Search

Search Results (400137 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-94082 2026-09-30 7.6 High
Author SQL Injection in Quiz Cat <= 3.1.1 versions.
CVE-2026-94081 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.
CVE-2026-94078 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions.
CVE-2026-94077 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions.
CVE-2026-94076 2026-09-30 8.8 High
Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.
CVE-2026-94074 2026-09-30 6.5 Medium
Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.
CVE-2026-93771 2026-09-30 7.2 High
Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.
CVE-2026-93770 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions.
CVE-2026-93651 2026-09-30 7.2 High
Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.
CVE-2026-93624 2026-09-30 7.2 High
Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.
CVE-2026-93621 2026-09-30 8.2 High
Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions.
CVE-2026-93514 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions.
CVE-2026-93512 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.
CVE-2026-92424 2026-09-30 6.8 Medium
The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary web scripts unfiltered under a privileged user's account, executing in the context of anyone who later views that content.
CVE-2026-91832 2026-09-30 7.1 High
The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting.
CVE-2026-91072 2026-09-30 4.4 Medium
The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an attacker with Administrator-level access rename or delete existing WebP-derivative image files outside that scope, including, on a multisite network, files belonging to a different site they have no access to.
CVE-2026-91051 2026-09-30 6.6 Medium
The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta field that is deserialized when the post is rendered, allowing them to perform PHP Object Injection, which can lead to remote code execution when a suitable gadget chain is present via another installed EWWW Image Optimizer WordPress plugin before 8.8.0 or .
CVE-2026-89193 2026-09-30 7.5 High
The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.
CVE-2026-88797 2026-09-30 7.1 High
The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any hosted on the WordPress.org repository.
CVE-2026-88791 2026-09-30 3.4 Low
The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.