged in, allowing any authenticated user with subscriber-level access to read the titles of internal post types such as…

  • CVE-2026-14207MedJul 30, 2026
    risk 0.00cvss 6.1epss 0.00

    The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field before storing and rendering it, allowing users with a course-editing role to inject JavaScript that executes in the session of an administrator who views the…

  • CVE-2026-13395HigJul 30, 2026
    risk 0.00cvss 8.6epss 0.00

    The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL…

  • CVE-2026-13345MedJul 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price, and SKU of draft,…

  • CVE-2026-13344MedJul 30, 2026
    risk 0.00cvss 4.8epss 0.00

    The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site…

  • CVE-2026-13330MedJul 30, 2026
    risk 0.00cvss 6.1epss 0.00

    The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with the upload_files capability (Author and above) to upload files containing malicious JavaScript,…

  • CVE-2026-13178HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.

  • CVE-2026-13145MedJul 30, 2026
    risk 0.00cvss 4.3epss 0.00

    The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address information, by supplying an…

  • CVE-2026-13143MedJul 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips an arbitrary pending booking to a paid…

  • CVE-2026-12687HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's configured role, up…

  • CVE-2026-12500HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before…

Page 698 of 739