VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15818 CVEsRSS

CVE-2026-18442High· 7.5
1w ago

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'wcfmmp_user_location_lng' parameter in all versions up to, and including, 3.8.2 due to insufficient escap…

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'wcfmmp_user_location_lng' parameter in all versions up to, and including, 3.8.2 due to insufficient escap…

▾ Twilightwclovers · WCFM Marketplace – Multivendor Marketplace for WooCommerceEPSS 0.50%via NVD
CVE-2026-17607Medium· 6.5
1w ago

The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1

The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1. This is due to insufficient escaping on the user-sup…

▾ Sunlitchuck1982 · WP Inventory ManagerEPSS 0.34%via NVD
CVE-2026-17586Medium· 6.4
1w ago

The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vkExUnit_cta_img_position' Post Meta in all versions up to, and including, 9.118.0 due to insufficient input sanitization and output …

The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vkExUnit_cta_img_position' Post Meta in all versions up to, and including, 9.118.0 due to insufficient input sanitization and output …

▾ Sunlitkurudrive · VK All in One Expansion UnitEPSS 0.31%via NVD
CVE-2026-16777Medium· 4.9
1w ago

The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.0 via the 'filename' parameter parameter

The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.0 via the 'filename' parameter parameter. This makes i…

▾ Sunlitjkohlbach · Store Exporter – Export WooCommerce Products, Orders, Subscriptions, CustomersEPSS 0.66%via NVD
CVE-2026-15275High· 7.5
1w ago

The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied par…

The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied par…

▾ Twilightwpexpertsio · WP Multi Store Locator ProEPSS 0.37%via NVD
CVE-2026-15004Medium· 5.4
1w ago

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions up to, and including, 6.5.6 due to insufficient input sanitization and out…

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions up to, and including, 6.5.6 due to insufficient input sanitization and out…

▾ Sunlitninjateam · FileBird – WordPress Media Library Folders & File ManagerEPSS 0.24%via NVD
CVE-2026-14472Medium· 6.4
1w ago

The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block Content in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping

The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block Content in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping. This ma…

▾ Sunlitextendthemes · Kubio AI Page BuilderEPSS 0.26%via NVD
CVE-2026-14323High· 7.5
1w ago

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter. This makes it possible for unauthenticated att…

▾ Twilightprintcart · Printcart Store – Web to Print Product Designer for WooCommerceEPSS 0.94%via NVD
CVE-2026-13471Medium· 4.3
1w ago

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via the LatePointAbilityDeleteBooking::execute due to …

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via the LatePointAbilityDeleteBooking::execute due to …

▾ Sunlitlatepoint · Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPressEPSS 0.33%via NVD
CVE-2026-12954High· 8.8
1w ago

The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function

The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function. This is due to the function performing no nonce verification, no cap…

▾ Twilightmapster · Mapster WP MapsEPSS 0.46%via NVD
CVE-2026-12739Medium· 4.3
1w ago

The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0

The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is author…

▾ Sunlitsaadiqbal · WP Easy Pay – Payment and Donation Form Builder for SquareEPSS 0.34%via NVD
CVE-2026-12384High· 8.8
1w ago

Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. This issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026. NOTE: The vendor was contacted early ab…

Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. This issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026. NOTE: The vendor was contacted early ab…

▾ TwilightTECHIN2B · TECHIN2B ApplicationEPSS 0.31%via NVD
CVE-2026-11757Medium· 6.1
1w ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Technologies Ltd

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Technologies Ltd. Co. Bar Association Website allows Reflected XSS. This issue affects Bar Association Website: through…

▾ SunlitKA Informatics Technologies Ltd. Co. · Bar Association WebsiteEPSS 0.18%via NVD
CVE-2026-89059High· 7.5PoC
1w ago

