VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15873 CVEsRSS

CVE-2026-86709Critical· 9.8
1w ago

The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators.

The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators.

▾ MidnightEPSS 0.63%via NVD
CVE-2026-86446Low· 3.7
1w ago

The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is checked, allowing unauthenticated attackers to obtain the correct answer to every option of a question, along with the…

The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is checked, allowing unauthenticated attackers to obtain the correct answer to every option of a question, along with the…

▾ SunlitEPSS 0.28%via NVD
CVE-2025-15697High· 7.1
1w ago

The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attack…

The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attack…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-86710Critical· 9.8
1w ago

The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, includi…

The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, includi…

▾ MidnightEPSS 0.50%via NVD
CVE-2026-85130High· 8.8
1w ago

The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for the JavaScript context it is later output in on an administrative screen, allowing unauthenticated users to run arbitr…

The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for the JavaScript context it is later output in on an administrative screen, allowing unauthenticated users to run arbitr…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-85128High· 7.5
1w ago

The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to offer, allowing unauthenticated users to request any role, including admi…

The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to offer, allowing unauthenticated users to request any role, including admi…

▾ TwilightEPSS 0.32%via NVD
CVE-2026-86824Medium· 4.8
1w ago

The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed hash, allowing an unauthenticated attacker who recovers that key offline …

The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed hash, allowing an unauthenticated attacker who recovers that key offline …

▾ SunlitEPSS 0.15%via NVD
CVE-2026-86788Medium· 6.8
1w ago

The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several of its widgets and blocks to a safe allowlist, allowing users with contributor-level acces…

The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several of its widgets and blocks to a safe allowlist, allowing users with contributor-level acces…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-88904High· 8.8
1w ago

The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authenticated user, including subscribers, t…

The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authenticated user, including subscribers, t…

▾ TwilightEPSS 0.42%via NVD
CVE-2026-88792High· 8.8
1w ago

The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to store arbitrary web scripts which will execute when …

The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to store arbitrary web scripts which will execute when …

▾ TwilightEPSS 0.51%via NVD
CVE-2026-87836Low· 2.7
1w ago

The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export to content owned by the requesting user, allowing users with the Author role and abo…

The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export to content owned by the requesting user, allowing users with the Author role and abo…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-91014High· 7.1
1w ago

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run arbitrary web scripts …

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run arbitrary web scripts …

▾ TwilightEPSS 0.28%via NVD
CVE-2026-88795Critical· 9.0
1w ago

The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating it as a side effect of the check that is supposed to valida…

The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating it as a side effect of the check that is supposed to valida…

▾ MidnightEPSS 0.81%via NVD
CVE-2026-87786High· 8.8
1w ago

The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated users to store JavaScript that runs in the session of an a…

The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated users to store JavaScript that runs in the session of an a…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-91016Medium· 5.3
1w ago

The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private ca…

The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private ca…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-91011Medium· 6.8
1w ago

The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is s…

The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is s…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-91008Low· 3.7
1w ago

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attend…

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attend…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-91010Medium· 4.3
1w ago

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion AJAX action, and only tests that a nonce parameter is present rather tha…

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion AJAX action, and only tests that a nonce parameter is present rather tha…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-91009Medium· 4.3
1w ago

The Active Woot Products Tables for WooCommerce

The Active Woot Products Tables for WooCommerce. 100% FREE  WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, such as subscriber, to change the title …

▾ SunlitEPSS 0.14%via NVD
CVE-2026-90922Medium· 5.3
1w ago

The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a pai…

The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a pai…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-91015Medium· 5.3
1w ago

The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on a nonce that is publicly output to every visitor, allowi…

The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on a nonce that is publicly output to every visitor, allowi…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-90923Medium· 6.5
1w ago

The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders.

The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders.

▾ SunlitEPSS 0.27%via NVD
CVE-2026-91019Medium· 4.9
1w ago

The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe…

The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-50604Medium· 4.9
1w ago

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certai…

▾ SunlitAcer · Agent ServiceEPSS 0.21%via NVD
CVE-2026-24073High· 7.8
1w ago

Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.

Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.07%via NVD
CVE-2026-24081High· 7.4
1w ago

Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.

Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.

▾ Twilightqualcomm · ar8035_firmwareEPSS 0.10%via NVD
CVE-2026-24075High· 7.8
1w ago

Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.

Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.

▾ Twilightqualcomm · wsa8845h_firmwareEPSS 0.06%via NVD
CVE-2026-24074High· 7.8
1w ago

Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.

Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.

▾ Twilightqualcomm · iqx5121_firmwareEPSS 0.07%via NVD
CVE-2026-25261Medium· 6.7
1w ago

Memory corruption while processing rear sensor IOCTL calls.

Memory corruption while processing rear sensor IOCTL calls.

▾ Sunlitqualcomm · cologne_firmwareEPSS 0.07%via NVD
CVE-2025-59607High· 7.8
1w ago

Memory Corruption when copying large input data exceeds normal allocation limits.

Memory Corruption when copying large input data exceeds normal allocation limits.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.07%via NVD
CVEs tagged “cve.org” — page 164 · VulnSea