Filtered by vendor Wordpress
Subscriptions
Total
15555 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16230 | 2 Strategy11, Wordpress | 2 Formidable Digital Signatures, Wordpress | 2026-08-13 | 9.8 Critical |
| The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled filename in the item_meta[field_id][content] parameter alongside the delete_saved_image flag during the standard entry-creation POST flow on any form that accepts anonymous submissions. | ||||
| CVE-2026-13457 | 2 Instawp, Wordpress | 2 Instawp Connect – 1-click Wp Staging & Migration, Wordpress | 2026-08-13 | 7.5 High |
| The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.1.3.6 via the (top-level script) function. This is due to the plugin stores its encrypted options file as options-{migrate_key}.txt in wp-content/instawpbackups/ without deploying an index.php or .htaccess to prevent directory listing, exposing the 40-character migrate_key on Apache servers with directory indexing enabled, which allows an attacker to derive the AES-256-CBC passphrase via SHA256(migrate_key), decrypt the options file to recover the api_signature. This makes it possible for unauthenticated attackers to get the database access details and api_signature. Exploitation requires the target WordPress site to be hosted on Apache with directory listing enabled (Options +Indexes) for the wp-content/instawpbackups/ directory, and time limited because it can only be exploited during the migration period. | ||||
| CVE-2026-18961 | 2 Fahdaslam, Wordpress | 2 Social Login, Passkeys, Magic Link & Email Otp – Passwordless Login By Ventraconnect, Wordpress | 2026-08-13 | 8.1 High |
| The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify's /v1/me endpoint as proof of mailbox ownership — Generic::normalize_common() copies this value into the normalized profile without requiring an email_verified assertion, and User_Links::link_or_login_user() subsequently passes it directly to get_user_by('email', $email) and issues a persistent authentication cookie via wp_set_auth_cookie() without a provider-specific verified-email gate, a local mailbox challenge, or a logged-in approval step. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including Administrators, by supplying a known target email address through a controlled Spotify OAuth flow, gaining full administrative access to the site. | ||||
| CVE-2026-3835 | 2 Buildwps, Wordpress | 2 Prevent Direct Access – Protect Wordpress Files, Wordpress | 2026-08-13 | 5.3 Medium |
| The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without escaping wildcard characters via `$wpdb->esc_like()`. This makes it possible for unauthenticated attackers to bypass the private token requirement by supplying SQL wildcard characters (such as `%`) as the token value, matching any record in the plugin's file table and downloading any protected file. | ||||
| CVE-2026-14211 | 2 Ameliabooking, Wordpress | 2 Booking For Appointments And Events Calendar, Wordpress | 2026-08-13 | 3.8 Low |
| The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers. | ||||
| CVE-2026-14548 | 2 Lingotek-translation, Wordpress | 2 Ray Enterprise Translation, Wordpress | 2026-08-13 | 6.5 Medium |
| The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to overwrite the administrator-configured translation API token with an arbitrary value. | ||||
| CVE-2026-14549 | 2 Lingotek-translation, Wordpress | 2 Ray Enterprise Translation, Wordpress | 2026-08-13 | 4.3 Medium |
| The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to add or delete the site's configured languages. | ||||
| CVE-2026-18789 | 2 Ezoic, Wordpress | 2 Ezoic, Wordpress | 2026-08-13 | 7.5 High |
| The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated attackers to trigger a server-side export of the site's database, including user password hashes and password reset tokens, as well as to persistently change some of its settings. | ||||
| CVE-2026-12976 | 2 Learnpress, Wordpress | 2 Learnpress, Wordpress | 2026-08-13 | 6.5 Medium |
| The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-assistant requests against that course's lesson content, allowing any authenticated user such as a subscriber to obtain material from paid courses they have not enrolled in. | ||||
| CVE-2026-13171 | 2 Eventin, Wordpress | 2 Eventin, Wordpress | 2026-08-12 | 8.2 High |
| The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordPress user accounts for arbitrary email addresses and inject order records. | ||||
| CVE-2026-13168 | 2 Eventin, Wordpress | 2 Eventin, Wordpress | 2026-08-12 | 6.5 Medium |
| The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users with contributor-level access and above to read other customers' personal data such as names and email addresses. | ||||
| CVE-2026-16747 | 2 Kirki, Wordpress | 2 Kirki, Wordpress | 2026-08-12 | 6.5 Medium |
| The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes attacker-controlled input through shortcode execution, allowing unauthenticated users to run any shortcode registered on the site, which on a default install leads to disclosure of the site administrator's email address and an arbitrary-recipient mail relay from the victim's domain. | ||||
| CVE-2026-65498 | 2 Complianz, Wordpress | 2 Complianz, Wordpress | 2026-08-12 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions. | ||||
| CVE-2026-29205 | 3 Cpanel, Webpros, Wordpress | 6 Cpanel, Whm, Wp Squared and 3 more | 2026-08-12 | 8.6 High |
| Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints. | ||||
| CVE-2026-19089 | 2 Tychesoftwares, Wordpress | 2 Product Input Fields For Woocommerce, Wordpress | 2026-08-12 | 9.8 Critical |
| The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on servers that do not honour the directory's access rules. | ||||
| CVE-2024-32532 | 2 Siteground, Wordpress | 2 Speed Optimizer, Wordpress | 2026-08-12 | 5.3 Medium |
| Missing Authorization vulnerability in SiteGround Speed Optimizer.This issue affects Speed Optimizer: from n/a through 7.4.6. | ||||
| CVE-2024-32518 | 1 Wordpress | 1 Wordpress | 2026-08-12 | 5.3 Medium |
| Missing Authorization vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ultimate Invoice: from n/a through 2.0.0. | ||||
| CVE-2026-66659 | 2 Essekia, Wordpress | 2 Tablesome Table, Wordpress | 2026-08-12 | 9.3 Critical |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection. This issue affects Tablesome Table: from n/a through 1.2.9. | ||||
| CVE-2026-15426 | 2 Acyba, Wordpress | 2 Acymailing – An Ultimate Newsletter Plugin And Marketing Automation Solution For Wordpress, Wordpress | 2026-08-12 | 8.8 High |
| The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.11.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the BCC field of the acy_notification_cms notification template, causing subsequent WordPress password-reset emails — including those targeting administrator accounts — to be silently copied to an attacker-controlled address, enabling account takeover via the captured reset link. Successful exploitation requires the site administrator to have enabled the "Send website emails with AcyMailing" option, which routes WordPress core notification emails through AcyMailing's templating system. | ||||
| CVE-2026-18988 | 2 Shapedplugin, Wordpress | 2 Easy Accordion – Ai-powered Faq & Accordion Blocks, Product Faq, Wordpress | 2026-08-12 | 6.4 Medium |
| The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block attribute in versions up to, and including, 3.1.8. This is due to insufficient input sanitization and output escaping in the accordion_header_renderer() function, which emits the attacker-supplied tag name using esc_attr() in an HTML tag-name context instead of tag_escape(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||