π¨ CVE-2026-17010
The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before outputting them, allowing users with contributor-level access and above to inject stored Cross-Site Scripting payloads that execute in the browser of a higher-privileged user who reviews the content.
π@cveNotify
The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before outputting them, allowing users with contributor-level access and above to inject stored Cross-Site Scripting payloads that execute in the browser of a higher-privileged user who reviews the content.
π@cveNotify
WPScan
Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta
See details on Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta CVE 2026-17010. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-17012
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's.
π@cveNotify
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's.
π@cveNotify
WPScan
Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver_email
See details on Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver_email CVE 2026-17012. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-17016
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal Data Transfer feature is enabled.
π@cveNotify
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal Data Transfer feature is enabled.
π@cveNotify
WPScan
Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via PDT Underpayment
See details on Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via PDT Underpayment CVE 2026-17016. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-17018
The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of its REST API endpoints, allowing users with the Contributor role and above to read arbitrary post metadata (including that of other users' draft, pending, private, and password-protected posts) and arbitrary user metadata of any user, including administrators.
π@cveNotify
The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of its REST API endpoints, allowing users with the Contributor role and above to read arbitrary post metadata (including that of other users' draft, pending, private, and password-protected posts) and arbitrary user metadata of any user, including administrators.
π@cveNotify
WPScan
CubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclosure via IDOR
See details on CubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclosure via IDOR CVE 2026-17018. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-17019
The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict who can upload them, allowing unauthenticated attackers to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting).
π@cveNotify
The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict who can upload them, allowing unauthenticated attackers to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting).
π@cveNotify
WPScan
JetEngine < 3.8.13.1 - Unauthenticated Stored XSS via Form File Upload (SVG)
See details on JetEngine < 3.8.13.1 - Unauthenticated Stored XSS via Form File Upload (SVG) CVE 2026-17019. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-17020
The Salon Booking System WordPress plugin through 10.30.33 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers.
π@cveNotify
The Salon Booking System WordPress plugin through 10.30.33 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers.
π@cveNotify
WPScan
Salon Booking System β Free Version <= 10.31.3 - Subscriber+ Arbitrary Booking PII Disclosure
See details on Salon Booking System β Free Version <= 10.31.3 - Subscriber+ Arbitrary Booking PII Disclosure CVE 2026-17020. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-17021
The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.
π@cveNotify
The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.
π@cveNotify
WPScan
Salon Booking System β Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total Tampering
See details on Salon Booking System β Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total Tampering CVE 2026-17021. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-17022
The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier.
π@cveNotify
The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier.
π@cveNotify
WPScan
Salon Booking System β Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking Wizard
See details on Salon Booking System β Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking Wizard CVE 2026-17022. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-17023
The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.
π@cveNotify
The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.
π@cveNotify
WPScan
Salon Booking System β Free Version <= 10.31.3 - Unauthenticated Google Calendar Connection Hijack via OAuth Callback
See details on Salon Booking System β Free Version <= 10.31.3 - Unauthenticated Google Calendar Connection Hijack via OAuth Callback CVE 2026-17023. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-17540
The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service.
π@cveNotify
The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service.
π@cveNotify
WPScan
Bit File Manager < 6.9.1 - Subscriber+ Arbitrary File Read and Deletion via Connector Command Request-Source Mismatch
See details on Bit File Manager < 6.9.1 - Subscriber+ Arbitrary File Read and Deletion via Connector Command Request-Source Mismatch CVE 2026-17540. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-17541
The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.
π@cveNotify
The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.
π@cveNotify
WPScan
Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Disclosure
See details on Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Disclosure CVE 2026-17541. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-17542
The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data.
π@cveNotify
The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data.
π@cveNotify
WPScan
Bit File Manager < 6.9.1 - Subscriber+ Sensitive Data Disclosure via bitapps_fm_connector
See details on Bit File Manager < 6.9.1 - Subscriber+ Sensitive Data Disclosure via bitapps_fm_connector CVE 2026-17542. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-18030
The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one of its form actions, allowing unauthenticated attackers to set an arbitrary password for any user, including administrators, and take over their account.
Exploitation requires the site to have a form using the BricksForge WordPress plugin before 3.1.8.8's password reset action in its update mode. The server-side current-password verification option for that action is disabled by default, so the vulnerable state is the default one once the action is used.
π@cveNotify
The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one of its form actions, allowing unauthenticated attackers to set an arbitrary password for any user, including administrators, and take over their account.
