🚨 CVE-2026-12966
The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers to tamper with other customers' orders, including forging a "payment sent" state, overwriting the payment-method label, and attaching forged payment-proof files.
🎖@cveNotify
The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers to tamper with other customers' orders, including forging a "payment sent" state, overwriting the payment-method label, and attaching forged payment-proof files.
🎖@cveNotify
WPScan
Direct Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering via digages AJAX Actions
See details on Direct Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering via digages AJAX Actions CVE 2026-12966. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13157
The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.
🎖@cveNotify
The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.
🎖@cveNotify
WPScan
Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload
See details on Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload CVE 2026-13157. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13158
The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.
🎖@cveNotify
The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.
🎖@cveNotify
WPScan
Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload
See details on Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload CVE 2026-13158. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13329
The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured orders.
🎖@cveNotify
The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured orders.
🎖@cveNotify
WPScan
WC Buckaroo BPE Gateway < 4.9.0 - Subscriber+ Unauthorized Order Refund
See details on WC Buckaroo BPE Gateway < 4.9.0 - Subscriber+ Unauthorized Order Refund CVE 2026-13329. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13596
The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.
🎖@cveNotify
The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.
🎖@cveNotify
WPScan
Participants Database < 2.7.8.4 - Unauthenticated SQL Injection via List Search
See details on Participants Database < 2.7.8.4 - Unauthenticated SQL Injection via List Search CVE 2026-13596. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13604
The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end page, that forwards client-supplied event data to the configured Facebook Conversions API using the administrator's stored access token. This allows an unauthenticated visitor to inject arbitrary conversion events into the administrator's Facebook ads account and exhaust the configured API quota.
🎖@cveNotify
The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end page, that forwards client-supplied event data to the configured Facebook Conversions API using the administrator's stored access token. This allows an unauthenticated visitor to inject arbitrary conversion events into the administrator's Facebook ads account and exhaust the configured API quota.
🎖@cveNotify
WPScan
Pixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo_event AJAX
See details on Pixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo_event AJAX CVE 2026-13604. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13725
The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX actions and reflects unsanitised user input in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.
🎖@cveNotify
The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX actions and reflects unsanitised user input in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.
🎖@cveNotify
WPScan
Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS via wdpAjax
See details on Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS via wdpAjax CVE 2026-13725. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13729
The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrative create and delete actions, allowing attackers to create rogue records or delete legitimate ones via a forged request (CSRF) when a logged-in administrator is tricked into visiting a crafted page.
🎖@cveNotify
The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrative create and delete actions, allowing attackers to create rogue records or delete legitimate ones via a forged request (CSRF) when a logged-in administrator is tricked into visiting a crafted page.
🎖@cveNotify
WPScan
Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation and Deletion via CSRF
See details on Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation and Deletion via CSRF CVE 2026-13729. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14195
The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role or higher to read the content of arbitrary posts, including other users' private, pending, and draft posts.
🎖@cveNotify
The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role or higher to read the content of arbitrary posts, including other users' private, pending, and draft posts.
🎖@cveNotify
WPScan
Brizy – Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure via get_post_info
See details on Brizy – Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure via get_post_info CVE 2026-14195. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14197
The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope.
🎖@cveNotify
The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope.
🎖@cveNotify
WPScan
Fluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOR
See details on Fluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOR CVE 2026-14197. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14214
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.
🎖@cveNotify
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.
🎖@cveNotify
WPScan
Amelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass Assignment
See details on Amelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass Assignment CVE 2026-14214. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14292
The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated visitors, who views a page displaying the package.
🎖@cveNotify
The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated visitors, who views a page displaying the package.
🎖@cveNotify
WPScan
WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title
See details on WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title CVE 2026-14292. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14309
The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS one-time-password password reset is enabled.
🎖@cveNotify
The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS one-time-password password reset is enabled.
🎖@cveNotify
WPScan
Chat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OTP Bypass
See details on Chat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OTP Bypass CVE 2026-14309. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14315
The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side advertising conversion APIs using the site's stored credentials.
🎖@cveNotify
The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side advertising conversion APIs using the site's stored credentials.
🎖@cveNotify
WPScan
Pixel Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event Submission
See details on Pixel Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event Submission CVE 2026-14315. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14561
The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know (including administrators) or to create arbitrary accounts.
🎖@cveNotify
The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know (including administrators) or to create arbitrary accounts.
🎖@cveNotify
WPScan
Authora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP Disclosure
See details on Authora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP Disclosure CVE 2026-14561. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14596
The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the base of the password-reset link it emails, allowing unauthenticated attackers to send a target user a legitimately-formatted reset email whose link points to an attacker-controlled host and carries a valid reset key, leading to account takeover when the victim clicks it.
🎖@cveNotify
The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the base of the password-reset link it emails, allowing unauthenticated attackers to send a target user a legitimately-formatted reset email whose link points to an attacker-controlled host and carries a valid reset key, leading to account takeover when the victim clicks it.
🎖@cveNotify
WPScan
DynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Password Reset Link Host Injection
See details on DynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Password Reset Link Host Injection CVE 2026-14596. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14823
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of events they do not own.
🎖@cveNotify
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of events they do not own.
🎖@cveNotify
WPScan
Event Tickets < 5.29.0.1 - Contributor+ Seating Layout and Ticket Inventory Modification via IDOR
See details on Event Tickets < 5.29.0.1 - Contributor+ Seating Layout and Ticket Inventory Modification via IDOR CVE 2026-14823. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14836
The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset verification-code flow, keying both the verification code and the per-source attempt counter on an unauthenticated, client-controlled value, allowing unauthenticated attackers to reset the limit at will and brute-force the code to take over any account, including administrators, when the verification-code reset mode is enabled.
🎖@cveNotify
The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset verification-code flow, keying both the verification code and the per-source attempt counter on an unauthenticated, client-controlled value, allowing unauthenticated attackers to reset the limit at will and brute-force the code to take over any account, including administrators, when the verification-code reset mode is enabled.
🎖@cveNotify
WPScan
Login/Signup Popup < 3.2.5 - Unauthenticated Account Takeover via Password Reset Rate Limit Bypass
See details on Login/Signup Popup < 3.2.5 - Unauthenticated Account Takeover via Password Reset Rate Limit Bypass CVE 2026-14836. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14839
The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public REST endpoint, allowing unauthenticated users to retrieve the title and full content of any post regardless of its status, including unpublished (draft, pending, private, and trashed) posts.
🎖@cveNotify
The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public REST endpoint, allowing unauthenticated users to retrieve the title and full content of any post regardless of its status, including unpublished (draft, pending, private, and trashed) posts.
🎖@cveNotify
WPScan
Mapster WP Maps < 1.24.0 - Unauthenticated Private and Draft Post Content Disclosure
See details on Mapster WP Maps < 1.24.0 - Unauthenticated Private and Draft Post Content Disclosure CVE 2026-14839. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14840
The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll.
🎖@cveNotify
The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll.
🎖@cveNotify
WPScan
YOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header Spoofing
See details on YOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header Spoofing CVE 2026-14840. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-15234
The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arbitrary HTML and JavaScript that executes in the session of any higher-privileged user (such as an administrator) who views the content.
🎖@cveNotify
The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arbitrary HTML and JavaScript that executes in the session of any higher-privileged user (such as an administrator) who views the content.
🎖@cveNotify
WPScan
Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute
See details on Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute CVE 2026-15234. View the latest Plugin Vulnerabilities on WPScan.