CVE tracker
394 subscribers
5.74K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-86707 - Private Feed Key <= 0.1 - Unauthenticated Authentication Bypass via 'feedkey' Parameter

CVE ID :CVE-2026-86707
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86709 - The Pressengine <= 1.0 - Unauthenticated Authentication Bypass

CVE ID :CVE-2026-86709
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86710 - Login with QR <= 1.0.0 - Unauthenticated Authentication Bypass via 'autologin_code' Parameter

CVE ID :CVE-2026-86710
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86788 - HT Mega 3.2.0 - 3.2.5 - Contributor+ Stored XSS via Section Headline Tag

CVE ID :CVE-2026-86788
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several of its widgets and blocks to a safe allowlist, allowing users with contributor-level access and above to store a crafted tag name that executes arbitrary JavaScript when the content is viewed, including by higher-privileged users who review or publish it.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86824 - Newsletter < 9.3.8 - Unauthenticated Subscriber PII Disclosure and Modification via Predictable Tracking Signature Key

CVE ID :CVE-2026-86824
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed hash, allowing an unauthenticated attacker who recovers that key offline to forge tracking links, obtain any subscriber's session token, and read and modify that subscriber's stored personal data.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87786 - Dewa Kirim <= 1.0.0 - Unauthenticated Stored XSS via Checkout Coordinates

CVE ID :CVE-2026-87786
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated users to store JavaScript that runs in the session of an administrator who later opens the order.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87836 - Comments Import & Export 2.1.11 - 2.5.3 - Author+ Comment PII Disclosure via Export

CVE ID :CVE-2026-87836
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export to content owned by the requesting user, allowing users with the Author role and above to retrieve every comment on the site, including commenter email addresses, IP addresses, unapproved comment content and comment meta.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88792 - Dictionary <= 1.0 - Unauthenticated Stored XSS via Direct Dictionary Update

CVE ID :CVE-2026-88792
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to store arbitrary web scripts which will execute when a user views an affected entry.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88795 - wpShopGermany IT-RECHT KANZLEI < 2.4 - Unauthenticated RCE via Predictable API Token

CVE ID :CVE-2026-88795
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating it as a side effect of the check that is supposed to validate it, allowing unauthenticated attackers to predict the token and use the access it grants to write arbitrary files, leading to remote code execution.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88904 - PuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privilege Escalation

CVE ID :CVE-2026-88904
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authenticated user, including subscribers, to add, modify and delete arbitrary blog options and thereby escalate their privileges.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90922 - Paid Member Subscriptions < 3.0.9 - Unauthenticated Membership Payment Bypass via PayPal Standard Amount and Currency Mismatch

CVE ID :CVE-2026-90922
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90923 - Autopay < 5.0.1 - Unauthenticated Cross-Customer Order Payment Parameter Disclosure and Deletion

CVE ID :CVE-2026-90923
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91008 - Event Booking Manager for WooCommerce < 5.3.8 - Unauthenticated Attendee PII Disclosure via Booking Confirmation Panel

CVE ID :CVE-2026-91008
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name, email address, phone number, and custom registration fields) by supplying an enumerable booking reference. Exploitation is limited to sites configured to use the Event Booking Manager for WooCommerce WordPress plugin before 5.3.8's native (non-WooCommerce) checkout, which is not the default.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91009 - Active Products Tables for WooCommerce < 2.1.3 - Subscriber+ Arbitrary Post Title Modification via woot_update_attachment

CVE ID :CVE-2026-91009
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The Active Woot Products Tables for WooCommerce. 100% FREE  WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, such as subscriber, to change the title of arbitrary posts, pages and products.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91010 - Invisible Anti-Spam & CAPTCHA < 5.1.1 - Subscriber+ Arbitrary Form Submission Deletion

CVE ID :CVE-2026-91010
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion AJAX action, and only tests that a nonce parameter is present rather than validating it, allowing any authenticated user, such as a subscriber, to permanently delete every form submission the Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 has stored.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91011 - EWWW Image Optimizer < 8.7.7 - Author+ Stored XSS via Image Class Attribute Backreference Expansion

CVE ID :CVE-2026-91011
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is stored in published content and executes in the browser of any user who later views the affected page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91014 - Realtyna Organic IDX plugin + WPL Real Estate < 5.4.2 - Reflected XSS via Location Selector Endpoint

CVE ID :CVE-2026-91014
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run arbitrary web scripts in a visitor's browser if they can trick the visitor into following a crafted link (reflected XSS).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91015 - Master Addons for Elementor < 3.1.9 - Unauthenticated Popup Deactivation via jltma_popup_disable_expired

CVE ID :CVE-2026-91015
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on a nonce that is publicly output to every visitor, allowing unauthenticated attackers to permanently disable any popup on the site.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91016 - Motors < 1.4.121 - Unauthenticated Draft/Private Listing Disclosure

CVE ID :CVE-2026-91016
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private car listings - including titles, prices, media URLs and seller notes - by supplying only the target's numeric user id.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91019 - Event Booking Manager for WooCommerce < 5.6.0 - Contributor+ Payment Gateway Credential Disclosure

CVE ID :CVE-2026-91019
Published : Sept. 17, 2026, 6 a.m. | 15 minutes ago
Description :The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44940 - Service token exposure and potential privilege escalation in SUSE Observability

CVE ID :CVE-2026-44940
Published : Sept. 17, 2026, 7:16 a.m. | 3 hours ago
Description :The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment.
Severity: 5.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...