Search

Search Results (402067 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-89289 2026-10-06 5.3 Medium
The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its id.
CVE-2026-86786 2026-10-06 5.3 Medium
The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including drafts, pending, scheduled, private and trashed posts, as well as post revisions and media metadata.
CVE-2026-66588 2026-10-06 7.5 High
Unauthenticated Broken Access Control in The7 <= 14.2.2 versions.
CVE-2026-62072 2026-10-06 8.8 High
Subscriber Broken Access Control in Progress Planner <= 1.10.0 versions.
CVE-2026-48199 2026-10-06 7.5 High
Unauthenticated Broken Access Control in Sermon'e <= 1.0.2 versions.
CVE-2026-48197 2026-10-06 7.2 High
Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0.
CVE-2026-42638 2026-10-06 7.5 High
Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.7.1 versions.
CVE-2026-42637 2026-10-06 6.5 Medium
Unauthenticated Settings Change in PayPlug for WooCommerce (Official) <= 3.1.0 versions.
CVE-2026-42636 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.4.6 versions.
CVE-2026-42635 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WooCommerce Simple Auctions <= 3.0.10 versions.
CVE-2026-42634 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Video Background Block – Use video as background in the section. <= 2.0.3 versions.
CVE-2026-42418 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Social Rocket <= 1.3.5 versions.
CVE-2026-42417 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions.
CVE-2026-42416 2026-10-06 8.5 High
Subscriber SQL Injection in UDesign Core <= 4.15.0 versions.
CVE-2026-42415 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions.
CVE-2026-42414 2026-10-06 8.5 High
Subscriber SQL Injection in ListingPro <= 2.9.12 versions.
CVE-2026-42413 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Snapshotify &#8211; All-in-One Backup &amp; Restore &amp; Migrate <= 1.3.2 versions.
CVE-2026-41563 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions.
CVE-2026-41562 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions.
CVE-2026-41561 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Museder RestoreOne <= 2.7.276 versions.