π¨ CVE-2026-79621
The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store before including it in the product enquiry notification email sent to the site administrator, allowing unauthenticated attackers to inject arbitrary content into that email, which is delivered when an unrelated visitor later submits a product enquiry.
π@cveNotify
The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store before including it in the product enquiry notification email sent to the site administrator, allowing unauthenticated attackers to inject arbitrary content into that email, which is delivered when an unrelated visitor later submits a product enquiry.
π@cveNotify
WPScan
CatalogX < 6.1.3 - Unauthenticated Email Content Injection via Shared Transient
See details on CatalogX < 6.1.3 - Unauthenticated Email Content Injection via Shared Transient CVE 2026-79621. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-80467
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities and then escalate it to administrator.
π@cveNotify
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities and then escalate it to administrator.
π@cveNotify
WPScan
Advanced Custom Fields: Extended 0.9.2.2 - 0.9.2.6 - Unauthenticated Privilege Escalation via Front-End User Insert Action
See details on Advanced Custom Fields: Extended 0.9.2.2 - 0.9.2.6 - Unauthenticated Privilege Escalation via Front-End User Insert Action CVE 2026-80467. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81194
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers to read other instructors' course sales records by supplying another user's identifier.
π@cveNotify
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers to read other instructors' course sales records by supplying another user's identifier.
π@cveNotify
WPScan
MasterStudy LMS < 3.7.46 - Subscriber+ Cross-Instructor Order Data Disclosure via author_id Parameter
See details on MasterStudy LMS < 3.7.46 - Subscriber+ Cross-Instructor Order Data Disclosure via author_id Parameter CVE 2026-81194. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81195
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning per-student course enrollment and progress data, allowing unauthenticated attackers to disclose the enrolled courses and learning progress of any registered user.
π@cveNotify
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning per-student course enrollment and progress data, allowing unauthenticated attackers to disclose the enrolled courses and learning progress of any registered user.
π@cveNotify
WPScan
MasterStudy LMS < 3.7.46 - Unauthenticated Student Enrollment Disclosure via student-courses REST Route
See details on MasterStudy LMS < 3.7.46 - Unauthenticated Student Enrollment Disclosure via student-courses REST Route CVE 2026-81195. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81196
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access to read other instructors' quiz questions, including the correct answers and explanations.
π@cveNotify
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access to read other instructors' quiz questions, including the correct answers and explanations.
π@cveNotify
WPScan
MasterStudy LMS < 3.7.46 - Instructor+ Quiz Answer Disclosure via IDOR
See details on MasterStudy LMS < 3.7.46 - Instructor+ Quiz Answer Disclosure via IDOR CVE 2026-81196. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81197
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route that lists an author's courses, nor does it filter that listing by publication status, allowing unauthenticated users to read the titles and IDs of unpublished (draft, pending and private) courses.
π@cveNotify
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route that lists an author's courses, nor does it filter that listing by publication status, allowing unauthenticated users to read the titles and IDs of unpublished (draft, pending and private) courses.
π@cveNotify
WPScan
MasterStudy LMS < 3.7.46 - Unauthenticated Unpublished Course Title Disclosure via course-list REST Route
See details on MasterStudy LMS < 3.7.46 - Unauthenticated Unpublished Course Title Disclosure via course-list REST Route CVE 2026-81197. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81198
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated users with the instructor role to delete or modify curriculum sections and materials belonging to courses owned by other instructors.
π@cveNotify
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated users with the instructor role to delete or modify curriculum sections and materials belonging to courses owned by other instructors.
π@cveNotify
WPScan
MasterStudy LMS < 3.7.46 - Instructor+ Cross-Course Curriculum Deletion and Tampering via IDOR
See details on MasterStudy LMS < 3.7.46 - Instructor+ Cross-Course Curriculum Deletion and Tampering via IDOR CVE 2026-81198. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81199
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to disclose the course counts, points, certificates, quiz and assignment totals of any registered user.
π@cveNotify
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to disclose the course counts, points, certificates, quiz and assignment totals of any registered user.
π@cveNotify
WPScan
MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure via student/stats REST Route
See details on MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure via student/stats REST Route CVE 2026-81199. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81426
The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order shipment status actions, which could allow attackers to make a logged-in vendor change the shipment status of their own orders via a crafted request.
