VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15490 CVEsRSS

CVE-2026-93654High· 7.2
3d ago

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cart_items[][product_name]' Parameter in all versions up to, and including, 7.2.1 due to insufficient input sani…

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cart_items[][product_name]' Parameter in all versions up to, and including, 7.2.1 due to insufficient input sani…

▾ Twilightcodename065 · Premium Packages – Sell Digital Products SecurelyEPSS 0.24%via NVD
CVE-2026-92713High· 8.1
3d ago

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2. This m…

▾ Twilightwpchill · Modula Image Gallery – Photo Grid & Video GalleryEPSS 0.27%via NVD
CVE-2026-96568High· 7.2
3d ago

The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_number' parameter in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escap…

The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_number' parameter in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escap…

▾ Twilightjetmonsters · Restaurant Menu and Food OrderingEPSS 0.24%via NVD
CVE-2026-93656Medium· 6.4
3d ago

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insuffic…

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insuffic…

▾ Sunlitcozmoslabs · User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role EditorEPSS 0.20%via NVD
CVE-2026-94573High· 7.2
3d ago

The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping

The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping. Th…

▾ Twilightaddonsorg · Repeater Fields for Elementor FormsEPSS 0.24%via NVD
CVE-2026-89426High· 8.8
3d ago

The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.6.1.0

The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.6.1.0. This is due to the `maybe_update_user_role()` function reading the ta…

▾ Twilightknitpay · Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and moreEPSS 0.47%via NVD
CVE-2026-95866High· 7.2
3d ago

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insuffic…

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insuffic…

▾ Twilightcozmoslabs · User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role EditorEPSS 0.26%via NVD
CVE-2026-17602Medium· 4.9
3d ago

The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.7.42 via the 'file_name' parameter parameter

The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.7.42 via the 'file_name' parameter parameter. This makes it possible for authenti…

▾ Sunlitsslzen · SSL Zen — SSL Certificate Installer & HTTPS RedirectsEPSS 0.56%via NVD
CVE-2026-13179Medium· 6.4
3d ago

The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shapes_values Parameter in all versions up to, and including, 4.9.8 due to ins…

The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shapes_values Parameter in all versions up to, and including, 4.9.8 due to ins…

▾ Sunlitflippercode · WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters & ListingsEPSS 0.33%via NVD
CVE-2026-95864High· 7.2
3d ago

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'css[fonts]' Parameter in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'css[fonts]' Parameter in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possib…

▾ Twilightthemifyme · Themify BuilderEPSS 0.27%via NVD
CVE-2026-92609Critical· 9.8⚖ disputed
3d ago

Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affect…

Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affect…

▾ MidnightApache Software Foundation · org.apache.qpid:qpid-broker-plugins-management-httpEPSS 0.38%via NVD
CVE-2026-93901High· 7.3
3d ago

The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.7.5

The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.7.5. This is due to the `provisionBlogCredentials()` function in `iHomefinderAdmin.php` being reachable via the `wp…

▾ Twilightihomefinder · Optima Express IDXEPSS 0.35%via NVD
CVE-2026-92608High· 7.5
3d ago

Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties that the target encoder does not handl…

Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties that the target encoder does not handl…

▾ TwilightApache Software Foundation · org.apache.qpid:qpid-broker-plugins-amqp-msg-conv-0-10-to-1-0EPSS 0.32%via NVD
CVE-2026-89406High· 7.5
3d ago

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up to, and including, 3.0.1

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up to, and including, 3.0.1. This is due to the Modula_Meta::add_metas() function…

▾ Twilightwpchill · Modula Image Gallery – Photo Grid & Video GalleryEPSS 0.39%via NVD
CVE-2026-93477Medium· 5.9
3d ago

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the bulk destroy and bulk update paths. Action arguments decl…

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the bulk destroy and bulk update paths. Action arguments decl…

▾ Sunlitash-project · ashEPSS 0.20%via NVD
CVE-2026-97846Medium· 6.8
3d ago

Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by binding it to their digital certificate

Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by binding it to their digital certificate. A flaw was discovered where the new Standard…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.14%via NVD
CVE-2026-78393Medium· 6.1
3d ago

