Filtered by vendor Wordpress
Subscriptions
Filtered by product Wordpress
Subscriptions
Total
15000 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-15678 | 2 Posimyth, Wordpress | 2 Nexter Blocks, Wordpress | 2026-08-07 | 6.1 Medium |
| The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Author by default), allowing them to upload a file containing malicious JavaScript that executes when the file is accessed, leading to Stored Cross-Site Scripting. | ||||
| CVE-2026-14204 | 2 Ivan, Wordpress | 2 Google Authenticator Wordpress, Wordpress | 2026-08-07 | 6.5 Medium |
| The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out of their account. | ||||
| CVE-2026-5391 | 2 Latepoint, Wordpress | 2 Appointment Booking Plugin – Latepoint | Calendar & Scheduling For Wordpress, Wordpress | 2026-08-07 | 6.4 Medium |
| The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' shortcode in all versions up to, and including, 5.3.2. This is due to insufficient input sanitization and output escaping in the 'locations' branch of the 'shortcode_latepoint_resources' function. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2025-9266 | 2 Themegrill, Wordpress | 2 Accelerate, Wordpress | 2026-08-07 | 4.3 Medium |
| The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enqueue_scripts() function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate the ThemeGrill Demo Importer plugin. | ||||
| CVE-2026-28141 | 2 Syed Balkhi, Wordpress | 2 Nextgen Gallery, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions. | ||||
| CVE-2026-28172 | 2 Data443 Risk Mitigation, Inc., Wordpress | 2 Tracking Code Manager, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions. | ||||
| CVE-2026-28177 | 2 Daniel Iser, Wordpress | 2 Popup Maker, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions. | ||||
| CVE-2026-28179 | 2 Damian Góra, Wordpress | 2 Fibosearch, Wordpress | 2026-08-07 | 5.9 Medium |
| Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions. | ||||
| CVE-2026-32469 | 2 Wordpress, Wpkube | 2 Wordpress, Captcha 4wp | 2026-08-07 | 5.3 Medium |
| Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions. | ||||
| CVE-2026-65504 | 2 Ivanbebek, Wordpress | 2 Box Now Delivery Croatia, Wordpress | 2026-08-07 | 7.5 High |
| Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions. | ||||
| CVE-2026-65517 | 2 Scott Paterson, Wordpress | 2 Easy Paypal Buy Now Button, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions. | ||||
| CVE-2026-65523 | 2 Approveme, Wordpress | 2 Formidable Forms Signature Online Contract Automation, Wordpress | 2026-08-07 | 7.5 High |
| Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions. | ||||
| CVE-2026-65541 | 2 Solutioned, Wordpress | 2 Staff Training, Wordpress | 2026-08-07 | 7.3 High |
| Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions. | ||||
| CVE-2026-65542 | 2 Rajat Varlani, Wordpress | 2 Super Socializer, Wordpress | 2026-08-07 | 8.8 High |
| Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions. | ||||
| CVE-2026-65543 | 2 Vimeodev, Wordpress | 2 Vimeo, Wordpress | 2026-08-07 | 7.5 High |
| Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions. | ||||
| CVE-2026-65544 | 2 Rajat Varlani, Wordpress | 2 Super Socializer, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions. | ||||
| CVE-2026-65546 | 2 Qode, Wordpress | 2 Qode Tours, Wordpress | 2026-08-07 | 9.3 Critical |
| Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions. | ||||
| CVE-2026-65553 | 2 Wbolt.com, Wordpress | 2 Spider Analyser – Wordpress搜索引擎蜘蛛分析插件, Wordpress | 2026-08-07 | 10 Critical |
| Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions. | ||||
| CVE-2026-65554 | 2 Lattepress, Wordpress | 2 Anspress – Question And Answer, Wordpress | 2026-08-07 | 7.1 High |
| Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions. | ||||
| CVE-2026-65556 | 2 Mihche, Wordpress | 2 Wpbruiser {no- Captcha Anti-spam}, Wordpress | 2026-08-07 | 9.8 Critical |
| Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. | ||||