π¨ CVE-2026-15151
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's settings) to reset the site's configured booking notification rules.
π@cveNotify
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's settings) to reset the site's configured booking notification rules.
π@cveNotify
WPScan
Five Star Restaurant Reservations < 2.7.23 - Booking Manager+ Missing Authorization via rtb_reset_notifications
See details on Five Star Restaurant Reservations < 2.7.23 - Booking Manager+ Missing Authorization via rtb_reset_notifications CVE 2026-15151. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-15206
The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fresh, attacker-supplied phone number to select the account and logs them in. An unauthenticated attacker can therefore log in as any user, including an administrator, who has a billing phone on file.
π@cveNotify
The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fresh, attacker-supplied phone number to select the account and logs them in. An unauthenticated attacker can therefore log in as any user, including an administrator, who has a billing phone on file.
π@cveNotify
WPScan
SMS Alert Order Notifications β WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-withβ¦
See details on SMS Alert Order Notifications β WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-with-Mobile CVE 2026-15206. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-15236
The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing long-term compromise of the linked account.
π@cveNotify
The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing long-term compromise of the linked account.
π@cveNotify
WPScan
Gallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token Disclosure
See details on Gallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token Disclosure CVE 2026-15236. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-15241
The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to retrieve indexed knowledge-base content.
π@cveNotify
The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to retrieve indexed knowledge-base content.
π@cveNotify
WPScan
ChatBot for eCommerce β WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_response
See details on ChatBot for eCommerce β WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_response CVE 2026-15241. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-15385
The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-menu-item settings; its only gate is a nonce that any logged-in user can read from a standard admin page. A subscriber-level user can therefore enable the mega menu on a site menu and store a menu-item style value that is rendered, without output escaping, into a style attribute on the public navigation. By breaking out of that attribute the user persists a JavaScript event handler that executes for every visitor who hovers the navigation, including administrators, leading to session/site takeover.
π@cveNotify
The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-menu-item settings; its only gate is a nonce that any logged-in user can read from a standard admin page. A subscriber-level user can therefore enable the mega menu on a site menu and store a menu-item style value that is rendered, without output escaping, into a style attribute on the public navigation. By breaking out of that attribute the user persists a JavaScript event handler that executes for every visitor who hovers the navigation, including administrators, leading to session/site takeover.
π@cveNotify
WPScan
RT Mega Menu < 1.5.2 - Subscriber+ Stored XSS via Menu Item CSS
See details on RT Mega Menu < 1.5.2 - Subscriber+ Stored XSS via Menu Item CSS CVE 2026-15385. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-16063
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author role and above to inject arbitrary JavaScript that executes in the browser of any visitor viewing the event, including administrators.
π@cveNotify
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author role and above to inject arbitrary JavaScript that executes in the browser of any visitor viewing the event, including administrators.
π@cveNotify
WPScan
Event Booking Manager for WooCommerce < 5.3.7 - Author+ Stored XSS via Event Timeline Content
See details on Event Booking Manager for WooCommerce < 5.3.7 - Author+ Stored XSS via Event Timeline Content CVE 2026-16063. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-16261
The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's password or log in as any existing account, including administrators, and take over the site.
π@cveNotify
The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's password or log in as any existing account, including administrators, and take over the site.
π@cveNotify
WPScan
Huge IT Login <= 1.0.4 - Unauthenticated Account Takeover
See details on Huge IT Login <= 1.0.4 - Unauthenticated Account Takeover CVE 2026-16261. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-16273
The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any higher-privileged user who views the affected post.
π@cveNotify
The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any higher-privileged user who views the affected post.
π@cveNotify
WPScan
Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta
See details on Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta CVE 2026-16273. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-16285
The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment β including private or unlinked uploads β by enumerating its numeric ID.
π@cveNotify
The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment β including private or unlinked uploads β by enumerating its numeric ID.
π@cveNotify
WPScan
WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download
See details on WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download CVE 2026-16285. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-13340
The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves them as SVG, allowing a user permitted to upload SVGs (such as an Author once granted upload access) to store a script-bearing file that executes in the browser of anyone who later views it, including an administrator.
π@cveNotify
The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves them as SVG, allowing a user permitted to upload SVGs (such as an Author once granted upload access) to store a script-bearing file that executes in the browser of anyone who later views it, including an administrator.
π@cveNotify
WPScan
SVG Support < 2.5.17 - Author+ Stored XSS via .svgz Sanitization Bypass
See details on SVG Support < 2.5.17 - Author+ Stored XSS via .svgz Sanitization Bypass CVE 2026-13340. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-15260
The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying arbitrary record IDs.
