Search Results (8418 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-54835 2 Rustaurius, Wordpress 2 Five Star Restaurant Menu, Wordpress 2026-06-29 7.5 High
Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.
CVE-2026-54837 2 Syed Balkhi, Wordpress 2 Intranet & Private Site – All-in-one Intranet, Wordpress 2026-06-29 7.5 High
Unauthenticated Broken Access Control in Intranet &amp; Private Site &#8211; All-In-One Intranet <= 1.8.1 versions.
CVE-2026-54846 2 Akosglys, Wordpress 2 Syncee Premium Dropshipping & Wholesale, Wordpress 2026-06-29 7.5 High
Unauthenticated Broken Access Control in Syncee Premium Dropshipping &amp; Wholesale <= 1.0.27 versions.
CVE-2026-56025 2 Paymob, Wordpress 2 Paymob For Woocommerce, Wordpress 2026-06-29 7.5 High
Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.
CVE-2026-56038 2 Frisbii, Wordpress 2 Frisbii Pay, Wordpress 2026-06-29 8.8 High
Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.
CVE-2026-56063 2 Bplugins, Wordpress 2 Mailchimp Block, Wordpress 2026-06-29 8.3 High
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.
CVE-2026-57323 2 Bplugins, Wordpress 2 Flash & Html5 Video, Wordpress 2026-06-29 5.8 Medium
Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.
CVE-2026-57430 2 Seopress Free, Wordpress 2 Seopress Pro, Wordpress 2026-06-29 4.3 Medium
Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.
CVE-2026-11364 2 Dornaweb, Wordpress 2 Product Specifications For Woocommerce, Wordpress 2026-06-29 4.3 Medium
The Product Specifications for WooCommerce plugin for WordPress is vulnerable to unauthorized modification, creation, and deletion of data in versions up to and including 0.8.9. This is due to a missing capability check and missing nonce verification in the __invoke() methods of the AttributeGroupController and AttributeController classes, which are bound to the 'dwps_modify_groups' and 'dwps_modify_attributes' AJAX actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create, edit, and delete arbitrary product specification groups and attributes (taxonomy terms in the 'spec-group' and attribute taxonomies), corrupting business data and impacting the site's frontend display.
CVE-2026-11773 2 Masteriyo, Wordpress 2 Masteriyo Lms – Lms Course Builder, Quizzes & Certificates, Wordpress 2026-06-29 4.3 Medium
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with student-level access and above, to modify the description (post content) of arbitrary course announcements authored by instructors or administrators.
CVE-2026-12471 2 Templatescoderthemes, Wordpress 2 Spexo, Wordpress 2026-06-29 4.3 Medium
The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plugin function in all versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate a limited set of plugins.
CVE-2026-12432 2 Themeisle, Wordpress 2 Stripe Payment Forms By Wp Full Pay – Accept Credit Card Payments, Donations & Subscriptions, Wordpress 2026-06-29 5.3 Medium
The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_nopriv_ hooks and the underlying update_failed_payment_status() function performs no capability check, no nonce verification, and no logged-in check before calling $this->db->updatePaymentByEventId() with attacker-controlled POST parameters. This makes it possible for unauthenticated attackers who can obtain a valid Stripe Payment Intent ID for the target site (Payment Intent IDs are exposed to the customer browser during normal Stripe.js checkout flows) to manipulate payment records in the site's database, marking previously successful payments as failed and overwriting failure codes and messages with attacker-supplied values.
CVE-2026-3462 2 Reepaydenmark, Wordpress 2 Frisbii Pay, Wordpress 2026-06-29 6.5 Medium
The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'upload_csv' and 'process_batch' functions in all versions up to, and including, 1.8.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary CSV data and overwrite WooCommerce payment tokens, postmeta, and order meta records.
CVE-2026-24547 2 Siteground, Wordpress 2 Email-marketing, Wordpress 2026-06-29 5.3 Medium
Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.
CVE-2026-54832 2 Jegstudio, Wordpress 2 Gutenverse, Wordpress 2026-06-29 7.5 High
Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.
CVE-2026-54840 2 Tribulant, Wordpress 2 Newsletters, Wordpress 2026-06-29 7.3 High
Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.
CVE-2026-57632 2 Omnisend, Wordpress 2 Email Marketing For Woocommerce, Wordpress 2026-06-29 5.4 Medium
Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.
CVE-2026-57640 2 Stylemixthemes, Wordpress 2 Masterstudy Lms, Wordpress 2026-06-29 4.3 Medium
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.
CVE-2026-57645 2 Tribulant, Wordpress 2 Newsletters, Wordpress 2026-06-29 8.1 High
newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.
CVE-2026-57649 2 Studiowombat, Wordpress 2 Shoppable Images, Wordpress 2026-06-29 4.3 Medium
Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.