CVE-2026-82223 - WordPress WP Event SOlution plugin <= 4.1.22 - Broken Access Control vulnerability
CVE ID :CVE-2026-82223
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-82223
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-83562 - WordPress WCFM Marketplace plugin <= 3.8.2 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-83562
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-83562
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84759 - WordPress Activity Log plugin <= 2.13.1 - Cross Site Request Forgery (CSRF) vulnerability
CVE ID :CVE-2026-84759
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84759
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84760 - WordPress Ultimate Gift Cards For WooCommerce plugin <= 3.2.9 - Broken Access Control vulnerability
CVE ID :CVE-2026-84760
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84760
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84764 - WordPress Simply Schedule Appointments plugin <= 1.6.12.23 - Cross Site Request Forgery (CSRF) vulnerability
CVE ID :CVE-2026-84764
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84764
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84770 - WordPress Mang Board WP plugin <= 2.3.8 - Cross Site Request Forgery (CSRF) vulnerability
CVE ID :CVE-2026-84770
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84770
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84771 - WordPress PublishPress Permissions plugin <= 4.8.3 - Insecure Direct Object References (IDOR) vulnerability
CVE ID :CVE-2026-84771
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84771
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84772 - WordPress Broken Link Checker plugin <= 2.4.14 - Server Side Request Forgery (SSRF) vulnerability
CVE ID :CVE-2026-84772
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84772
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84775 - WordPress Really Simple SSL plugin <= 9.8.0 - Denial of Service Attack vulnerability
CVE ID :CVE-2026-84775
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84775
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84780 - WordPress WP Go Maps plugin <= 10.1.08 - Denial of Service Attack vulnerability
CVE ID :CVE-2026-84780
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84780
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66652 - WordPress Grand Tour theme <= 5.5.1 - Cross Site Request Forgery (CSRF) vulnerability
CVE ID :CVE-2026-66652
Published : Sept. 2, 2026, 11:50 a.m. | 22 minutes ago
Description :Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery. This issue affects Grand Tour: from n/a through 5.5.1.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66652
Published : Sept. 2, 2026, 11:50 a.m. | 22 minutes ago
Description :Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery. This issue affects Grand Tour: from n/a through 5.5.1.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84835 - WordPress Rentsyst plugin <= 2.1.2 - Broken Access Control vulnerability
CVE ID :CVE-2026-84835
Published : Sept. 2, 2026, 11:52 a.m. | 19 minutes ago
Description :Missing Authorization vulnerability in DimaFreund Rentsyst allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rentsyst: from n/a through 2.1.2.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84835
Published : Sept. 2, 2026, 11:52 a.m. | 19 minutes ago
Description :Missing Authorization vulnerability in DimaFreund Rentsyst allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rentsyst: from n/a through 2.1.2.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78591 - Kibana Fleet Path Traversal Vulnerability
CVE ID :CVE-2026-78591
Published : Sept. 2, 2026, 3:17 p.m. | 55 minutes ago
Description :Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged user could cause a subsequent action taken by a higher-privileged user in the Fleet administration interface to act on an unintended target, resulting in the deletion of resources including accounts with elevated privileges.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78591
Published : Sept. 2, 2026, 3:17 p.m. | 55 minutes ago
Description :Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged user could cause a subsequent action taken by a higher-privileged user in the Fleet administration interface to act on an unintended target, resulting in the deletion of resources including accounts with elevated privileges.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78594 - Elastic APM Server Improper Handling of Highly Compressed Data Denial of Service
CVE ID :CVE-2026-78594
Published : Sept. 2, 2026, 3:17 p.m. | 55 minutes ago
Description :Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source map content could store specially crafted, highly compressed content that exhausts the memory available to APM Server when it is later processed, terminating the process. The condition recurs on every restart until the stored content is removed.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78594
Published : Sept. 2, 2026, 3:17 p.m. | 55 minutes ago
Description :Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source map content could store specially crafted, highly compressed content that exhausts the memory available to APM Server when it is later processed, terminating the process. The condition recurs on every restart until the stored content is removed.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78598 - Kibana Machine Learning Incorrect Authorization Vulnerability
