Export limit exceeded: 399128 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399128 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-92807 | 2 Pdfcrowd, Wordpress-extensions | 2 Save As Pdf Plugin, Save As Pdf Plugin By Pdfcrowd | 2026-09-28 | 8.8 High |
| The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`button_`/non-`email_` shortcode attribute verbatim into a custom options array without sanitization, allowlist enforcement, or capability checks, and `create_button()` AES-encrypts that array — including the attacker-supplied callback value — and embeds the resulting blob in the rendered button HTML; when the blob is later POSTed to the unauthenticated `wp_ajax_nopriv_save_as_pdf_pdfcrowd` endpoint, `save_as_pdf_pdfcrowd()` decrypts it and invokes `$options['pdf_created_callback']` as a PHP callable at line 1722 with no `is_callable()` guard, no allowlist, and no capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to invoke arbitrary PHP functions or static class methods with plugin option data as the sole argument, enabling disclosure of the site's stored PDFCrowd API key and username or further server-side abuse. Note that the encryption boundary does not mitigate this vector because the server itself encrypts the attacker-chosen callback during shortcode rendering, supplying any authenticated Contributor with a cryptographically valid blob that any unauthenticated visitor can subsequently replay to trigger invocation. | ||||
| CVE-2026-16557 | 1 Wordpress-extensions | 1 Nimble Builder | 2026-09-28 | 4.3 Medium |
| The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-builder content of arbitrary non-public (draft, pending, private, scheduled) posts and pages. | ||||
| CVE-2025-15698 | 1 Wordpress-extensions | 1 Business Name Generator | 2026-09-28 | 3.5 Low |
| The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2026-19860 | 2 Jetmonsters, Wordpress-extensions | 2 Jetformbuilder — Dynamic Blocks Form Builder, Jetformbuilder | 2026-09-28 | 5.5 Medium |
| The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server to be deleted. The deletion itself is carried out when the form is submitted, which requires no authentication. | ||||
| CVE-2026-76554 | 1 Wordpress-extensions | 1 Wp Import Export Lite | 2026-09-28 | 7.2 High |
| The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to create or modify user accounts and assign roles, allowing users granted a delegated WP Import Export Lite WordPress plugin before 3.9.35 permission, who cannot otherwise manage users, to create administrator accounts and to overwrite the credentials and role of existing accounts, including administrators. | ||||
| CVE-2026-76790 | 1 Wordpress-extensions | 1 Estatik | 2026-09-28 | 7.1 High |
| The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back in an unauthenticated AJAX response, leading to Reflected Cross-Site Scripting. | ||||
| CVE-2026-84750 | 1 Wordpress-extensions | 1 Ultimate Addons For Contact Form 7 | 2026-09-28 | 6.5 Medium |
| The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uploaded through one of its form fields, and stores them at a predictable public path with the attacker-chosen extension intact, allowing unauthenticated users to upload arbitrary files. The PHP handler shipped by default with the Debian and Ubuntu Apache packages maps .phar to PHP alongside .php and .phtml, so on that stack the uploaded file is executed and the issue leads to Remote Code Execution and full site takeover. Where the host routes only .php to the PHP handler, the same file is instead served from the site's own origin with its script intact, leading to Stored Cross-Site Scripting. | ||||
| CVE-2026-85574 | 1 Wordpress-extensions | 1 Unbounce Landing Pages | 2026-09-28 | 8 High |
| The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin. | ||||
| CVE-2026-86591 | 1 Wordpress-extensions | 1 Botiga Pro | 2026-09-28 | 9.8 Critical |
| The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover. The same route also allows unauthenticated users to store arbitrary web scripts which are then executed on every page of the site's front end, as well as to move arbitrary posts to the trash. | ||||
| CVE-2026-88824 | 1 Wordpress-extensions | 1 Master Blocks | 2026-09-28 | 8.8 High |
| The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page. | ||||
| CVE-2026-88926 | 1 Wordpress-extensions | 1 Vikrentitems Flexible Rental Management System | 2026-09-28 | 8.6 High |
| The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-92099 | 1 Wordpress-extensions | 1 Wpgraphql Smart Cache | 2026-09-28 | 6.5 Medium |
| The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persisted query from a request, allowing unauthenticated users to publish arbitrary query documents and claim query aliases before a site's own frontend registers them. | ||||
| CVE-2026-92403 | 1 Wordpress-extensions | 1 Secure Custom Fields | 2026-09-28 | 3.7 Low |
| The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different registered form and modify the title and content of the post that form is bound to. | ||||
| CVE-2026-92404 | 1 Wordpress-extensions | 1 Mgosync | 2026-09-28 | 7.5 High |
| The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, from a configured site. | ||||
| CVE-2026-92420 | 1 Wordpress-extensions | 1 Hydra Booking | 2026-09-28 | 3.8 Low |
| The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking-provider-level user to cancel and permanently delete other providers' bookings on the same site. | ||||
| CVE-2026-92421 | 1 Wordpress-extensions | 1 Hydra Booking | 2026-09-28 | 4.7 Medium |
| The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the user making the request, allowing authenticated users holding a Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3-assigned host role to modify other hosts' profile data and reassign ownership of another host's record to themselves. | ||||
| CVE-2026-92425 | 1 Wordpress-extensions | 1 Hydra Booking | 2026-09-28 | 5.5 Medium |
| The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its own administrator-assigned custom role to read, modify and permanently delete other hosts' records and the WordPress user accounts linked to them. | ||||
| CVE-2026-92430 | 1 Wordpress-extensions | 1 Rede Itau For Woocommerce | 2026-09-28 | 5.3 Medium |
| The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook before updating an order's status, allowing unauthenticated attackers to mark a pending order as paid without paying. | ||||
| CVE-2026-92435 | 1 Wordpress-extensions | 1 Mailchimp For Woocommerce | 2026-09-28 | 5.3 Medium |
| The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change. | ||||
| CVE-2026-9832 | 2 Themehigh, Wordpress-extensions | 2 Stripe Payment Gateway For Woocommerce, Payment Gateway Of Stripe For Woocommerce | 2026-09-28 | 5.3 Medium |
| The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_stripe` webhook endpoint (`EH_Stripe_Webhook_Handler::handle()`) wrapping the only call to `\Stripe\Webhook::constructEvent()` inside an `if (!empty($endpoint_secret))` guard that is never entered on default installations — because the `eh_stripe_webhook_secret` option is empty after a fresh plugin install — causing the raw, attacker-controlled POST body to be decoded and processed as a fully trusted Stripe event without any signature verification, authentication, or authorization. This makes it possible for unauthenticated attackers to send forged Stripe webhook events to manipulate WooCommerce order statuses, including marking unpaid orders as paid or completed via `payment_complete()`, forcing legitimate orders into a failed state, fabricating dispute notifications, and injecting forged refund events. This vulnerability is only exploitable when the Stripe webhook signing secret has not been configured by an administrator; once a valid signing secret is saved, `\Stripe\Webhook::constructEvent()` is enforced and forged requests are rejected. | ||||