Export limit exceeded: 404447 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404447 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-94375 | 2026-10-11 | 5.3 Medium | ||
| The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8 via the get_file_path. This makes it possible for unauthenticated attackers to extract download exported order CSV files containing customer PII — including names, billing and shipping addresses, email addresses, phone numbers, and order contents — directly over HTTP with no authentication. This is exploitable whenever the .htaccess and index.php guard files are absent from wp-content/webtoffee_export/, which can occur after any uninstall/reinstall cycle, migration, backup restore, or staging sync, since the export directory persists but its guard files do not; export filenames follow a fully deterministic second-precision timestamp pattern, making them brute-forceable across any suspected export window. | ||||
| CVE-2026-93746 | 2026-10-11 | 7.5 High | ||
| The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.2 via the 'email' parameter of the guest print_document_from_the_mail_link handler dispatched from print_window() on init. This is due to the handler authorizing access to an order's printable documents when the attacker-supplied (base64-encoded) 'email' equals the order's billing email — a non-secret identifier — instead of requiring the WooCommerce order_key. This makes it possible for unauthenticated attackers, when the site is configured to allow guest access to documents ('wt_pklist_print_button_access_for' != 'logged_in'), to retrieve any other customer's invoice, packing slip, delivery note, dispatch label or shipping label — including customer name, billing/shipping address, phone number, purchased products, prices, taxes and invoice metadata — by knowing the target order ID and the associated billing email address. | ||||
| CVE-2026-92975 | 2026-10-11 | 8.1 High | ||
| The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.3 via the `create_support_user()` function. This is due to the function identifying the support account solely by matching against publicly hardcoded constants — `user_login` `'groundhogg'` and email addresses `'support@groundhogg.io'` / `'help@groundhogg.io'` — where the `in_array()` email-equality check at line 238 is not a security boundary because any user fully controls their own email value. This makes it possible for an attacker with an account whose `user_login` is `'groundhogg'` and whose `user_email` matches one of the hardcoded support constants to have that account silently promoted to administrator — and additionally to super admin on multisite when the triggering administrator holds `manage_network_options` — resulting in full site takeover. Exploitation requires a two-actor flow: the attacker must first obtain or pre-plant an account with the hardcoded credentials (possible when open user registration is enabled or another account-creation path exists), after which a legitimate administrator must invoke the support-access feature via the `submit_ticket` or `process_send_support_access` entry points to trigger the promotion. | ||||
| CVE-2026-91136 | 2026-10-11 | 7.5 High | ||
| The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the 'svg_image' parameter of the /wp-json/elicus/v1/dipl-modules/svg-animator REST endpoint. This is due to the endpoint's permission callback (SVGAnimatorController::index_permission) returning true unconditionally combined with insufficient validation of the 'svg_image' input — sanitize_text_field() and esc_html() do not restrict filesystem paths, the file:// stream wrapper, or arbitrary URLs — before it is passed to file_get_contents() (with a wp_remote_get() fallback) and the raw response body is returned in the JSON 'html' field. This makes it possible for unauthenticated attackers to read arbitrary files on the affected site's server which may make remote code execution possible. | ||||
| CVE-2026-91050 | 2026-10-11 | 4.3 Medium | ||
| The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference / Missing Authorization in versions up to, and including, 5.7.2. This is due to the publicly reachable steps__start and steps__load_step routes accepting a params[presets][order_item_id] value that is copied verbatim into the booking object without verifying that the referenced order item belongs to the current customer, is a bundle item, is paid, or has remaining capacity — the is_bundle_scheduling() bundle discriminator is a mere !empty(order_item_id) truthiness check, and the code flow explicitly removes the customer and payment steps when this is truthy (the source even carries a TODO acknowledging the missing validation). This makes it possible for unauthenticated attackers to create approved appointments against other customers' order items and to read those customers' names, email addresses, and order codes returned in the booking confirmation. | ||||
| CVE-2026-89301 | 2026-10-11 | 7.5 High | ||
