Filtered by vendor Wordpress
Subscriptions
Filtered by product Wordpress
Subscriptions
Total
15003 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-12713 | 2 Arni Cinco, Wordpress | 2 Wpcargo Track & Trace, Wordpress | 2026-08-07 | 9.1 Critical |
| The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by CVE-2024-44004. | ||||
| CVE-2026-13153 | 2 Wordpress, Wpdevteam | 2 Wordpress, Gutenberg Essential Blocks | 2026-08-07 | 7.5 High |
| The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product. | ||||
| CVE-2026-13154 | 2 Wordpress, Wpdevteam | 2 Wordpress, Gutenberg Essential Blocks | 2026-08-07 | 7.5 High |
| The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public. | ||||
| CVE-2026-13703 | 2 Clogica, Wordpress | 2 Seo Redirection Plugin, Wordpress | 2026-08-07 | 5.4 Medium |
| The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any logged-in user such as a subscriber to read the site's configured 301 redirect rules, including their source and destination URLs. | ||||
| CVE-2026-28005 | 2 Kadencewp, Wordpress | 2 Kadence Woocommerce Email Designer, Wordpress | 2026-08-07 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. | ||||
| CVE-2026-28082 | 2 Crocoblock. Jetimpex Inc., Wordpress | 2 Jetreviews, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions. | ||||
| CVE-2026-28111 | 2 Wordpress, Wpmudev | 2 Wordpress, Forminator Forms | 2026-08-07 | 8.8 High |
| Contributor Privilege Escalation in Forminator <= 1.56.0 versions. | ||||
| CVE-2026-28139 | 2 Wordpress, Wp-dreams | 2 Wordpress, Ajax Search | 2026-08-07 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. | ||||
| CVE-2026-5158 | 2 Wordpress, Wpxpo | 2 Wordpress, Postx - Gutenberg Blocks For Post Grid | 2026-08-07 | 6.4 Medium |
| The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inputPlaceHolder' parameter in all versions up to, and including, 5.0.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-25403 | 2 Bdthemes, Wordpress | 2 Utlimate Store Kit Elementor Addons, Wordpress | 2026-08-06 | 6.5 Medium |
| Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | ||||
| CVE-2026-28140 | 2 Jetmonsters, Wordpress | 2 Jetformbuilder, Wordpress | 2026-08-06 | 7.5 High |
| Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions. | ||||
| CVE-2026-65548 | 2 Muffingroup, Wordpress | 2 Betheme, Wordpress | 2026-08-06 | 9.9 Critical |
| Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions. | ||||
| CVE-2026-65507 | 2 Sergey, Wordpress | 2 Aiwu, Wordpress | 2026-08-06 | 9.8 Critical |
| Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions. | ||||
| CVE-2026-61963 | 2 Davidlingren, Wordpress | 2 Media Library Assistant, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions. | ||||
| CVE-2026-66451 | 2 Arraytics, Wordpress | 2 Wp Event Solution, Wordpress | 2026-08-06 | 6.5 Medium |
| Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions. | ||||
| CVE-2026-66706 | 2 Markjaquith, Wordpress | 2 Subscribe To Comments, Wordpress | 2026-08-06 | 5.9 Medium |
| Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions. | ||||
| CVE-2026-66663 | 2 Passionate Programmer Peter, Wordpress | 2 Wp Data Access, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. | ||||
| CVE-2026-66690 | 2 Nexcess, Wordpress | 2 Givewp, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions. | ||||
| CVE-2026-66699 | 2 Dokan, Wordpress | 2 Dokan, Wordpress | 2026-08-06 | 5.3 Medium |
| Custom role Broken Access Control in Dokan <= 5.0.10 versions. | ||||
| CVE-2026-18501 | 2 Stiofansisland, Wordpress | 2 Userswp – Front-end Login Form, User Registration, User Profile & Members Directory Plugin For Wp, Wordpress | 2026-08-06 | 6.4 Medium |
| The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Badge Widget Variable Substitution in all versions up to, and including, 1.2.69 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||