CVE ID :CVE-2026-78598
Published : Sept. 2, 2026, 3:17 p.m. | 55 minutes ago
Description :Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single Kibana space could cause a job's saved object to become accessible across all spaces in the Kibana instance, without holding access rights to those additional spaces.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78598
Published : Sept. 2, 2026, 3:17 p.m. | 55 minutes ago
Description :Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single Kibana space could cause a job's saved object to become accessible across all spaces in the Kibana instance, without holding access rights to those additional spaces.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78599 - Kibana Fleet Path Traversal Vulnerability
CVE ID :CVE-2026-78599
Published : Sept. 2, 2026, 3:17 p.m. | 55 minutes ago
Description :Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet write access could cause a subsequent administrative delete action to act on unintended internal resources. Exploitation requires an administrator to interact with the affected Fleet interface.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78599
Published : Sept. 2, 2026, 3:17 p.m. | 55 minutes ago
Description :Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet write access could cause a subsequent administrative delete action to act on unintended internal resources. Exploitation requires an administrator to interact with the affected Fleet interface.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78600 - Elastic Cloud on Kubernetes Incomplete Cleanup Privilege Escalation
CVE ID :CVE-2026-78600
Published : Sept. 2, 2026, 3:17 p.m. | 55 minutes ago
Description :Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to retain unauthorized read access to the associated Elasticsearch cluster.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78600
Published : Sept. 2, 2026, 3:17 p.m. | 55 minutes ago
Description :Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to retain unauthorized read access to the associated Elasticsearch cluster.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78601 - Kibana Missing Authorization Vulnerability
CVE ID :CVE-2026-78601
Published : Sept. 2, 2026, 3:17 p.m. | 55 minutes ago
Description :Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation, allowing an authenticated user with elevated Kibana privileges to indirectly cause a background task to read from Elasticsearch indices that user is not authorized to access. Derived entity data from those indices is then exposed through the entity store output.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78601
Published : Sept. 2, 2026, 3:17 p.m. | 55 minutes ago
Description :Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation, allowing an authenticated user with elevated Kibana privileges to indirectly cause a background task to read from Elasticsearch indices that user is not authorized to access. Derived entity data from those indices is then exposed through the entity store output.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78602 - Elastic Maps Server Path Traversal Vulnerability
CVE ID :CVE-2026-78602
Published : Sept. 2, 2026, 3:17 p.m. | 55 minutes ago
Description :Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach the service over the network could cause it to return the contents of files outside its intended content directory that are readable by the server process.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78602
Published : Sept. 2, 2026, 3:17 p.m. | 55 minutes ago
Description :Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach the service over the network could cause it to return the contents of files outside its intended content directory that are readable by the server process.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78604 - Elastic Agent Incorrect Permission Assignment Privilege Escalation
CVE ID :CVE-2026-78604
Published : Sept. 2, 2026, 3:17 p.m. | 55 minutes ago
Description :Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code of their choosing, ultimately obtaining SYSTEM-level privileges on the host.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78604
Published : Sept. 2, 2026, 3:17 p.m. | 55 minutes ago
Description :Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code of their choosing, ultimately obtaining SYSTEM-level privileges on the host.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78609 - Elastic Cloud on Kubernetes Incorrect Authorization Vulnerability
CVE ID :CVE-2026-78609
Published : Sept. 2, 2026, 3:17 p.m. | 55 minutes ago
Description :Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate material to be included in the Elasticsearch client trust bundle managed by ECK in a separate namespace.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78609
Published : Sept. 2, 2026, 3:17 p.m. | 55 minutes ago
Description :Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate material to be included in the Elasticsearch client trust bundle managed by ECK in a separate namespace.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...