Total
396138 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-82215 | 2026-09-11 | N/A | 5.9 MEDIUM | ||
| The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment notifications it receives before acting on them, allowing unauthenticated attackers who know the store's merchant identifier to mark arbitrary orders as paid, or to cancel or fail them. | |||||
| CVE-2026-74925 | 2026-09-11 | N/A | 7.2 HIGH | ||
| The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site. | |||||
| CVE-2026-83546 | 2026-09-11 | N/A | 6.8 MEDIUM | ||
| The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed. | |||||
| CVE-2026-89010 | 2026-09-11 | N/A | 9.8 CRITICAL | ||
| WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to the sync_server daemon on TCP port 13136. The daemon interpolates attacker-controlled filename input containing shell metacharacters into a shell command string via sprintf() and passes it to system() without sanitization, enabling root-level command execution on the device. | |||||
| CVE-2026-14565 | 2026-09-11 | N/A | 5.4 MEDIUM | ||
| The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated user such as a subscriber to store JavaScript that executes in the browser of visitors viewing the affected product. | |||||
| CVE-2026-14566 | 2026-09-11 | N/A | 4.3 MEDIUM | ||
| The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order, allowing any authenticated user such as a subscriber to tamper with the custom metadata of orders belonging to other customers. | |||||
| CVE-2026-87985 | 2026-09-11 | N/A | N/A | ||
| An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments. These arguments are not properly inspected, enabling a crafted allowlisted command to execute arbitrary code on the user's system without approval. | |||||
| CVE-2026-83545 | 2026-09-11 | N/A | 6.8 MEDIUM | ||
| The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes when the content is viewed. | |||||
| CVE-2026-82305 | 2026-09-11 | N/A | 5.3 MEDIUM | ||
| The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site. | |||||
| CVE-2026-86779 | 2026-09-11 | N/A | 2.7 LOW | ||
| The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above to permanently delete any chart on the site, including charts created by other users such as administrators. | |||||
| CVE-2026-86781 | 2026-09-11 | N/A | 5.3 MEDIUM | ||
| The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowing any authenticated user, including Subscribers, to download the site's TLS private key, certificates, and diagnostic logs. | |||||
| CVE-2026-86812 | 2026-09-11 | N/A | 6.5 MEDIUM | ||
| The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allowing unauthenticated users to disclose guest order information and to change the status of, or trash, any order. | |||||
| CVE-2026-85116 | 2026-09-11 | N/A | 6.5 MEDIUM | ||
| The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. | |||||
| CVE-2026-86809 | 2026-09-11 | N/A | 5.3 MEDIUM | ||
| The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment authority obtained from a different transaction. | |||||
| CVE-2026-85678 | 2026-09-11 | N/A | 6.8 MEDIUM | ||
| The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it inside a script tag on the front end, allowing users with contributor level access and above to store arbitrary JavaScript that will execute in the browser of anyone who views the post, including the editor or administrator who reviews it. | |||||
| CVE-2026-8301 | 2026-09-11 | N/A | 7.8 HIGH | ||
| Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: before 1.0.8. | |||||
| CVE-2026-14562 | 2026-09-11 | N/A | 5.3 MEDIUM | ||
| The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, allowing unauthenticated attackers to disclose other customers' order and attachment data. | |||||
| CVE-2026-8303 | 2026-09-11 | N/A | 7.8 HIGH | ||
| Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5. | |||||
| CVE-2026-85677 | 2026-09-11 | N/A | 8.8 HIGH | ||
| The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted comments, allowing unauthenticated users to store JavaScript that will execute in the browser of any administrator who reviews the comment queue, and of any visitor to the post once the comment is approved. | |||||
| CVE-2026-14559 | 2026-09-11 | N/A | 9.8 CRITICAL | ||
| The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address. | |||||
