CVE tracker
394 subscribers
5.74K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-84904 - King Addons for Elementor 51.1.56 - 51.1.80 - Author+ Missing Authorization via Image Optimizer

CVE ID :CVE-2026-84904
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and never confirming ownership of the targeted object, allowing authenticated users with author-level access and above to disclose absolute file paths for, overwrite the bytes of, and site-wide re-reference media belonging to other users, including administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85009 - RestroPress <= 3.4.6 - Unauthenticated Order Enumeration and Order Note Modification via Payment Recovery

CVE ID :CVE-2026-85009
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverable state and to write notes to another customer's order.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85122 - Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Stored XSS via Form Type Confusion

CVE ID :CVE-2026-85122
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unescaped in an admin page, leading to Stored XSS.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85123 - Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Registration Policy Bypass via Login Form Type Confusion

CVE ID :CVE-2026-85123
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to create WordPress accounts on a site whose owner has disabled registration.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85127 - VikBooking 1.8.8 - 1.8.14 - Unauthenticated Stored XSS via SVG Chat Attachment

CVE ID :CVE-2026-85127
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85350 - UpsellWP < 2.2.10 - Unauthenticated Price Manipulation via Frequently Bought Together

CVE ID :CVE-2026-85350
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, allowing unauthenticated users to buy arbitrary products at the campaign's discounted price.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87767 - WP Shortcut Link <= 1.2.0 - Unauthenticated SQL Injection via url

CVE ID :CVE-2026-87767
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter before using it in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87770 - Price Drop Alert for WooCommerce <= 1.1 - Unauthenticated SQL Injection via product

CVE ID :CVE-2026-87770
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using them in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87771 - Product Question and Answer <= 1.1.0 - Unauthenticated SQL Injection via p_id and read

CVE ID :CVE-2026-87771
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them in SQL queries on AJAX actions available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87774 - Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQL Injection via week

CVE ID :CVE-2026-87774
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87775 - Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQLi via tzwrs_update_cell

CVE ID :CVE-2026-87775
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87965 - Easy Appointments < 4.0.2.2 - Unauthenticated Appointment Cancellation/Confirmation via Forgeable Email-Link Token

CVE ID :CVE-2026-87965
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointment cancellation and confirmation action, deriving the token from a hardcoded source-embedded salt and the appointment's creation timestamp, so unauthenticated attackers who know or guess that timestamp can cancel or confirm arbitrary appointments.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87966 - Easy Appointments 4.0 - 4.0.2.1 - Unauthenticated Arbitrary Appointment Modification and Deletion via IDOR

CVE ID :CVE-2026-87966
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied id, allowing unauthenticated attackers to overwrite, and through a follow-on cleanup delete, arbitrary appointments.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88798 - Really Simple Security (Free) < 9.8.3 - Unauthenticated Unbounded Option Growth via Spoofed Client IP Header

CVE ID :CVE-2026-88798
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88825 - iGMS Direct Booking < 2.0 - Unauthenticated Stored XSS via Widget Settings

CVE ID :CVE-2026-88825
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowing unauthenticated users to store arbitrary web scripts that execute in the context of an administrator viewing the iGMS Direct Booking WordPress plugin before 2.0 settings, and in the browser of any visitor to a page displaying the booking widget.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88844 - MasterStudy LMS 3.6.2 - < 3.7.50 - Instructor+ Student PII Disclosure via IDOR

CVE ID :CVE-2026-88844
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the course before returning its enrolled-student data, allowing users with the MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50's Instructor role to disclose the names and email addresses of students enrolled in other instructors' courses.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88993 - All Bootstrap Blocks <= 1.3.31 - Contributor+ Stored XSS via areoi/button type Attribute

CVE ID :CVE-2026-88993
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with Contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-89007 - Bookit < 2.6.0.5 - Bookit Staff+ Arbitrary Appointment Deletion via Missing Authorization

CVE ID :CVE-2026-89007
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users with its low-privileged custom Staff role to delete arbitrary appointments.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-89008 - Bookit < 2.6.0.5 - Bookit Staff+ Appointment PII Disclosure

CVE ID :CVE-2026-89008
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-retrieval actions, allowing users with a low-privilege Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5-specific role to read other users' appointment records, including customer names, email addresses, phone numbers and private booking comments.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90978 - Filter Gallery < 1.1.5 - Subscriber+ Arbitrary Post Overwrite and Plugin Option Deletion via Fail-Open Nonce Check

CVE ID :CVE-2026-90978
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonce field is omitted, and applies no capability check, allowing low-privileged users to overwrite the content of arbitrary posts and delete the Filter Gallery WordPress plugin before 1.1.5's stored gallery options.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90984 - Generate PDF using Contact Form 7 < 4.2.2 - Unauthenticated Server-Side Request Forgery via Array-Valued Form Field

CVE ID :CVE-2026-90984
Published : Sept. 18, 2026, 6 a.m. | 19 minutes ago
Description :The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its PDF renderer performs on submitted form content, allowing unauthenticated users to make the server request internal resources and read the response back through the generated PDF.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...