The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the addresses of links it generates on its front-end directory pages, leading to Reflected Cross-Site Scripting which could…

The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the addresses of links it generates on its front-end directory pages, leading to Reflected Cross-Site Scripting which could…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-78397Medium· 4.0
3d ago

The Link Library WordPress plugin before 7.9.6 does not validate the destination of a user-supplied URL before falling back to an unprotected fetch when its safe request is rejected, allowing unauthenticated visitors to make the site iss…

The Link Library WordPress plugin before 7.9.6 does not validate the destination of a user-supplied URL before falling back to an unprotected fetch when its safe request is rejected, allowing unauthenticated visitors to make the site iss…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-78394Medium· 4.1
3d ago

The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a generated image to disk, allowing users with the Contributor role and above to create directories and write or overwrite…

The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a generated image to disk, allowing users with the Contributor role and above to create directories and write or overwrite…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-75553Low· 2.4
3d ago

Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a hard-coded cryptographic key from the affected product.

Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a hard-coded cryptographic key from the affected product.

▾ SunlitTohoku Electric Power Company, Incorporated · Tohoku Electric Power "Yorisou e Net" Android AppEPSS 0.14%via NVD
CVE-2026-93897Medium· 6.4
3d ago

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text-type Custom Field (e.g., 'phone') in all versions up to, and including, 2.8.181 …

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text-type Custom Field (e.g., 'phone') in all versions up to, and including, 2.8.181 …

▾ Sunlitpaoltaia · GeoDirectory – WP Business Directory Plugin and Classified Listings DirectoryEPSS 0.22%via NVD
CVE-2026-62062High· 8.8PoC
3d ago

Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1.

Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1.

▾ MidnightElementor · elementorEPSS 0.13%via NVD
CVE-2026-92212Medium· 6.1
3d ago

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field in all versions up to, and including, 3.6.5.3 due to …

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field in all versions up to, and including, 3.6.5.3 due to …

▾ Sunlitjetmonsters · JetFormBuilder — Dynamic Blocks Form BuilderEPSS 0.21%via NVD
CVE-2026-84281High· 7.2
3d ago

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output …

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output …

▾ Twilightradykal · Fancy Product DesignerEPSS 0.21%via NVD
CVE-2026-83591High· 7.2
3d ago

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Regex Transformation in all versions up to, and including, 1.1.16 due to insufficient input sanitization …

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Regex Transformation in all versions up to, and including, 1.1.16 due to insufficient input sanitization …

▾ Twilightmohammed_kaludi · AMP for WP – Accelerated Mobile PagesEPSS 0.25%via NVD
CVE-2026-96766Medium· 6.4
3d ago

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_hours' parameter in all versions up to, and including, 2.8.183 due to i…

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_hours' parameter in all versions up to, and including, 2.8.183 due to i…

▾ Sunlitpaoltaia · GeoDirectory – WP Business Directory Plugin and Classified Listings DirectoryEPSS 0.20%via NVD
CVE-2026-19775Medium· 4.3
3d ago

The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.7

The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying that a user …

▾ Sunlitallterraindeveloper · OpenStation: Desktop Windows, Dock & Virtual Desktops for WP AdminEPSS 0.23%via NVD
CVE-2026-93899Medium· 6.5
3d ago

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to generic SQL Injection via 'group_id' Message Meta Parameter in all versions up to, and including, 3.0.4 due to insufficie…

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to generic SQL Injection via 'group_id' Message Meta Parameter in all versions up to, and including, 3.0.4 due to insufficie…

▾ Sunlitwordplus · Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat BotsEPSS 0.27%via NVD
CVE-2026-89055Critical· 9.1PoC
3d ago

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an actio…

▾ Abyssalivole · Customer Reviews for WooCommerceEPSS 0.39%via NVD
CVE-2026-92829Medium· 4.3
3d ago

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.1.0

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.1.0. This is due to the plugin not properly verifying that a user is authorized to per…

▾ Sunlitpr-gateway · Blog2Social: Social Media Auto Post & SchedulerEPSS 0.32%via NVD
CVEs tagged “cve.org” — page 35 · VulnSea