Total
396899 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-78362 | 2026-09-08 | N/A | 9.8 CRITICAL | ||
| The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, which is its normal operating state. | |||||
| CVE-2026-85146 | 2026-09-08 | N/A | 9.8 CRITICAL | ||
| SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code. | |||||
| CVE-2026-84225 | 2026-09-08 | N/A | 2.2 LOW | ||
| The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open. | |||||
| CVE-2026-84028 | 2026-09-08 | N/A | 6.8 MEDIUM | ||
| The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page. | |||||
| CVE-2026-19862 | 2026-09-08 | N/A | 4.8 MEDIUM | ||
| The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender. Exploitation requires the site to be configured to take one of the message's addresses from a form field. | |||||
| CVE-2026-85540 | 2026-09-08 | N/A | 8.8 HIGH | ||
| DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents. | |||||
| CVE-2026-84927 | 2026-09-08 | N/A | 2.7 LOW | ||
| The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly across the site. | |||||
| CVE-2026-84021 | 2026-09-08 | N/A | 6.8 MEDIUM | ||
| The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a filter that can be evaded, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user clicks the affected link. | |||||
| CVE-2026-77826 | 2026-09-08 | N/A | 8.8 HIGH | ||
| The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user registration is disabled. | |||||
| CVE-2026-13159 | 2026-09-08 | N/A | 4.3 MEDIUM | ||
| The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to install a fixed set of companion from the WordPress.org repository. Where the request runs in the session of a user who can activate , those are activated as well. | |||||
| CVE-2026-15247 | 2026-09-08 | N/A | 5.4 MEDIUM | ||
| The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials. | |||||
| CVE-2026-85541 | 2026-09-08 | N/A | 5.4 MEDIUM | ||
| DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website. | |||||
| CVE-2026-84926 | 2026-09-08 | N/A | 2.7 LOW | ||
| The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role. | |||||
| CVE-2026-19859 | 2026-09-08 | N/A | 6.5 MEDIUM | ||
| The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registered on the site on any page displaying a form. Escaping is applied to that content before a later shortcode-expansion pass rather than after it, so the escaping can be bypassed. | |||||
| CVE-2026-84745 | 2026-09-08 | N/A | 2.7 LOW | ||
| The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with a low-privilege role such as contributor to read the full contents of every unpublished record on the site, including other users'. | |||||
| CVE-2026-83543 | 2026-09-08 | N/A | 4.1 MEDIUM | ||
| The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the response. | |||||
| CVE-2025-15693 | 2026-09-08 | N/A | 2.7 LOW | ||
| The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and sub-site administrators on multisite, to enumerate directories and file names outside the web root. | |||||
| CVE-2026-84219 | 2026-09-08 | N/A | 7.5 HIGH | ||
| The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an administrator, and on every page of the site when its header or footer is built to show comments. | |||||
| CVE-2026-81348 | 2026-09-08 | N/A | 3.7 LOW | ||
| The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post content, comments and post URLs from a site the administrator placed behind mandatory login. | |||||
| CVE-2025-15694 | 2026-09-08 | N/A | 3.5 LOW | ||
| The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed, for example in a multisite setup. | |||||
