Total
397972 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-78139 | 2026-08-28 | N/A | 4.3 MEDIUM | ||
| The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modified on one of its REST endpoints in all versions up to, and including, 3.1.3, allowing authenticated attackers with Subscriber-level access to unsubscribe arbitrary customers from product stock-alert notifications. | |||||
| CVE-2026-78137 | 2026-08-28 | N/A | 7.5 HIGH | ||
| The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout total when the BOGO offer feature is enabled. | |||||
| CVE-2026-19092 | 2026-08-28 | N/A | 9.8 CRITICAL | ||
| The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output. | |||||
| CVE-2026-16569 | 2026-08-28 | N/A | 4.3 MEDIUM | ||
| The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock quantity of arbitrary products. | |||||
| CVE-2026-78333 | 2026-08-28 | N/A | 8.8 HIGH | ||
| The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as admin. | |||||
| CVE-2026-19084 | 2026-08-28 | N/A | 7.5 HIGH | ||
| The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL. | |||||
| CVE-2026-19715 | 2026-08-28 | N/A | 7.5 HIGH | ||
| The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing unauthenticated users to read the OAuth tokens and authorisation codes it has issued as well as user records including password hashes when debug logging is enabled. | |||||
| CVE-2026-13415 | 2026-08-28 | N/A | 7.2 HIGH | ||
| The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administrator. | |||||
| CVE-2026-13416 | 2026-08-28 | N/A | 3.5 LOW | ||
| The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to inject arbitrary web scripts that execute when a visitor views the page. | |||||
| CVE-2026-19454 | 2026-08-28 | N/A | 4.4 MEDIUM | ||
| The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network, including every site's data and the shared webroot. | |||||
| CVE-2026-19423 | 2026-08-28 | N/A | 8.1 HIGH | ||
| The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form permits, and screens the value against the site's registered role names rather than against the form's own allow-list, allowing unauthenticated users who register through the Ultimate Member WordPress plugin before 2.13.0's own form to grant themselves arbitrary capabilities and reach administrator-equivalent access. | |||||
| CVE-2026-16568 | 2026-08-28 | N/A | 4.3 MEDIUM | ||
| The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not verify that the requesting user owns the customer profile being queried through one of its REST endpoints, allowing any authenticated user (e.g. a customer/subscriber) to retrieve other users' personal data, including their email address, name, and roles. | |||||
| CVE-2026-77017 | 2026-08-28 | N/A | 7.7 HIGH | ||
| The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed directory before serving it, allowing users with a role as low as subscriber to read arbitrary files on the server, including its configuration file and authentication secrets. | |||||
| CVE-2026-77016 | 2026-08-28 | N/A | 9.6 CRITICAL | ||
| The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored file path before deleting it, allowing users with a role as low as subscriber to delete arbitrary files on the server. | |||||
| CVE-2026-78125 | 2026-08-28 | N/A | 5.3 MEDIUM | ||
| The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in all versions up to, and including, 4.0.2, allowing unauthenticated attackers to disclose the payment status of arbitrary orders by enumerating order identifiers. | |||||
| CVE-2026-13414 | 2026-08-28 | N/A | 4.8 MEDIUM | ||
| The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain (and exposed to anonymous visitors on others), allowing unauthenticated attackers to disable the site's maintenance/coming-soon mode under a non-default countdown configuration. | |||||
| CVE-2026-19225 | 2026-08-28 | N/A | 6.6 MEDIUM | ||
| The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network. | |||||
| CVE-2026-19223 | 2026-08-28 | N/A | 7.2 HIGH | ||
| The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network. | |||||
| CVE-2026-57909 | 2026-08-28 | N/A | N/A | ||
| A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system. | |||||
| CVE-2026-77018 | 2026-08-28 | N/A | 8.8 HIGH | ||
| The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory, allowing users with a role as low as subscriber to upload arbitrary files and achieve remote code execution. | |||||