π@cveNotify
The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation records by supplying arbitrary record IDs.
π@cveNotify
WPScan
Geo My WP < 4.5.5.3 - Subscriber+ Arbitrary Geolocation Record Modification and Deletion via IDOR
See details on Geo My WP < 4.5.5.3 - Subscriber+ Arbitrary Geolocation Record Modification and Deletion via IDOR CVE 2026-15260. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-15383
The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauthenticated tracking REST endpoint and later renders unescaped in an administrator report page. This allows an unauthenticated attacker to store a malicious script that executes in the session of any administrator who views the access report, leading to site takeover.
π@cveNotify
The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauthenticated tracking REST endpoint and later renders unescaped in an administrator report page. This allows an unauthenticated attacker to store a malicious script that executes in the session of any administrator who views the access report, leading to site takeover.
π@cveNotify
WPScan
Blog Floating Button <= 1.4.20 - Unauthenticated Stored XSS via User-Agent Header
See details on Blog Floating Button <= 1.4.20 - Unauthenticated Stored XSS via User-Agent Header CVE 2026-15383. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-15930
The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data (including the email address) and take over that account through the password reset flow.
π@cveNotify
The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data (including the email address) and take over that account through the password reset flow.
π@cveNotify
WPScan
Simple Membership < 4.7.8 - Unauthenticated Administrator Account Takeover via Registration Username Collision
See details on Simple Membership < 4.7.8 - Unauthenticated Administrator Account Takeover via Registration Username Collision CVE 2026-15930. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-15931
The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when displaying it in the administration dashboard, allowing unauthenticated attackers to store arbitrary JavaScript that executes in an administrator's session.
π@cveNotify
The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when displaying it in the administration dashboard, allowing unauthenticated attackers to store arbitrary JavaScript that executes in an administrator's session.
π@cveNotify
WPScan
Simple Membership < 4.7.8 - Unauthenticated Stored XSS via PayPal Subscription Subscriber Name
See details on Simple Membership < 4.7.8 - Unauthenticated Stored XSS via PayPal Subscription Subscriber Name CVE 2026-15931. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-16539
The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating a page, allowing users with the Editor role and above to perform SQL Injection attacks.
π@cveNotify
The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating a page, allowing users with the Editor role and above to perform SQL Injection attacks.
π@cveNotify
WPScan
SM Page Duplicator <= 1.0.0 - Editor+ SQL Injection via Page Duplication
See details on SM Page Duplicator <= 1.0.0 - Editor+ SQL Injection via Page Duplication CVE 2026-16539. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-16564
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes, allowing users with a Dokan vendor account to modify the status of any WooCommerce order on the marketplace, including orders belonging to other vendors and the store's own customers.
π@cveNotify
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes, allowing users with a Dokan vendor account to modify the status of any WooCommerce order on the marketplace, including orders belonging to other vendors and the store's own customers.
π@cveNotify
WPScan
Dokan < 5.0.9 - Vendor+ Arbitrary Order Status Modification via orders/bulk-actions REST Endpoint
See details on Dokan < 5.0.9 - Vendor+ Arbitrary Order Status Modification via orders/bulk-actions REST Endpoint CVE 2026-16564. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-16565
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the marketplace.
π@cveNotify
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the marketplace.
π@cveNotify
WPScan
Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API
See details on Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API CVE 2026-16565. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-61372
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki.
This issue affects Apache Jena Fuseki: through 6.1.0.
Users are recommended to upgrade to version 6.2.0, which fixes the issue.
π@cveNotify
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki.
This issue affects Apache Jena Fuseki: through 6.1.0.
Users are recommended to upgrade to version 6.2.0, which fixes the issue.
π@cveNotify
π¨ CVE-2026-18612
A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the file /cgi-bin/glc of the component plugins.so Native Plugin. This manipulation causes command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
π@cveNotify
A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the file /cgi-bin/glc of the component plugins.so Native Plugin. This manipulation causes command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
π@cveNotify
GitHub
iot_vul/GL-iNet/MT3000/4.4.5/plugins_package_name_glc_rce/CVE.md at main Β· StrTzz123/iot_vul
Contribute to StrTzz123/iot_vul development by creating an account on GitHub.
π¨ CVE-2026-18613
A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
π@cveNotify
A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
π@cveNotify
GitHub
iot_vul/GL-iNet/MT3000/4.4.5/plugins_set_config_glc_write/CVE.md at main Β· StrTzz123/iot_vul
Contribute to StrTzz123/iot_vul development by creating an account on GitHub.
π¨ CVE-2026-40717
Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
π@cveNotify
Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
π@cveNotify