Exploitation requires the site to have a form using the BricksForge WordPress plugin before 3.1.8.8's password reset action in its update mode. The server-side current-password verification option for that action is disabled by default, so the vulnerable state is the default one once the action is used.
π@cveNotify
WPScan
Bricksforge < 3.1.8.8 - Unauthenticated Arbitrary Password Reset via Pro Forms
See details on Bricksforge < 3.1.8.8 - Unauthenticated Arbitrary Password Reset via Pro Forms CVE 2026-18030. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-18200
The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including administrators.
π@cveNotify
The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including administrators.
π@cveNotify
WPScan
FoodBoxBooker < 1.0.8 - Subscriber+ Arbitrary User Profile Update
See details on FoodBoxBooker < 1.0.8 - Subscriber+ Arbitrary User Profile Update CVE 2026-18200. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-18468
The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently completed a reset verification, including an administrator.
π@cveNotify
The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently completed a reset verification, including an administrator.
π@cveNotify
WPScan
Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Verification State Keyed on a Client-Suppliedβ¦
See details on Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Verification State Keyed on a Client-Supplied Address Header CVE 2026-18468. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-18469
The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-derived value, keying both the verification code and the per-source attempt counter on client-controlled data, allowing unauthenticated attackers to reset the limit at will and brute-force the code to take over any account, including administrators, when the verification-code reset mode is enabled.
π@cveNotify
The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-derived value, keying both the verification code and the per-source attempt counter on client-controlled data, allowing unauthenticated attackers to reset the limit at will and brute-force the code to take over any account, including administrators, when the verification-code reset mode is enabled.
π@cveNotify
WPScan
Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Code Brute Force
See details on Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Code Brute Force CVE 2026-18469. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-18470
The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the account's owner, and does not adequately redact the address returned in its response, allowing unauthenticated users to obtain registered users' email addresses, including administrators'.
π@cveNotify
The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the account's owner, and does not adequately redact the address returned in its response, allowing unauthenticated users to obtain registered users' email addresses, including administrators'.
π@cveNotify
WPScan
Login & Register Forms < 4.0.2 - Unauthenticated Registered User Email Address Disclosure via Lost Password Response
See details on Login & Register Forms < 4.0.2 - Unauthenticated Registered User Email Address Disclosure via Lost Password Response CVE 2026-18470. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-18666
The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing users with a role as low as Subscriber to perform SQL injection and extract arbitrary data from the database, including user password hashes.
π@cveNotify
The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing users with a role as low as Subscriber to perform SQL injection and extract arbitrary data from the database, including user password hashes.
π@cveNotify
WPScan
Library Management System < 3.6.7 - Subscriber+ SQL Injection via Filter Value
See details on Library Management System < 3.6.7 - Subscriber+ SQL Injection via Filter Value CVE 2026-18666. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-18786
The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView WordPress plugin before 2.3.2-specific string, making it possible for unauthenticated attackers to bypass the REST nonce check and perform any REST action available to a logged-in administrator, such as creating a new administrator account, via a crafted link an administrator is tricked into opening.
π@cveNotify
The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView WordPress plugin before 2.3.2-specific string, making it possible for unauthenticated attackers to bypass the REST nonce check and perform any REST action available to a logged-in administrator, such as creating a new administrator account, via a crafted link an administrator is tricked into opening.
π@cveNotify
WPScan
CheckView < 2.3.2 - Administrator Account Creation via REST API Authentication Bypass
See details on CheckView < 2.3.2 - Administrator Account Creation via REST API Authentication Bypass CVE 2026-18786. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-18946
The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticated attackers to enumerate and download files submitted by other users.
π@cveNotify
The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticated attackers to enumerate and download files submitted by other users.
π@cveNotify
WPScan
Contact Form to Any API < 3.0.7 - Unauthenticated Sensitive File Disclosure via Predictable Filename
See details on Contact Form to Any API < 3.0.7 - Unauthenticated Sensitive File Disclosure via Predictable Filename CVE 2026-18946. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-18960
The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API.
π@cveNotify
The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API.
π@cveNotify
WPScan
Block User Account < 2.0.1 - Subscriber+ Account Block Bypass via Application Passwords
See details on Block User Account < 2.0.1 - Subscriber+ Account Block Bypass via Application Passwords CVE 2026-18960. View the latest Plugin Vulnerabilities on WPScan.