๐จ CVE-2026-11793
A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server by storing a crafted credential with an oversized algorithm ID. FORTIFY_SOURCE mitigates this to denial of service only.
๐@cveNotify
A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server by storing a crafted credential with an oversized algorithm ID. FORTIFY_SOURCE mitigates this to denial of service only.
๐@cveNotify
Redhat
CVE-2026-11793 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-15013
The SAML Single Sign On โ SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAML_Utilities::mo_saml_cast_key()` reads the `SignatureMethod` Algorithm attribute directly from the attacker-controlled `SAMLResponse` parameter rather than enforcing the locally configured algorithm, causing the plugin to recast the IdP's RSA public key as an HMAC-SHA1 shared secret and validate the forged signature against it. This makes it possible for unauthenticated attackers to forge a SAML assertion targeting any WordPress account โ including administrators โ obtain valid WordPress authentication cookies, and achieve full administrator-level account takeover.
๐@cveNotify
The SAML Single Sign On โ SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAML_Utilities::mo_saml_cast_key()` reads the `SignatureMethod` Algorithm attribute directly from the attacker-controlled `SAMLResponse` parameter rather than enforcing the locally configured algorithm, causing the plugin to recast the IdP's RSA public key as an HMAC-SHA1 shared secret and validate the forged signature against it. This makes it possible for unauthenticated attackers to forge a SAML assertion targeting any WordPress account โ including administrators โ obtain valid WordPress authentication cookies, and achieve full administrator-level account takeover.
๐@cveNotify
๐จ CVE-2026-64828
Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary HTML and JavaScript through the order notes field without sanitization. Attackers can craft malicious payloads in customer order placement that execute in the admin's browser session when viewing order details, enabling session token theft or unauthorized administrative actions.
๐@cveNotify
Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary HTML and JavaScript through the order notes field without sanitization. Attackers can craft malicious payloads in customer order placement that execute in the admin's browser session when viewing order details, enabling session token theft or unauthorized administrative actions.
๐@cveNotify
CodeCanyon
TableTrack - Complete Restaurant Management System SaaS
TableTrack is a complete Restaurant Management System SaaS built on Laravel, designed for multi-tenant restaurant businesses of all sizes. From a single bistro to a multi-branch restaurant chain, T...
๐จ CVE-2026-64829
Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password reset flow's failure to clear the sessioncode field in qa-include/app/users-edit.php. While the normal password-change flow in qa-include/pages/account.php explicitly clears the sessioncode to invalidate persistent qa_session cookies, the forgot-password handler qa_finish_reset_user() omits this step, allowing any valid persistent cookie issued before the reset to continue authenticating the account after the password reset completes.
๐@cveNotify
Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password reset flow's failure to clear the sessioncode field in qa-include/app/users-edit.php. While the normal password-change flow in qa-include/pages/account.php explicitly clears the sessioncode to invalidate persistent qa_session cookies, the forgot-password handler qa_finish_reset_user() omits this step, allowing any valid persistent cookie issued before the reset to continue authenticating the account after the password reset completes.
๐@cveNotify
GitHub
Invalidate remember-me sessions after password reset by BroNiz4m ยท Pull Request #1017 ยท q2a/question2answer
This PR updates the forgot-password reset flow to invalidate old persistent "Remember me" sessions after a successful password reset.
The normal account password-change flow alrea...
The normal account password-change flow alrea...
๐จ CVE-2026-61511
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.
๐@cveNotify
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.
๐@cveNotify
๐จ CVE-2026-64827
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches 'login_admin.php'. Attackers can append '/login_admin.php' to the path of any target PHP script to cause the authentication check to pass and gain unauthenticated access to all PHP scripts under the manager HTML directory.
๐@cveNotify
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches 'login_admin.php'. Attackers can append '/login_admin.php' to the path of any target PHP script to cause the authentication check to pass and gain unauthenticated access to all PHP scripts under the manager HTML directory.
๐@cveNotify
Karmainsecurity
Telenia Software TVox <= 26.5.3 (set_env.php) Authentication Bypass Vulnerability | Karma(In)Security
This is the personal website of Egidio Romano, a very curious guy from Sicily, Italy. He's a computer security enthusiast, particularly addicted to webapp security.
๐จ CVE-2026-14205
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.
๐@cveNotify
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.
๐@cveNotify
WPScan
WP Events Manager < 2.2.5 - Subscriber+ Payment Bypass via 'qty' Parameter
See details on WP Events Manager < 2.2.5 - Subscriber+ Payment Bypass via 'qty' Parameter CVE 2026-14205. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14331
The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a public subscription form, leading to Reflected Cross-Site Scripting that executes in the browser of an unauthenticated visitor who interacts with the form through a crafted link.
๐@cveNotify
The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a public subscription form, leading to Reflected Cross-Site Scripting that executes in the browser of an unauthenticated visitor who interacts with the form through a crafted link.
๐@cveNotify
WPScan
Subscribe2 < 10.46 - Reflected XSS via email Parameter
See details on Subscribe2 < 10.46 - Reflected XSS via email Parameter CVE 2026-14331. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14943
The Password Protected โ Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors to bypass the sitewide password gate and read otherwise-protected content and account identifiers via the REST API. This re-introduces a previously-fixed issue (CVE-2024-0437), which was patched in 2.6.7 and regressed in 2.6.8.
