Search Results (16392 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-95513 2 Vcita, Wordpress 2 Online Booking & Scheduling Calendar For Wordpress By Vcita, Wordpress 2026-09-23 7.5 High
Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions.
CVE-2026-95514 2 Netgsm, Wordpress 2 Netgsm, Wordpress 2026-09-23 5.3 Medium
Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions.
CVE-2026-95525 2 Wedevs, Wordpress 2 Wp User Frontend, Wordpress 2026-09-23 6.5 Medium
Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.
CVE-2026-94080 2 Webwizards, Wordpress 2 Marketking, Wordpress 2026-09-23 5.3 Medium
Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.
CVE-2026-95529 2 Codepeople, Wordpress 2 Calculated Fields Form, Wordpress 2026-09-23 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions.
CVE-2026-95515 2 Ninjaforms, Wordpress 2 Ninja Forms, Wordpress 2026-09-23 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
CVE-2026-95522 2 Syed Balkhi, Wordpress 2 Easy Digital Downloads, Wordpress 2026-09-23 7.6 High
Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.
CVE-2026-95523 2 Wedevs, Wordpress 2 Wp User Frontend, Wordpress 2026-09-23 6.5 Medium
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
CVE-2026-95524 2 Wedevs, Wordpress 2 Wp User Frontend, Wordpress 2026-09-23 5.3 Medium
Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
CVE-2026-95527 2 Conekta Group, Wordpress 2 Conekta Payment Gateway, Wordpress 2026-09-23 6.5 Medium
Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.
CVE-2026-95590 2 Tainacan, Wordpress 2 Tainacan, Wordpress 2026-09-23 7.1 High
Subscriber SQL Injection in Tainacan <= 1.2.0 versions.
CVE-2026-95604 2 Tangible, Wordpress 2 Loops & Logic, Wordpress 2026-09-23 7.5 High
Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.
CVE-2026-93526 2 Nexcess, Wordpress 2 Event Tickets, Wordpress 2026-09-23 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions.
CVE-2026-93772 2 Tomdever, Wordpress 2 Wpforo Forum, Wordpress 2026-09-23 6.5 Medium
Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions.
CVE-2026-93513 2 Siteskite, Wordpress 2 Siteskite, Wordpress 2026-09-23 4.3 Medium
Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions.
CVE-2026-94168 2 Leap13, Wordpress 2 Premium Addons For Elementor, Wordpress 2026-09-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.
CVE-2026-94124 2 Levelfourdevelopment, Wordpress 2 Wp-easycart, Wordpress 2026-09-23 8.5 High
Contributor SQL Injection in WP EasyCart <= 5.9.4 versions.
CVE-2026-95601 2 Wbw Plugins, Wordpress 2 Product Filter By Wbw, Wordpress 2026-09-23 9.3 Critical
Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions.
CVE-2026-95586 2 Themefic, Wordpress 2 Ultimate Addons For Contact Form 7, Wordpress 2026-09-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.
CVE-2026-93368 2 Travispluse, Wordpress 2 Rename Wp-login.php To Anything You Want, Wordpress 2026-09-23 7.5 High
The Rename wp-login.php to anything you want plugin for WordPress is vulnerable to time-based SQL Injection via 'log' (Username) Parameter in all versions up to, and including, 2.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. WordPress core applies wp_unslash() to the 'log' POST value before dispatching the wp_login_failed action, stripping magic-quotes backslash escaping and allowing a raw single quote to reach the plugin's handler unimpeded.