Search Results (227 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-92712 2 Rockiger, Wordpress-extensions 2 Reactpress, Reactpress 2026-09-30 6.4 Medium
The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permalink' parameter in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the permalink parameter is only passed through sanitize_url(), which does not prevent fetching attacker-controlled remote URLs whose response body — including script tags and event-handler attributes — is written verbatim to disk via file_put_contents().
CVE-2026-96342 2 Amauri, Wordpress-extensions 2 Wpmobile.app, Wpmobile.app 2026-09-30 N/A
Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83.
CVE-2026-102386 2 Jacob N. Breetvelt, Wordpress-extensions 2 Wp Photo Album Plus, Wp Photo Album Plus 2026-09-30 6.5 Medium
Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions.
CVE-2026-102395 2 Supsystic, Wordpress-extensions 2 Easy Google Maps, Easy Google Maps 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions.
CVE-2026-102396 2 Supsystic, Wordpress-extensions 2 Ultimate Maps By Supsystic, Ultimate Maps By Supsystic 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions.
CVE-2026-102398 2 Supsystic, Wordpress-extensions 2 Popup By Supsystic, Popup By Supsystic 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions.
CVE-2026-102399 2 Supsystic, Wordpress-extensions 2 Photo Gallery By Supsystic, Photo Gallery By Supsystic 2026-09-30 5.4 Medium
Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions.
CVE-2026-96326 2 Htplugins, Wordpress-extensions 2 Ht Contact Form – Drag & Drop Form Builder For Wordpress, Ht Contact Form 2026-09-30 7.2 High
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-87741 2 Brainstormforce, Wordpress-extensions 2 Convertplug, Convertplus 2026-09-29 8.8 High
The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action. The vulnerability exists because the action's nonce guard is gated behind an isset() check and fails open when the cp_admin_page_nonce parameter is omitted entirely, no capability check is performed on the callback, and sanitize_text_field() — applied to the $style value before it is concatenated directly into a shortcode string evaluated by do_shortcode() — does not strip shortcode delimiters, allowing an attacker to inject a second, fully attacker-controlled [smile_modal] invocation that causes smile_modal_popup() to pass attacker-supplied base64-decoded bytes to maybe_unserialize() with no allowed_classes restriction. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
CVE-2026-87963 1 Wordpress-extensions 1 Yo 2026-09-29 8.6 High
The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attackers to perform SQL injection and read arbitrary database contents including administrator password hashes.
CVE-2026-66618 2 Flippercode, Wordpress-extensions 2 Wp Maps, Wp Maps 2026-09-29 7.6 High
Administrator SQL Injection in WP Maps <= 4.9.9 versions.
CVE-2026-66619 2 Tribulant, Wordpress-extensions 2 Newsletters, Newsletters 2026-09-29 7.6 High
Administrator SQL Injection in Newsletters <= 4.18 versions.
CVE-2026-66631 2 Moreconvert, Wordpress-extensions 2 Woocommerce Wishlist, Mc Woocommerce Wishlist 2026-09-29 7.6 High
Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.
CVE-2026-73999 2 Goratech, Wordpress-extensions 2 Cooked, Cooked 2026-09-29 5.4 Medium
Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.
CVE-2026-78528 2 Berqier, Wordpress-extensions 2 Berqwp, Berqwp 2026-09-29 5.3 Medium
Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.
CVE-2026-16750 2 Stylemixthemes, Wordpress-extensions 2 Motors - Car Dealer, Classifieds & Listing, Motors – Car Dealership & Classified Listings 2026-09-29 5.3 Medium
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_load_cars() function in all versions up to, and including, 1.4.120. This makes it possible for unauthenticated attackers to retrieve draft, pending, private, and future car listings belonging to arbitrary users.
CVE-2026-16582 2 Ameliabooking, Wordpress-extensions 2 Booking For Appointments And Events Calendar, Booking For Appointments And Events Calendar – Amelia 2026-09-29 5.3 Medium
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.4.5. This is due to the plugin accepting a client-supplied package-redemption identifier as proof of payment without validating it. This makes it possible for unauthenticated attackers to create approved appointment bookings without completing payment
CVE-2026-14311 2 Ameliabooking, Wordpress-extensions 2 Booking For Appointments And Events Calendar, Booking For Appointments And Events Calendar – Amelia 2026-09-29 5.4 Medium
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with wpamelia-provider role, to view and modify arbitrary customers, including password reset. Takeover of WordPress user accounts, with the roles up to Editor, is also possible if that user had made an Amelia booking. This vulnerability affects only the Premium version of the plugin, where the Employee Panel is present.
CVE-2026-81340 2 Stylemix, Wordpress-extensions 2 Masterstudy Lms Wordpress Plugin, Masterstudy Lms 2026-09-29 3.8 Low
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the site, granting free course enrolment, revoking other users' paid enrolments, and tampering with order notes.
CVE-2026-81810 2 Wordpress-extensions, Yaniiliev 2 All In One Wp Migration And Backup, All In One Wp Migration And Backup 2026-09-29 7.2 High
The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only on an installation-wide secret which it discloses to any user permitted to export the site, allowing such a user to import an arbitrary site archive and gain administrator access. Exploitation requires an administrator to have granted the export capability to a role that does not hold the All-in-One WP Migration and Backup WordPress plugin before 7.111's own import capability, which is not a default configuration.