Filtered by CWE-862
Total 8907 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-65491 2 Jonathan Daggerhart, Wordpress 2 Query Wrangler, Wordpress 2026-08-02 4.3 Medium
Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
CVE-2026-12654 2 Payment Plugins, Wordpress 2 Payment Plugins For Stripe Woocommerce, Wordpress 2026-08-02 5.3 Medium
The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary pending asynchronous WooCommerce orders as paid by forging a charge.pending event with attacker-controlled metadata.order_id, metadata.gateway_id, and a charge object carrying status=succeeded and captured=true, triggering payment_complete() and downstream fulfillment flows with an attacker-supplied transaction ID. Exploitation requires the merchant to have left the webhook_secret_test or webhook_secret_live option blank, which is the plugin's default state until a Stripe-issued whsec_ value is manually configured; once a non-empty secret is set, the signature verification cannot be bypassed.
CVE-2026-13692 2 Payu, Wordpress 2 Payu Commercepro Plugin, Wordpress 2026-08-02 5.3 Medium
The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.
CVE-2026-18218 1 Redhat 8 Build Keycloak, Build Of Keycloak, Data Grid and 5 more 2026-08-02 4.2 Medium
A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm already has an older, non-zero revocation policy in place. This issue can allow previously issued tokens to remain valid for refreshing sessions and accessing user information even after an administrator has attempted to invalidate them. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
CVE-2026-16105 1 Redhat 8 Build Keycloak, Build Of Keycloak, Data Grid and 5 more 2026-08-02 4.9 Medium
A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm.
CVE-2026-18208 1 Redhat 8 Build Keycloak, Build Of Keycloak, Data Grid and 5 more 2026-08-02 6.5 Medium
A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential client, configured to receive signed JWT introspection responses, attempts to introspect a token issued for a different audience. Although the endpoint correctly identifies the token as inactive for that client, it still returns the full set of token claims within a signed JWT field. This allows an unauthorized client to bypass audience-based restrictions and access sensitive information contained in the token.
CVE-2026-18437 2 Mailerpress, Wordpress 2 Mailerpress – Newsletter, Email Marketing & Ai Automation, Wordpress 2026-08-02 5.3 Medium
The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details.
CVE-2026-18436 2 Mailerpress, Wordpress 2 Mailerpress – Newsletter, Email Marketing & Ai Automation, Wordpress 2026-08-02 5.3 Medium
The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<id>/restore-revision/<revision_id>). The route in the vulnerable range was registered without a permissionCallback, allowing the restoreRevision() handler to run for unauthenticated requests and overwrite a campaign's content_html with any prior revision. This makes it possible for unauthenticated attackers to modify campaign content by restoring an arbitrary revision.
CVE-2026-17580 2 Wordpress, Wplakeorg 2 Wordpress, Advanced Views – Display Custom Fields (acf, Pods, Metabox), Posts, Cpt And Woo Products Anywhere In Gutenberg, Elementor, Divi, Beaver… 2026-08-02 6.5 Medium
The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.1 via the register_rest_routes. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive admin-authored editor content — including template markup, CSS code, JavaScript code, and PHP controller variables — for any Layout or Post Selection post on the site.
CVE-2026-27391 2 Stylemixthemes, Wordpress 2 Ulisting, Wordpress 2026-08-02 5.4 Medium
Subscriber Broken Access Control in uListing <= 2.2.0 versions.
CVE-2026-27392 2 Stylemixthemes, Wordpress 2 Ulisting, Wordpress 2026-08-02 4.3 Medium
Contributor Broken Access Control in uListing <= 2.2.0 versions.
CVE-2026-27423 2 Rolandbarkerxnauwebdesign, Wordpress 2 Participants Database, Wordpress 2026-08-02 4.3 Medium
Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.
CVE-2026-57367 2 Wordpress, Wpbookingsystem 2 Wordpress, Wp Booking System 2026-08-02 7.1 High
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
CVE-2026-57717 2 Knit Pay, Wordpress 2 Knit Pay, Wordpress 2026-08-02 6.5 Medium
Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.
CVE-2026-61943 2 Shahjada, Wordpress 2 Wpdm Premium Packages, Wordpress 2026-08-02 7.5 High
Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
CVE-2026-65468 2 Crocoblock, Wordpress 2 Jetbooking, Wordpress 2026-08-02 5.3 Medium
Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
CVE-2026-65469 2 Strategy11, Wordpress 2 Awp Classifieds, Wordpress 2026-08-02 5.3 Medium
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
CVE-2026-65478 2 Cridio, Wordpress 2 Listingpro, Wordpress 2026-08-02 5.4 Medium
Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.
CVE-2026-65499 2 Peprodev, Wordpress 2 Peprodev Ultimate Invoice, Wordpress 2026-08-02 6.5 Medium
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-65506 2 Sonaar, Wordpress 2 Mp3 Audio Player For Music, Radio & Podcast, Wordpress 2026-08-02 5.3 Medium
Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.