Search

Search Results (402612 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-94299 2026-10-06 6.5 Medium
The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers to forge payment confirmations and change the status of arbitrary orders on any installation where that secret has been left at its default empty value.
CVE-2026-94278 2026-10-06 5.5 Medium
The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belonging to other users, including administrators, and to corrupt unrelated stored site data that referenced the old file path.
CVE-2026-94271 2026-10-06 5.3 Medium
The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the payment with the payment provider when handling the return from the hosted checkout, and does not check the payment status or amount, allowing unauthenticated users to have orders marked as paid without any payment being taken.
CVE-2026-94270 2026-10-06 5.3 Medium
The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the authenticity of incoming payment provider notifications, and ships with that verification disabled by default, allowing unauthenticated attackers to mark an unpaid order as paid, or to cancel or refund an existing order.
CVE-2026-93617 2026-10-06 7.2 High
Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1.
CVE-2026-89289 2026-10-06 5.3 Medium
The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its id.
CVE-2026-86786 2026-10-06 5.3 Medium
The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including drafts, pending, scheduled, private and trashed posts, as well as post revisions and media metadata.
CVE-2026-41563 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions.
CVE-2026-41558 2026-10-06 7.5 High
Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.
CVE-2026-39791 2026-10-06 5.3 Medium
Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions.
CVE-2026-39789 2026-10-06 7.5 High
Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.
CVE-2026-39760 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.
CVE-2026-39757 2026-10-06 9.9 Critical
Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions.
CVE-2026-39756 2026-10-06 6.5 Medium
Unauthenticated Insecure Direct Object References (IDOR) in Wappointment <= 2.7.7 versions.
CVE-2026-39755 2026-10-06 9.9 Critical
Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions.
CVE-2026-39754 2026-10-06 6.5 Medium
Contributor Arbitrary File Download in Piotnet Addons For Elementor <= 7.1.71 versions.
CVE-2026-39753 2026-10-06 9.8 Critical
Unauthenticated Privilege Escalation in Taskbot <= 6.6 versions.
CVE-2026-39752 2026-10-06 7.7 High
Contributor Arbitrary File Deletion in Jobs for WordPress <= 2.8.2 versions.
CVE-2026-39751 2026-10-06 7.5 High
Unauthenticated Broken Access Control in PayPlug for WooCommerce (Official) <= 3.1.0 versions.
CVE-2026-39750 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.0.6 versions.