Filtered by vendor Wordpress
Subscriptions
Filtered by product Wordpress
Subscriptions
Total
15075 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66681 | 2 Jeff Farthing, Wordpress | 2 Theme My Login, Wordpress | 2026-08-07 | 4.3 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions. | ||||
| CVE-2026-66683 | 2 Wordpress, Wp Zone | 2 Wordpress, Custom Css And Javascript | 2026-08-07 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions. | ||||
| CVE-2026-66685 | 2 Alex, Wordpress | 2 Featured Video Plus, Wordpress | 2026-08-07 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions. | ||||
| CVE-2026-66686 | 2 Vladimir Garagulya, Wordpress | 2 Plugins Garbage Collector (database Cleanup), Wordpress | 2026-08-07 | 6.5 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions. | ||||
| CVE-2026-66696 | 2 Nexcess, Wordpress | 2 Gutenberg Blocks By Kadence Blocks, Wordpress | 2026-08-07 | 4.3 Medium |
| Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions. | ||||
| CVE-2026-15209 | 2 Jshelpdesk, Wordpress | 2 Jshelpdesk, Wordpress | 2026-08-07 | 6.5 Medium |
| The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body. | ||||
| CVE-2026-14817 | 2 Bdthemes, Wordpress | 2 Element Pack Addons For Elementor, Wordpress | 2026-08-07 | 6.8 Medium |
| The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level access or higher to inject arbitrary JavaScript that executes in the session of any visitor who views the affected content. | ||||
| CVE-2026-16540 | 2 Nsqua, Wordpress | 2 Simply Schedule Appointments, Wordpress | 2026-08-07 | 7.5 High |
| The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them. | ||||
| CVE-2026-16532 | 2 Link Library Project, Wordpress | 2 Link Library, Wordpress | 2026-08-07 | 9.1 Critical |
| The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-16968 | 2 Wordpress, Wpgeodirectory | 2 Wordpress, Geodirectory | 2026-08-07 | 6.5 Medium |
| The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators. | ||||
| CVE-2025-15677 | 2 Wordpress, Wpgeodirectory | 2 Wordpress, Geodirectory | 2026-08-07 | 3.5 Low |
| The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in a multisite setup). | ||||
| CVE-2026-15210 | 2 Glboy, Wordpress | 2 Otp Login With Phone Number, Otp Verification, Wordpress | 2026-08-07 | 9.1 Critical |
| The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's. | ||||
| CVE-2026-15372 | 2 Wordpress, Wp2fac | 2 Wordpress, Wp2fac | 2026-08-07 | 7.5 High |
| The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts. | ||||
| CVE-2026-16065 | 2 Welcart, Wordpress | 2 Welcart E-commerce, Wordpress | 2026-08-07 | 6.5 Medium |
| The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks. | ||||
| CVE-2026-12713 | 2 Arni Cinco, Wordpress | 2 Wpcargo Track & Trace, Wordpress | 2026-08-07 | 9.1 Critical |
| The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by CVE-2024-44004. | ||||
| CVE-2026-13153 | 2 Wordpress, Wpdevteam | 2 Wordpress, Gutenberg Essential Blocks | 2026-08-07 | 7.5 High |
| The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product. | ||||
| CVE-2026-13154 | 2 Wordpress, Wpdevteam | 2 Wordpress, Gutenberg Essential Blocks | 2026-08-07 | 7.5 High |
| The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public. | ||||
| CVE-2026-13703 | 2 Clogica, Wordpress | 2 Seo Redirection Plugin, Wordpress | 2026-08-07 | 5.4 Medium |
| The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any logged-in user such as a subscriber to read the site's configured 301 redirect rules, including their source and destination URLs. | ||||
| CVE-2026-28005 | 2 Kadencewp, Wordpress | 2 Kadence Woocommerce Email Designer, Wordpress | 2026-08-07 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. | ||||
| CVE-2026-28082 | 2 Crocoblock. Jetimpex Inc., Wordpress | 2 Jetreviews, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions. | ||||