| The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to limited file deletion due to insufficient file path validation in the process function in all versions up to, and including, 4.7.13 This makes it possible for unauthenticated attackers to delete arbitrary safe files on the server.. The public nonce (rtmedia_upload_nonce) is emitted into frontend JavaScript on any page rendering the rtMedia gallery or upload shortcode, making it retrievable by unauthenticated visitors without any prior authentication or privileged action. | ||||
| CVE-2026-83526 | 2026-10-11 | 8.8 High | ||
| The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This is due to insufficient file type validation in check_mimetype(), which writes attacker-supplied remote file content to the public uploads directory before any MIME or extension check, combined with a missing capability check on new player creation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. This requires successfully exploiting a race condition. | ||||
| CVE-2026-77183 | 2026-10-11 | 8.8 High | ||
| The FooSales – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.43.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated attackers, with FooSales Cashier-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account. | ||||
| CVE-2026-6723 | 2026-10-11 | 5.3 Medium | ||
| The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 1.6.11.11. This is due to the appointment update REST API endpoint not restricting which fields can be modified by token-authenticated customers. This makes it possible for unauthenticated attackers to modify admin-controlled fields on that appointment, including faking payment confirmation, reassigning the appointment to another user, and changing the service type. | ||||
| CVE-2026-5727 | 2026-10-11 | 5.4 Medium | ||
| The Hello Plus plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to publish their own Hello+ header/footer templates and draft currently active templates owned by higher-privileged users. | ||||
| CVE-2026-3717 | 2026-10-11 | 5.3 Medium | ||
| The CV Builder – Professional Resume Builder SaaS plugin for WordPress is vulnerable to unauthorized arbitrary file upload due to a missing capability check on the 'wp_save_signature_image' function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to upload arbitrary content to the WordPress uploads directory as png files. | ||||
| CVE-2026-18496 | 2026-10-11 | 5.3 Medium | ||
| The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.4.3 via the wpbc_is_show_popover_in_flex_timeline() function. This makes it possible for unauthenticated attackers to extract sensitive data including names, email addresses, and phone numbers of customers who have made bookings. | ||||
| CVE-2026-15178 | 2026-10-11 | 5.4 Medium | ||
| The Fluent Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.2.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Custom-level access and above, to read private form submissions, change submission statuses, permanently delete submissions, and modify global plugin settings. | ||||
| CVE-2026-12626 | 2026-10-11 | 7.2 High | ||
| The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 28.2 via deserialization of untrusted input via the ‘value’ parameter. This makes it possible for authenticated attackers, with custom-level access and above, to inject a PHP Object. No known gadget chain is available. | ||||
| CVE-2026-108506 | 1 Zte | 1 Z80 Ultra | 2026-10-11 | 5.5 Medium |
| ZTE Z80 Ultra's system interfaces do not have robust invocation authentication, with inadequate access control. Third-party apps may call the interfaces through reflection and retrieve relevant information. | ||||
| CVE-2026-108505 | 1 Zte | 1 Z80 Ultra | 2026-10-11 | 3.3 Low |
| ZTE Z80 Ultra has a local information disclosure vulnerability. Third-party applications can capture data returned by system interfaces to obtain device-related information. | ||||
| CVE-2026-108504 | 1 Zte | 1 Z80 Ultra | 2026-10-11 | 5.5 Medium |
| ZTE Z80 Ultra has an unauthorized information disclosure vulnerability. The access control for methods within the framework is insufficient. An attacker can exploit this method to read device-related information. | ||||
| CVE-2026-108503 | 1 Zte | 1 Z80 Ultra | 2026-10-11 | 3.3 Low |
| ZTE Z80 Ultra has an interface permission validation vulnerability. The callable functions provided by the system lack sufficient access control. An attacker can leverage these functions to read relevant information. | ||||
| CVE-2026-108502 | 1 Zte | 1 Z80 Ultra | 2026-10-11 | 3.3 Low |
| ZTE Z80 Ultra contains an information disclosure vulnerability, through which third-party applications can read relevant information by hooking system APIs. | ||||
| CVE-2026-108501 | 1 Zte | 1 Zte Z80 Ultra | 2026-10-11 | 5.7 Medium |
| ZTE Z80 Ultra has a system interface permission verification defect. The interface lacks necessary access control, and relevant information can be read by reflectively invoking the interface. | ||||