Total
398466 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-17012 | 2026-08-26 | N/A | 5.3 MEDIUM | ||
| The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's. | |||||
| CVE-2026-15211 | 2026-08-26 | N/A | 5.9 MEDIUM | ||
| The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed on the WooCommerce order-received flow: it captures a client-supplied token and marks the order paid whenever the capture status is COMPLETED, without comparing the captured amount to the order total. This allows an attacker (unauthenticated where guest checkout is enabled) to substitute an approved, uncaptured PayPal order token and have an expensive order marked paid without paying its price. | |||||
| CVE-2026-13703 | 2026-08-26 | N/A | 5.4 MEDIUM | ||
| The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any logged-in user such as a subscriber to read the site's configured 301 redirect rules, including their source and destination URLs. | |||||
| CVE-2026-16953 | 2026-08-26 | N/A | 4.8 MEDIUM | ||
| The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action solely by a client-supplied session cookie value, so an unauthenticated attacker who obtains a victim's session identifier and file reference can delete that victim's uploaded files. | |||||
| CVE-2026-16036 | 2026-08-26 | N/A | 7.5 HIGH | ||
| The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the challenge, and take over the account, including administrator accounts. | |||||
| CVE-2026-15148 | 2026-08-26 | N/A | 5.3 MEDIUM | ||
| The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the merchant, including other users' bookings. | |||||
| CVE-2026-16619 | 2026-08-26 | N/A | 7.5 HIGH | ||
| The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login, allowing an attacker who already knows a user's password to guess the one-time code without limit and take over the account. | |||||
| CVE-2026-15210 | 2026-08-26 | N/A | 9.1 CRITICAL | ||
| The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's. | |||||
| CVE-2026-15230 | 2026-08-26 | N/A | 8.1 HIGH | ||
| The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon codes. | |||||
| CVE-2026-16297 | 2026-08-26 | N/A | 4.1 MEDIUM | ||
| The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment. | |||||
| CVE-2026-15149 | 2026-08-26 | N/A | 5.3 MEDIUM | ||
| The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a booking, and relies on client-controlled cart data, allowing unauthenticated users to create confirmed reservations for free or at an arbitrarily reduced price. | |||||
| CVE-2026-14860 | 2026-08-26 | N/A | 5.3 MEDIUM | ||
| The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing unauthenticated attackers to make the server issue requests to arbitrary hosts and read back responses that parse as RSS/XML. | |||||
| CVE-2026-16290 | 2026-08-26 | N/A | 5.3 MEDIUM | ||
| The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin before 6.0.0.0's member-visibility setting. | |||||
| CVE-2026-13399 | 2026-08-26 | N/A | 7.5 HIGH | ||
| The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments | |||||
| CVE-2026-16065 | 2026-08-26 | N/A | 6.5 MEDIUM | ||
| The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks. | |||||
| CVE-2026-16608 | 2026-08-26 | N/A | 5.3 MEDIUM | ||
| The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics. | |||||
| CVE-2026-16534 | 2026-08-26 | N/A | 9.1 CRITICAL | ||
| The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email. | |||||
| CVE-2026-16268 | 2026-08-26 | N/A | 8.2 HIGH | ||
| The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the server side, allowing unauthenticated attackers to make the site issue requests to arbitrary internal or external hosts. | |||||
| CVE-2026-16267 | 2026-08-26 | N/A | 8.1 HIGH | ||
| The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects. | |||||
| CVE-2026-12501 | 2026-08-26 | N/A | 5.3 MEDIUM | ||
| The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, nor that the paid amount matches the order total, before marking a booking as paid, allowing unauthenticated attackers to mark bookings as fully paid using a token payment made to an attacker-controlled account. | |||||
