Vendor CVEs
WordPress
All CVEs
36,918 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-66437 | Med | 0.00 | 4.9 | 0.00 | Jul 27, 2026 | Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions. | ||
| CVE-2026-66434 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions. | ||
| CVE-2026-66433 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions. | ||
| CVE-2026-66428 | Med | 0.00 | 4.3 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions. | ||
| CVE-2026-66427 | Hig | 0.00 | 7.6 | 0.00 | Jul 27, 2026 | Administrator SQL Injection in WP Google Review Slider <= 18.4 versions. | ||
| CVE-2026-65568 | Med | 0.00 | 5.0 | 0.00 | Jul 27, 2026 | Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions. | ||
| CVE-2026-65567 | Med | 0.00 | 5.3 | 0.00 | Jul 27, 2026 | Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions. | ||
| CVE-2026-65564 | Med | 0.00 | 5.3 | 0.00 | Jul 27, 2026 | Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions. | ||
| CVE-2026-65563 | Med | 0.00 | 5.9 | 0.00 | Jul 27, 2026 | Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions. | ||
| CVE-2026-65562 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions. | ||
| CVE-2026-65561 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions. | ||
| CVE-2026-65558 | Med | 0.00 | 5.4 | 0.00 | Jul 27, 2026 | Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions. | ||
| CVE-2026-65557 | Med | 0.00 | 5.9 | 0.00 | Jul 27, 2026 | Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions. | ||
| CVE-2026-65436 | Med | 0.00 | 6.8 | 0.00 | Jul 27, 2026 | Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions. | ||
| CVE-2026-65435 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions. | ||
| CVE-2026-65434 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions. | ||
| CVE-2026-65433 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | ||
| CVE-2026-59560 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Subscriber Broken Access Control in FundEngine <= 1.7.8 versions. | ||
| CVE-2026-59559 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | ||
| CVE-2026-59558 | Hig | 0.00 | 7.1 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions. | ||
| CVE-2026-59557 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions. | ||
| CVE-2026-59556 | Hig | 0.00 | 7.1 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions. | ||
| CVE-2026-59553 | Hig | 0.00 | 7.1 | 0.00 | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions. | ||
| CVE-2026-59552 | Hig | 0.00 | 7.2 | 0.00 | Jul 27, 2026 | Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | ||
| CVE-2026-59551 | Hig | 0.00 | 8.5 | 0.00 | Jul 27, 2026 | Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | ||
| CVE-2026-59550 | Cri | 0.00 | 9.3 | 0.00 | Jul 27, 2026 | Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions. | ||
| CVE-2026-59549 | Cri | 0.00 | 9.3 | 0.00 | Jul 27, 2026 | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | ||
| CVE-2026-59548 | Hig | 0.00 | 7.5 | 0.00 | Jul 27, 2026 | Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions. | ||
| CVE-2026-59546 | Hig | 0.00 | 7.4 | 0.00 | Jul 27, 2026 | Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions. | ||
| CVE-2026-59539 | Hig | 0.00 | 7.5 | 0.00 | Jul 27, 2026 | Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions. | ||
| CVE-2026-59538 | Cri | 0.00 | 9.3 | 0.00 | Jul 27, 2026 | Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions. | ||
| CVE-2026-59537 | Hig | 0.00 | 7.6 | 0.00 | Jul 27, 2026 | Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions. | ||
| CVE-2026-59536 | Hig | 0.00 | 7.5 | 0.00 | Jul 27, 2026 | Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions. | ||
| CVE-2026-59535 | Hig | 0.00 | 7.3 | 0.00 | Jul 27, 2026 | Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions. | ||
| CVE-2026-59534 | Hig | 0.00 | 7.5 | 0.00 | Jul 27, 2026 | Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions. | ||
| CVE-2026-59533 | Cri | 0.00 | 9.3 | 0.00 | Jul 27, 2026 | Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions. | ||
| CVE-2026-59532 | Hig | 0.00 | 7.5 | 0.00 | Jul 27, 2026 | Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions. | ||
| CVE-2026-59531 | Hig | 0.00 | 7.5 | 0.00 | Jul 27, 2026 | Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions. | ||
| CVE-2026-59530 | Hig | 0.00 | 7.5 | 0.00 | Jul 27, 2026 | Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions. | ||
| CVE-2026-59529 | Hig | 0.00 | 7.5 | 0.00 | Jul 27, 2026 | Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions. | ||
| CVE-2026-59528 | Hig | 0.00 | 7.5 | 0.00 | Jul 27, 2026 | Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions. | ||
| CVE-2026-59527 | Cri | 0.00 | 9.3 | 0.00 | Jul 27, 2026 | Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | ||
| CVE-2026-9830 | Hig | 0.00 | 8.2 | 0.00 | Jul 27, 2026 | The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data… | ||
| CVE-2026-14827 | Med | 0.00 | 6.8 | 0.00 | Jul 27, 2026 | The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone… | ||
| CVE-2026-14820 | Med | 0.00 | 5.3 | 0.00 | Jul 27, 2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers… | ||
| CVE-2026-14568 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete… | ||
| CVE-2026-14289 | Cri | 0.00 | 9.0 | 0.00 | Jul 27, 2026 | The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write… | ||
| CVE-2026-14236 | Med | 0.00 | 4.7 | 0.00 | Jul 27, 2026 | The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an… | ||
| CVE-2026-14235 | Hig | 0.00 | 7.5 | 0.00 | Jul 27, 2026 | The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can… | ||
| CVE-2026-14203 | Med | 0.00 | 4.8 | 0.00 | Jul 27, 2026 | The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an… |
- risk 0.00cvss 4.9epss 0.00
Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.
- risk 0.00cvss 4.3epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
- risk 0.00cvss 7.6epss 0.00
Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.
- risk 0.00cvss 5.0epss 0.00
Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.
- risk 0.00cvss 5.9epss 0.00
Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
- risk 0.00cvss 5.4epss 0.00
Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.
- risk 0.00cvss 5.9epss 0.00
Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
- risk 0.00cvss 6.8epss 0.00
Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
- risk 0.00cvss 7.2epss 0.00
Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions.
- risk 0.00cvss 8.5epss 0.00
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.
- risk 0.00cvss 7.4epss 0.00
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
- risk 0.00cvss 7.5epss 0.00
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
- risk 0.00cvss 7.6epss 0.00
Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
- risk 0.00cvss 7.3epss 0.00
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
- risk 0.00cvss 7.5epss 0.00
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
- risk 0.00cvss 8.2epss 0.00
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data…
- risk 0.00cvss 6.8epss 0.00
The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone…
- risk 0.00cvss 5.3epss 0.00
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers…
- risk 0.00cvss 6.5epss 0.00
The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete…
- risk 0.00cvss 9.0epss 0.00
The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write…
- risk 0.00cvss 4.7epss 0.00
The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an…
- risk 0.00cvss 7.5epss 0.00
The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can…
- risk 0.00cvss 4.8epss 0.00
The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an…
Page 701 of 739