Export limit exceeded: 401185 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (401185 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100157 | 2 Roxnor, Wordpress-extensions | 2 Wp Ultimate Review, Wp Ultimate Review | 2026-10-04 | 6.5 Medium |
| The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The nonce required to pass the only gate is emitted to unauthenticated visitors via the public review form, and submitted shortcode payloads are auto-published without admin approval by default, meaning exploitation requires no account and no privileged interaction. | ||||
| CVE-2026-92084 | 2 Beaverbuilder, Wordpress-extensions | 2 Beaver Builder Page Builder – Drag And Drop Website Builder, Beaver Builder Page Builder | 2026-10-04 | 9.1 Critical |
| The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. Exploitation requires the target site to have a Beaver Builder page containing the Sidebar module populated with a widget that displays attacker-controllable text, such as the core Recent Comments widget, with comment moderation disabled or the attacker's comment approved. | ||||
| CVE-2026-92767 | 2 Wordpress-extensions, Zayedbaloch | 2 Twenty20 Image Before-after, Twenty20 Image Before-after | 2026-10-04 | 6.4 Medium |
| The Twenty20 Image Before-After plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'offset' Shortcode Attribute in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-103065 | 2 Themeum, Wordpress-extensions | 2 Kirki, Kirki | 2026-10-04 | 8.2 High |
| Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1. | ||||
| CVE-2026-103342 | 2 Unlimited-elements, Wordpress-extensions | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor | 2026-10-04 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20. | ||||
| CVE-2026-96451 | 2 Ultimatemember, Wordpress-extensions | 2 Ultimate Member, Ultimate Member | 2026-10-04 | 8.8 High |
| Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1. | ||||
| CVE-2026-105123 | 2 Vincent-peugnet, Wcms | 2 Wcms, Wcms | 2026-10-04 | 8.8 High |
| W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path]. | ||||
| CVE-2026-105124 | 2 Vincent-peugnet, Wcms | 2 Wcms, Wcms | 2026-10-04 | 6.1 Medium |
| W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges. | ||||
| CVE-2026-17005 | 1 Wordpress-extensions | 1 Horizontal Scrolling Announcements | 2026-10-04 | N/A |
| The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted) to perform Stored Cross-Site Scripting attacks that execute in the browser of anyone viewing the announcement. | ||||
| CVE-2026-104118 | 2 Razorpay, Wordpress-extensions | 2 Razorpay For Woocommerce, Razorpay For Woocommerce | 2026-10-04 | N/A |
| The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders. | ||||
| CVE-2026-104119 | 1 Wordpress-extensions | 1 Simple Shopping Cart | 2026-10-04 | N/A |
| The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where administrators do not have the unfiltered_html capability. | ||||
| CVE-2026-86817 | 1 Wordpress-extensions | 1 Five Star Business Profile And Schema | 2026-10-04 | N/A |
| The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and arbitrary site option values, in public output readable by unauthenticated visitors. | ||||
| CVE-2026-93549 | 1 Wordpress-extensions | 1 Cocart | 2026-10-04 | N/A |
| The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session. | ||||
| CVE-2026-97332 | 1 Wordpress-extensions | 1 User Private Files | 2026-10-04 | N/A |
| The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticated users to retrieve other users' private files directly. | ||||
| CVE-2026-103354 | 2 Stellarwp, Wordpress-extensions | 2 Gutenberg Blocks By Kadence Blocks, Gutenberg Blocks By Kadence Blocks | 2026-10-04 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Stored XSS.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.7.11.1. | ||||
| CVE-2026-97276 | 2 Veronalabs, Wordpress-extensions | 2 Wp Statistics, Wp Statistics | 2026-10-04 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics wp-statistics allows Reflected XSS.This issue affects WP Statistics: from n/a through 14.16.14. | ||||
| CVE-2026-103062 | 2 Cozmoslabs, Wordpress-extensions | 2 Translatepress, Translatepress | 2026-10-04 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Stored XSS.This issue affects TranslatePress: from n/a through 3.3.6. | ||||
| CVE-2026-103344 | 2 Unlimited-elements, Wordpress-extensions | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor | 2026-10-04 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20. | ||||
| CVE-2026-103355 | 2 Unlimited-elements, Wordpress-extensions | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor | 2026-10-04 | 9.3 Critical |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20. | ||||
| CVE-2026-97307 | 2 Stylemixthemes, Wordpress-extensions | 2 Cost Calculator Builder, Cost Calculator Builder | 2026-10-04 | 7.5 High |
| Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17. | ||||