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafte…

▾ MidnightRed Hat · RESTEasyEPSS 0.79%via NVD
CVE-2026-92714Medium· 6.5
1w ago

The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init

The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic…

▾ Sunlitcodename065 · Download ManagerEPSS 0.41%via NVD
CVE-2026-92619High· 7.2
1w ago

The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action

The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action. The vulnerability exists because the `handle_ajax_save()` function …

▾ Twilightwpdevelop · Booking CalendarEPSS 0.66%via NVD
CVE-2026-89058High· 7.4PoC
1w ago

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. Thi…

▾ MidnightRed Hat · RESTEasyEPSS 0.47%via NVD
CVE-2026-92561Medium· 6.1
1w ago

The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to, and including, 11.8.2 due to insufficient input sanitization and output escaping

The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to, and including, 11.8.2 due to insufficient input sanitization and output escaping. This makes it …

▾ Sunlitwpdevelop · Booking CalendarEPSS 0.41%via NVD
CVE-2026-91707Medium· 5.3
1w ago

The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.11.1

The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.11.1. This is due to the software allowing users to execute an action that does not properly validate a value before …

▾ SunlitElegant Themes · DiviEPSS 0.45%via NVD
CVE-2026-89413High· 8.1
1w ago

The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4

The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it pos…

▾ Twilightfarazfrank · Filter GalleryEPSS 0.54%via NVD
CVE-2026-89330Medium· 6.1
1w ago

The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'unique' parameter in all versions up to, and inclu…

The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'unique' parameter in all versions up to, and inclu…

▾ Sunlitwpdevteam · EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documentsEPSS 0.37%via NVD
CVE-2026-89278Medium· 5.3
1w ago

The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.34.6 via the enqueue_frontend_scr…

The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.34.6 via the enqueue_frontend_scr…

▾ Sunlitjohn-dagelmore · GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AIEPSS 0.44%via NVD
CVE-2026-89138Medium· 4.3
1w ago

The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4

The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it pos…

▾ Sunlitfarazfrank · Filter GalleryEPSS 0.39%via NVD
CVE-2026-84909Medium· 6.4
1w ago

The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute in all versions up to, and including, 2.8.0 due to insufficient input san…

The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute in all versions up to, and including, 2.8.0 due to insufficient input san…

▾ Sunlitsmub · Custom Twitter Feeds – A Tweets Widget or X Feed WidgetEPSS 0.41%via NVD
CVE-2026-75017Medium· 4.3
1w ago

The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.6

The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.6. This is due to t…

▾ Sunlitwpblockart · Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post GridEPSS 0.42%via NVD
CVE-2026-75016Medium· 6.4
1w ago

The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's clientId attribute in versions up to, and including, 1.8.6

The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's clientId attribute in versions up to, and including, 1.8.6. This is due to insufficient input sanitization and output escap…

▾ Sunlitwpblockart · Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post GridEPSS 0.35%via NVD
CVE-2026-18317Medium· 4.3
1w ago

The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.3

The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.3. This is due to the plugin not properly verifying tha…

▾ Sunlitfoxtheme · Foxtool All-in-One: Contact chat button, Custom login, Media optimize imagesEPSS 0.21%via NVD
CVE-2026-17576Medium· 6.5
1w ago

The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, and including, 1.13.9

The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, and including, 1.13.9. This is due to insufficient escaping on the array-key names supplied in the JSON request body…

▾ Sunlitrevmakx · InfiniteWP ClientEPSS 0.27%via NVD
CVE-2026-12106Medium· 6.4
1w ago

The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the downloadImage function

The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the downloadImage function. This makes it possible for authenticated attackers, with contrib…

▾ Sunlitairani · Auto Upload ImagesEPSS 0.25%via NVD
CVE-2024-38639Medium· 4.8
1w ago

An improper authentication vulnerability has been reported to affect product

An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system. QTS is not affected. We have already fixed the vulnerability…

▾ SunlitQNAP Systems Inc. · QTSEPSS 0.25%via NVD
CVEs tagged “cve.org” — page 127 · VulnSea