Export limit exceeded: 402067 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402067 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402067 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-89289 | 2026-10-06 | 5.3 Medium | ||
| The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its id. | ||||
| CVE-2026-86786 | 2026-10-06 | 5.3 Medium | ||
| The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including drafts, pending, scheduled, private and trashed posts, as well as post revisions and media metadata. | ||||
| CVE-2026-66588 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in The7 <= 14.2.2 versions. | ||||
| CVE-2026-62072 | 2026-10-06 | 8.8 High | ||
| Subscriber Broken Access Control in Progress Planner <= 1.10.0 versions. | ||||
| CVE-2026-48199 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in Sermon'e <= 1.0.2 versions. | ||||
| CVE-2026-48197 | 2026-10-06 | 7.2 High | ||
| Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0. | ||||
| CVE-2026-42638 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.7.1 versions. | ||||
| CVE-2026-42637 | 2026-10-06 | 6.5 Medium | ||
| Unauthenticated Settings Change in PayPlug for WooCommerce (Official) <= 3.1.0 versions. | ||||
| CVE-2026-42636 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.4.6 versions. | ||||
| CVE-2026-42635 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WooCommerce Simple Auctions <= 3.0.10 versions. | ||||
| CVE-2026-42634 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Video Background Block – Use video as background in the section. <= 2.0.3 versions. | ||||
| CVE-2026-42418 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Social Rocket <= 1.3.5 versions. | ||||
| CVE-2026-42417 | 2026-10-06 | 9.3 Critical | ||
| Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions. | ||||
| CVE-2026-42416 | 2026-10-06 | 8.5 High | ||
| Subscriber SQL Injection in UDesign Core <= 4.15.0 versions. | ||||
| CVE-2026-42415 | 2026-10-06 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions. | ||||
| CVE-2026-42414 | 2026-10-06 | 8.5 High | ||
| Subscriber SQL Injection in ListingPro <= 2.9.12 versions. | ||||
| CVE-2026-42413 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in Snapshotify – All-in-One Backup & Restore & Migrate <= 1.3.2 versions. | ||||
| CVE-2026-41563 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions. | ||||
| CVE-2026-41562 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions. | ||||
| CVE-2026-41561 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in Museder RestoreOne <= 2.7.276 versions. | ||||