Filtered by vendor Wordpress
Subscriptions
Filtered by product Wordpress
Subscriptions
Total
14915 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-18464 | 2 Wordpress, Wp Maps Pro | 2 Wordpress, Wp Maps Pro | 2026-08-10 | 7.5 High |
| The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service. | ||||
| CVE-2026-17022 | 2 Salonbookingsystem, Wordpress | 2 Salon Booking System, Wordpress | 2026-08-10 | 7.5 High |
| The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier. | ||||
| CVE-2026-16535 | 2 Link Library Project, Wordpress | 2 Link Library, Wordpress | 2026-08-10 | 6.1 Medium |
| The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who can be tricked into performing an action. | ||||
| CVE-2026-14224 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-08-10 | 5.4 Medium |
| The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment's edit form. A subscriber-level user with an appointment of their own can therefore reuse that nonce to overwrite the customer metadata (email, name, phone, description) of another user's appointment. Because the Easy Appointments WordPress plugin before 3.12.28 then treats that metadata as the appointment's contact data, a subsequent administrator status change with customer notifications enabled delivers the victim's appointment notification to the attacker-controlled email address. | ||||
| CVE-2026-14221 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-08-10 | 3.8 Low |
| The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and delete bookings. | ||||
| CVE-2026-14188 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-08-10 | 2.7 Low |
| The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information. | ||||
| CVE-2026-13692 | 2 Payu, Wordpress | 2 Payu Commercepro Plugin, Wordpress | 2026-08-10 | 5.3 Medium |
| The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders. | ||||
| CVE-2026-14223 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-08-10 | 4.3 Medium |
| The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier. | ||||
| CVE-2026-14222 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-08-10 | 3.8 Low |
| The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system. | ||||
| CVE-2026-48093 | 2 Davidartiss, Wordpress | 2 Code Embed, Wordpress | 2026-08-10 | 6.5 Medium |
| The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the external URL embed feature in post content. The vulnerable code scans rendered content for URL embed tokens, fetches the remote URL, and inserts the remote response body into the page without output sanitization or an `unfiltered_html` capability check. This allows a Contributor attacker to submit a pending post containing an inert-looking URL token that executes attacker-controlled JavaScript when an Administrator or Editor previews or reviews the post. This is distinct from CVE-2026-2512, which affected custom field meta values up to version 2.5.1. This vector affects version 2.6 and uses the documented external URL embed feature in post content. This particular issue is patched in version 2.6.1. | ||||
| CVE-2026-18933 | 2 Wordpress, Wpdownloadmanager | 2 Wordpress, Download Manager | 2026-08-10 | 7.2 High |
| The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no wp_check_filetype_and_ext, no validate_file, and no extension blocklist exist anywhere in the upload handler. | ||||
| CVE-2026-15238 | 2 Motopress Hotel Booking, Wordpress | 2 Motopress Hotel Booking, Wordpress | 2026-08-10 | N/A |
| The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier. | ||||
| CVE-2026-18030 | 2 Bricksforge, Wordpress | 2 Bricksforge, Wordpress | 2026-08-10 | N/A |
| The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one of its form actions, allowing unauthenticated attackers to set an arbitrary password for any user, including administrators, and take over their account. Exploitation requires the site to have a form using the BricksForge WordPress plugin before 3.1.8.8's password reset action in its update mode. The server-side current-password verification option for that action is disabled by default, so the vulnerable state is the default one once the action is used. | ||||
| CVE-2026-14226 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-08-10 | 4.3 Medium |
| The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookings on the site, including customer names, schedules, and statuses. | ||||
| CVE-2026-12971 | 2 Learnpress, Wordpress | 2 Learnpress, Wordpress | 2026-08-10 | N/A |
| The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery. | ||||
| CVE-2026-13170 | 2 Eventin, Wordpress | 2 Eventin, Wordpress | 2026-08-10 | N/A |
| The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files. | ||||
| CVE-2026-17023 | 2 Salonbookingsystem, Wordpress | 2 Salon Booking System, Wordpress | 2026-08-10 | N/A |
| The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature. | ||||
| CVE-2026-17020 | 2 Salonbookingsystem, Wordpress | 2 Salon Booking System, Wordpress | 2026-08-10 | N/A |
| The Salon Booking System WordPress plugin through 10.30.33 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers. | ||||
| CVE-2026-17021 | 2 Salonbookingsystem, Wordpress | 2 Salon Booking System, Wordpress | 2026-08-10 | N/A |
| The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings. | ||||
| CVE-2026-66470 | 2 Shabti, Wordpress | 2 Frontend Admin By Dynamapps, Wordpress | 2026-08-08 | 7.1 High |
| Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions. | ||||