Total
9903 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-65007 | 2026-07-23 | N/A | 9.6 CRITICAL | ||
| The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the account-management ACL runs and authorizes the caller on only the admin.login permission (the baseline permission held by every panel user). This allows any user with admin.login to mint a persistent API key bound to any account, and the forged key inherits the target account's API permissions. On installs where an API-enabled account holds broader permissions, this enables account impersonation and privilege escalation up to account takeover. | |||||
| CVE-2026-61973 | 2026-07-23 | N/A | 4.3 MEDIUM | ||
| Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions. | |||||
| CVE-2026-61972 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions. | |||||
| CVE-2026-61943 | 2026-07-23 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions. | |||||
| CVE-2026-27355 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions. | |||||
| CVE-2026-12082 | 2026-07-23 | N/A | 7.5 HIGH | ||
| The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data. | |||||
| CVE-2026-15827 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/gutenkit/v1/mailchimp/get/lists and /wp-json/gutenkit/v1/mailchimp/get/interests REST API endpoints in versions up to, and including, 2.4.12. Both endpoints are registered with permission_callback => '__return_true', and their callbacks read the site's stored Mailchimp API key from the gutenkit_settings_list option and proxy Mailchimp audience/list, merge-field, interest-category, interest-name, and subscriber-count metadata back to the caller with no login, nonce, or capability check. This makes it possible for unauthenticated attackers to retrieve private Mailchimp audience configuration information from any site that has configured the GutenKit Mailchimp integration. | |||||
| CVE-2026-15015 | 2026-07-23 | N/A | 9.8 CRITICAL | ||
| The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain an administrator-bound OAuth Bearer token via a self-registered client, granting full administrator-equivalent access to the plugin's MCP tool surface and all exposed WordPress content, users, and options. This is exploitable by combining the publicly accessible Dynamic Client Registration endpoint, which allows unauthenticated callers to register arbitrary OAuth clients with an attacker-controlled redirect_uri, with the unprotected authorization endpoint to complete the full OAuth flow without any administrator interaction. | |||||
| CVE-2026-65529 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions. | |||||
| CVE-2026-65500 | 2026-07-23 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. | |||||
| CVE-2026-65495 | 2026-07-23 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions. | |||||
| CVE-2026-65489 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions. | |||||
| CVE-2026-65476 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Civi <= 2.2.4 versions. | |||||
| CVE-2026-65469 | 2026-07-23 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions. | |||||
| CVE-2026-65457 | 2026-07-23 | N/A | 4.3 MEDIUM | ||
| Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions. | |||||
| CVE-2026-61954 | 2026-07-23 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions. | |||||
| CVE-2026-57703 | 2026-07-23 | N/A | 6.3 MEDIUM | ||
| Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions. | |||||
| CVE-2026-57425 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions. | |||||
| CVE-2026-57367 | 2026-07-23 | N/A | 7.1 HIGH | ||
| Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions. | |||||
| CVE-2026-27423 | 2026-07-23 | N/A | 4.3 MEDIUM | ||
| Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions. | |||||
