Search

Search Results (371802 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-15348 2 Codename065, Wordpress 2 Premium Packages – Sell Digital Products Securely, Wordpress 2026-08-02 6.3 Medium
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via the `wpdmppdl` parameter. This is due to the `download()` function — hooked to the unauthenticated WordPress `wp` action — decoding the attacker-controlled `wpdmppdl` parameter using only `base64_decode()` and `json_decode()` with no HMAC, cryptographic signature, or nonce verification, and then issuing WordPress authentication cookies after a domain check that is trivially bypassed because both sides of the comparison are attacker-supplied values. This makes it possible for unauthenticated attackers to authenticate as any non-administrator WordPress user, including subscribers, customers, contributors, authors, editors, and shop managers, who owns an order, gaining full session-level access to that account.
CVE-2026-57373 2 Wisetr, Wordpress 2 Funnel Kit Funnel Builder Pro, Wordpress 2026-08-02 6.5 Medium
Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.
CVE-2026-57374 2 Wisetr, Wordpress 2 Funnel Kit Funnel Builder Pro, Wordpress 2026-08-02 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.
CVE-2026-59554 2 Wordpress, Ziina 2 Wordpress, Ziina 2026-08-02 7.5 High
Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
CVE-2026-65477 2 Select-themes, Wordpress 2 Tonda Core, Wordpress 2026-08-02 7.5 High
Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.
CVE-2026-65481 2 Elated-themes, Wordpress 2 Vino, Wordpress 2026-08-02 7.5 High
Contributor Local File Inclusion in Vino <= 1.9 versions.
CVE-2026-65491 2 Jonathan Daggerhart, Wordpress 2 Query Wrangler, Wordpress 2026-08-02 4.3 Medium
Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
CVE-2026-65514 2 Codepeople, Wordpress 2 Appointment Hour Booking, Wordpress 2026-08-02 6.5 Medium
Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
CVE-2026-65518 2 Scott Paterson, Wordpress 2 Accept Donations With Paypal & Stripe, Wordpress 2026-08-02 6.5 Medium
Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.
CVE-2026-12353 1 Redhat 3 Certificate System, Dogtag Certificate System, Enterprise Linux 2026-08-02 5.3 Medium
An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.
CVE-2026-12981 2 Cafehaus, Wordpress 2 Cafehaus Api, Wordpress 2026-08-02 7.5 High
The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.
CVE-2026-14603 2 Wordpress, Wowoptin 2 Wordpress, Next-gen Popup Maker 2026-08-02 7.5 High
The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database.
CVE-2026-15665 2 Wordpress, Wpmanageninja 2 Wordpress, Fluent Support – Helpdesk & Customer Support Ticket System 2026-08-02 6.4 Medium
The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The XSS payload is in a hidden attribute so it only fires in specific browsers when specific access keys are used making exploitation unlikely.
CVE-2026-12654 2 Payment Plugins, Wordpress 2 Payment Plugins For Stripe Woocommerce, Wordpress 2026-08-02 5.3 Medium
The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary pending asynchronous WooCommerce orders as paid by forging a charge.pending event with attacker-controlled metadata.order_id, metadata.gateway_id, and a charge object carrying status=succeeded and captured=true, triggering payment_complete() and downstream fulfillment flows with an attacker-supplied transaction ID. Exploitation requires the merchant to have left the webhook_secret_test or webhook_secret_live option blank, which is the plugin's default state until a Stripe-issued whsec_ value is manually configured; once a non-empty secret is set, the signature verification cannot be bypassed.
CVE-2026-15739 2 Widgetpack, Wordpress 2 Rich Showcase For Google Reviews, Wordpress 2026-08-02 6.4 Medium
The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and including, 6.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-16730 1 Redhat 5 Enterprise Linux, Hardened Images, Hummingbird and 2 more 2026-08-02 5.5 Medium
A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.
CVE-2026-17039 1 Redhat 3 Certificate System, Dogtag Certificate System, Enterprise Linux 2026-08-02 3.1 Low
A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.
CVE-2026-13605 2 Photoswipe, Wordpress 2 Photoswipe, Wordpress 2026-08-02 6.8 Medium
The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping. Because the title attribute survives the post-content sanitization applied to users who lack the unfiltered_html capability, an authenticated user with Author-level access can store a JavaScript payload that executes in the browser of any visitor, including an administrator, who clicks the link.
CVE-2026-13690 2 Userswp, Wordpress 2 Userswp, Wordpress 2026-08-02 7.4 High
The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.
CVE-2026-13692 2 Payu, Wordpress 2 Payu Commercepro Plugin, Wordpress 2026-08-02 5.3 Medium
The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.