Search Results (622 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100512 2 Hook & Filter, Wordpress-extensions 2 Nested Pages, Nested Pages 2026-10-01 9.8 Critical
Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
CVE-2026-102376 2 Wordpress-extensions, Wpmudev 2 Branda, Branda 2026-10-01 7.1 High
Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions.
CVE-2026-102377 2 10web, Wordpress-extensions 2 Photo Gallery, Photo Gallery By 10web 2026-10-01 8.8 High
Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.
CVE-2026-102391 2 Jetmonsters, Wordpress-extensions 2 Jetformbuilder, Jetformbuilder 2026-10-01 7.1 High
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions.
CVE-2026-102392 2 Themehigh, Wordpress-extensions 2 Extra Product Options For Woocommerce, Extra Product Options For Woocommerce 2026-10-01 7.2 High
Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.
CVE-2026-89424 2 Inisev, Wordpress-extensions 2 Duplicate Post, Duplicate Post 2026-10-01 6.4 Medium
The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires that the site owner has enabled the plugin's User Level Permissions for the Subscriber role, as this grants access to the i_saw_this_noti AJAX branch needed to deliver the payload.
CVE-2026-97661 2 Scottpaterson, Wordpress-extensions 2 Business Essentials For Contact Form 7, Business Essentials For Contact Form 7 2026-10-01 7.2 High
The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Form Field in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Payments module to be enabled and a form to be configured to accept both PayPal and Stripe as payment gateways.
CVE-2026-103353 2 Wordpress-extensions, Wpmanageninja 2 Fluentform, Fluent Forms 2026-10-01 5.3 Medium
Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects FluentForm: from n/a through 6.2.14.
CVE-2026-103067 2 Memberful, Wordpress-extensions 2 Memberful - Membership Plugin, Memberful 2026-10-01 8 High
Cross-Site Request Forgery (CSRF) vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Cross Site Request Forgery.This issue affects Memberful - Membership Plugin: from n/a through 1.81.0.
CVE-2026-103340 2 Geminilabs, Wordpress-extensions 2 Site Reviews, Site Reviews 2026-10-01 5.3 Medium
Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 8.3.2.
CVE-2026-102381 2 Ahmad, Wordpress-extensions 2 Majestic Support, Majestic Support 2026-10-01 5.3 Medium
Missing Authorization vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0.
CVE-2026-102390 2 Villatheme, Wordpress-extensions 2 Affi – Affiliate Marketing For Woocommerce, Affi - Affiliate Marketing For Woocommerce 2026-10-01 5.3 Medium
Missing Authorization vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.9.
CVE-2026-103063 2 Wordpress-extensions, Wpmet 2 Elementskit Elementor Addons Lite, Elementskit Elementor Addons 2026-10-01 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor addons Lite: from n/a through 4.0.6.
CVE-2026-102379 2 Villatheme, Wordpress-extensions 2 Buildkit – Product Builder For Woocommerce – Custom Pc Builder, Buildkit-product Builder For Woocommerce-custom Pc Builder 2026-10-01 8.5 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Blind SQL Injection.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28.
CVE-2026-62061 2 Metagauss, Wordpress-extensions 2 Profilegrid, Profilegrid 2026-10-01 5.3 Medium
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 6.0.0.2.
CVE-2026-62060 2 Captivateaudio, Wordpress-extensions 2 Captivate Sync, Captivate Sync 2026-10-01 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Blind SQL Injection.This issue affects Captivate Sync: from n/a through 3.3.2.
CVE-2026-62059 2 Ultimatemember, Wordpress-extensions 2 Ultimate Member, Ultimate Member 2026-10-01 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ultimate Member: from n/a through 2.13.1.
CVE-2026-103752 2 Paul Ryan, Wordpress-extensions 2 Authorizer, Authorizer 2026-10-01 9.8 Critical
Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions.
CVE-2026-62071 2 Nickboss, Wordpress-extensions 2 Wordpress File Upload, Wordpress File Upload 2026-10-01 9.3 Critical
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.
CVE-2026-97269 2 Getwpfunnels, Wordpress-extensions 2 Wpfunnels, Wpfunnels 2026-10-01 6.5 Medium
Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions.