Filtered by vendor Wordpress Subscriptions
Filtered by product Wordpress Subscriptions
Total 15000 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-15678 2 Posimyth, Wordpress 2 Nexter Blocks, Wordpress 2026-08-07 6.1 Medium
The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Author by default), allowing them to upload a file containing malicious JavaScript that executes when the file is accessed, leading to Stored Cross-Site Scripting.
CVE-2026-14204 2 Ivan, Wordpress 2 Google Authenticator Wordpress, Wordpress 2026-08-07 6.5 Medium
The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out of their account.
CVE-2026-5391 2 Latepoint, Wordpress 2 Appointment Booking Plugin – Latepoint | Calendar & Scheduling For Wordpress, Wordpress 2026-08-07 6.4 Medium
The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' shortcode in all versions up to, and including, 5.3.2. This is due to insufficient input sanitization and output escaping in the 'locations' branch of the 'shortcode_latepoint_resources' function. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2025-9266 2 Themegrill, Wordpress 2 Accelerate, Wordpress 2026-08-07 4.3 Medium
The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enqueue_scripts() function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate the ThemeGrill Demo Importer plugin.
CVE-2026-28141 2 Syed Balkhi, Wordpress 2 Nextgen Gallery, Wordpress 2026-08-07 7.1 High
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
CVE-2026-28172 2 Data443 Risk Mitigation, Inc., Wordpress 2 Tracking Code Manager, Wordpress 2026-08-07 7.1 High
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
CVE-2026-28177 2 Daniel Iser, Wordpress 2 Popup Maker, Wordpress 2026-08-07 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
CVE-2026-28179 2 Damian Góra, Wordpress 2 Fibosearch, Wordpress 2026-08-07 5.9 Medium
Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
CVE-2026-32469 2 Wordpress, Wpkube 2 Wordpress, Captcha 4wp 2026-08-07 5.3 Medium
Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
CVE-2026-65504 2 Ivanbebek, Wordpress 2 Box Now Delivery Croatia, Wordpress 2026-08-07 7.5 High
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
CVE-2026-65517 2 Scott Paterson, Wordpress 2 Easy Paypal Buy Now Button, Wordpress 2026-08-07 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.
CVE-2026-65523 2 Approveme, Wordpress 2 Formidable Forms Signature Online Contract Automation, Wordpress 2026-08-07 7.5 High
Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.
CVE-2026-65541 2 Solutioned, Wordpress 2 Staff Training, Wordpress 2026-08-07 7.3 High
Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
CVE-2026-65542 2 Rajat Varlani, Wordpress 2 Super Socializer, Wordpress 2026-08-07 8.8 High
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
CVE-2026-65543 2 Vimeodev, Wordpress 2 Vimeo, Wordpress 2026-08-07 7.5 High
Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
CVE-2026-65544 2 Rajat Varlani, Wordpress 2 Super Socializer, Wordpress 2026-08-07 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.
CVE-2026-65546 2 Qode, Wordpress 2 Qode Tours, Wordpress 2026-08-07 9.3 Critical
Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.
CVE-2026-65553 2 Wbolt.com, Wordpress 2 Spider Analyser – Wordpress搜索引擎蜘蛛分析插件, Wordpress 2026-08-07 10 Critical
Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
CVE-2026-65554 2 Lattepress, Wordpress 2 Anspress – Question And Answer, Wordpress 2026-08-07 7.1 High
Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.
CVE-2026-65556 2 Mihche, Wordpress 2 Wpbruiser {no- Captcha Anti-spam}, Wordpress 2026-08-07 9.8 Critical
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.