Total
398466 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-16590 | 2026-08-26 | N/A | 6.5 MEDIUM | ||
| The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to retrieve stored contact messages and associated user data belonging to other users. | |||||
| CVE-2026-17542 | 2026-08-26 | N/A | 7.5 HIGH | ||
| The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data. | |||||
| CVE-2026-15047 | 2026-08-26 | N/A | 6.8 MEDIUM | ||
| The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS). | |||||
| CVE-2026-17044 | 2026-08-26 | N/A | 8.6 HIGH | ||
| The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users. | |||||
| CVE-2026-3430 | 2026-08-26 | N/A | 8.6 HIGH | ||
| The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail. | |||||
| CVE-2026-18465 | 2026-08-26 | N/A | 6.5 MEDIUM | ||
| The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not properly validate a user-controlled path before using it in a file inclusion, allowing unauthenticated attackers to include and execute arbitrary existing local PHP files on the server. | |||||
| CVE-2026-12698 | 2026-08-26 | N/A | 4.3 MEDIUM | ||
| The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned account and forging their forum reputation score. | |||||
| CVE-2026-16030 | 2026-08-26 | N/A | 8.1 HIGH | ||
| The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts. | |||||
| CVE-2026-16940 | 2026-08-26 | N/A | 10.0 CRITICAL | ||
| The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover. | |||||
| CVE-2026-14314 | 2026-08-26 | N/A | 5.3 MEDIUM | ||
| The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated attackers to forge a token and disclose image attachments, including other customers' uploaded payment receipts, that they do not own. | |||||
| CVE-2026-17010 | 2026-08-26 | N/A | 5.4 MEDIUM | ||
| The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before outputting them, allowing users with contributor-level access and above to inject stored Cross-Site Scripting payloads that execute in the browser of a higher-privileged user who reviews the content. | |||||
| CVE-2026-17541 | 2026-08-26 | N/A | 7.5 HIGH | ||
| The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them. | |||||
| CVE-2026-18037 | 2026-08-26 | N/A | 6.5 MEDIUM | ||
| The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available. | |||||
| CVE-2026-15372 | 2026-08-26 | N/A | 7.5 HIGH | ||
| The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts. | |||||
| CVE-2026-16539 | 2026-08-26 | N/A | 8.1 HIGH | ||
| The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating a page, allowing users with the Editor role and above to perform SQL Injection attacks. | |||||
| CVE-2026-13170 | 2026-08-26 | N/A | 7.2 HIGH | ||
| The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files. | |||||
| CVE-2026-17014 | 2026-08-26 | N/A | 5.3 MEDIUM | ||
| The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores. | |||||
| CVE-2026-12713 | 2026-08-26 | N/A | 9.1 CRITICAL | ||
| The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by CVE-2024-44004. | |||||
| CVE-2026-10599 | 2026-08-26 | N/A | 7.5 HIGH | ||
| The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark arbitrary orders as paid and bypass payment. | |||||
| CVE-2026-17540 | 2026-08-26 | N/A | 8.8 HIGH | ||
| The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service. | |||||