๐@cveNotify
The Password Protected โ Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors to bypass the sitewide password gate and read otherwise-protected content and account identifiers via the REST API. This re-introduces a previously-fixed issue (CVE-2024-0437), which was patched in 2.6.7 and regressed in 2.6.8.
๐@cveNotify
WPScan
Password Protected < 2.8.4 - Unauthenticated Sensitive Information Exposure via REST API
See details on Password Protected < 2.8.4 - Unauthenticated Sensitive Information Exposure via REST API CVE 2026-14943. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-15032
The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an HTML attribute, allowing unauthenticated users to store a Cross-Site Scripting payload that executes in the browser of any user, including administrators, who views the affected content.
๐@cveNotify
The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an HTML attribute, allowing unauthenticated users to store a Cross-Site Scripting payload that executes in the browser of any user, including administrators, who views the affected content.
๐@cveNotify
WPScan
wpDiscuz < 7.6.60 - Unauthenticated Stored XSS via Image URL Conversion
See details on wpDiscuz < 7.6.60 - Unauthenticated Stored XSS via Image URL Conversion CVE 2026-15032. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-15214
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that subscription's ID.
๐@cveNotify
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that subscription's ID.
๐@cveNotify
WPScan
Subscriptions for WooCommerce < 2.0.1 - Subscriber+ Subscription Detail Disclosure via IDOR
See details on Subscriptions for WooCommerce < 2.0.1 - Subscriber+ Subscription Detail Disclosure via IDOR CVE 2026-15214. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-15215
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin before 2.0.1, resulting in remote code execution.
๐@cveNotify
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin before 2.0.1, resulting in remote code execution.
๐@cveNotify
WPScan
Subscriptions for WooCommerce < 2.0.1 - Shop Manager+ Arbitrary Plugin Installation
See details on Subscriptions for WooCommerce < 2.0.1 - Shop Manager+ Arbitrary Plugin Installation CVE 2026-15215. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-15245
The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript context before echoing it into an inline script, allowing users with the contributor role and above to inject arbitrary JavaScript that executes in the browser of anyone viewing the affected content.
๐@cveNotify
The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript context before echoing it into an inline script, allowing users with the contributor role and above to inject arbitrary JavaScript that executes in the browser of anyone viewing the affected content.
๐@cveNotify
WPScan
BNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider Shortcode
See details on BNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider Shortcode CVE 2026-15245. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-15359
The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers to overwrite the administrator's stored cloud service connection with an account under their control, disconnecting the legitimate administrator and redirecting the site's cloud template library to attacker-controlled content.
๐@cveNotify
The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers to overwrite the administrator's stored cloud service connection with an account under their control, disconnecting the legitimate administrator and redirecting the site's cloud template library to attacker-controlled content.
๐@cveNotify
WPScan
Templately < 3.7.1 - Unauthenticated Administrator Templately Cloud Connection Overwrite
See details on Templately < 3.7.1 - Unauthenticated Administrator Templately Cloud Connection Overwrite CVE 2026-15359. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-15361
The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks.
๐@cveNotify
The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks.
๐@cveNotify
WPScan
Content Views < 4.5 - Subscriber+ SQL Injection via preview_request
See details on Content Views < 4.5 - Subscriber+ SQL Injection via preview_request CVE 2026-15361. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-15386
The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds for linked galleries, allowing users with the Author role or above to store a JavaScript payload that executes in the browser of any visitor (including administrators) who views a post containing such a gallery.
๐@cveNotify
The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds for linked galleries, allowing users with the Author role or above to store a JavaScript payload that executes in the browser of any visitor (including administrators) who views a post containing such a gallery.
๐@cveNotify
WPScan
Meow Gallery < 5.5.2 - Author+ Stored XSS via Attachment Alt-Text
See details on Meow Gallery < 5.5.2 - Author+ Stored XSS via Attachment Alt-Text CVE 2026-15386. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-16030
The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts.
๐@cveNotify
The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts.
๐@cveNotify
WPScan
MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication
See details on MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication CVE 2026-16030. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-16038
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free.
๐@cveNotify
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free.
๐@cveNotify
WPScan
MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways
See details on MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways CVE 2026-16038. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-16039
The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each customer's personal information.
๐@cveNotify
The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each customer's personal information.
๐@cveNotify
WPScan
MStore API < 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDOR
See details on MStore API < 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDOR CVE 2026-16039. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-16041
The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners.
๐@cveNotify
The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners.
๐@cveNotify
WPScan
MStore API < 4.21.0 - Unauthenticated Product Review Creation
See details on MStore API < 4.21.0 - Unauthenticated Product Review Creation CVE 2026-16041. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-16262
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker.
๐@cveNotify
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker.
๐@cveNotify
WPScan
Estatik < 4.3.3 - Login CSRF
See details on Estatik < 4.3.3 - Login CSRF CVE 2026-16262. View the latest Plugin Vulnerabilities on WPScan.