π@cveNotify
The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order shipment status actions, which could allow attackers to make a logged-in vendor change the shipment status of their own orders via a crafted request.
π@cveNotify
WPScan
WC Vendors < 2.7.2.1 - Order Shipment Status Change via CSRF
See details on WC Vendors < 2.7.2.1 - Order Shipment Status Change via CSRF CVE 2026-81426. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81427
The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment status change owns the referenced order, allowing any authenticated vendor to mark another vendor's order as shipped, add an order note falsely attributed to the victim vendor, and trigger the customer shipment notification email.
π@cveNotify
The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment status change owns the referenced order, allowing any authenticated vendor to mark another vendor's order as shipped, add an order note falsely attributed to the victim vendor, and trigger the customer shipment notification email.
π@cveNotify
WPScan
WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Order Shipment Status Change
See details on WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Order Shipment Status Change CVE 2026-81427. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81428
The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownership or the object type of user-supplied IDs when saving product variations, allowing authenticated users with the vendor role to modify product variations belonging to other vendors, and to change the status and title of arbitrary posts, via IDOR.
π@cveNotify
The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownership or the object type of user-supplied IDs when saving product variations, allowing authenticated users with the vendor role to modify product variations belonging to other vendors, and to change the status and title of arbitrary posts, via IDOR.
π@cveNotify
WPScan
WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Product and Arbitrary Post Modification via IDOR
See details on WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Product and Arbitrary Post Modification via IDOR CVE 2026-81428. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81432
The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on some of its AJAX actions, allowing attackers to make a logged-in user with the edit_posts capability (Contributor and above) delete or modify custom widget skins via a crafted request, provided they can trick the user into performing an action such as clicking a link.
π@cveNotify
The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on some of its AJAX actions, allowing attackers to make a logged-in user with the edit_posts capability (Contributor and above) delete or modify custom widget skins via a crafted request, provided they can trick the user into performing an action such as clicking a link.
π@cveNotify
WPScan
JetStyleManager < 1.3.9 - Skin Deletion and Modification via CSRF
See details on JetStyleManager < 1.3.9 - Skin Deletion and Modification via CSRF CVE 2026-81432. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81583
The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and unauthenticated users on some networks, to create new sites and be granted administrator over them.
π@cveNotify
The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and unauthenticated users on some networks, to create new sites and be granted administrator over them.
π@cveNotify
WPScan
Theme My Login 7.0 - 7.1.15 - Subscriber+ Unauthorised Multisite Site Creation and Privilege Escalation
See details on Theme My Login 7.0 - 7.1.15 - Subscriber+ Unauthorised Multisite Site Creation and Privilege Escalation CVE 2026-81583. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81737
The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in an admin area page, and the escaping it does apply is undone by a subsequent decoding step, leading to Stored XSS which will execute in the context of a logged in administrator.
π@cveNotify
The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in an admin area page, and the escaping it does apply is undone by a subsequent decoding step, leading to Stored XSS which will execute in the context of a logged in administrator.
π@cveNotify
WPScan
FAQ Builder AYS 1.6.3 - 1.8.4 - Unauthenticated Stored XSS via ays_get_user_information
See details on FAQ Builder AYS 1.6.3 - 1.8.4 - Unauthenticated Stored XSS via ays_get_user_information CVE 2026-81737. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-81807
The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and run scripts in the browser of anyone viewing the chat, including administrators.
π@cveNotify
The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and run scripts in the browser of anyone viewing the chat, including administrators.
π@cveNotify
WPScan
Simple Ajax Chat < 20260827 - Unauthenticated Stored XSS via Chat Message Linkification
See details on Simple Ajax Chat < 20260827 - Unauthenticated Stored XSS via Chat Message Linkification CVE 2026-81807. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-82183
The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts.
π@cveNotify
The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts.
π@cveNotify
WPScan
OAuth Single Sign On 6.25.0 - 7.0.0 - Unauthenticated Account Takeover via Unverified Steam OpenID Assertion
See details on OAuth Single Sign On 6.25.0 - 7.0.0 - Unauthenticated Account Takeover via Unverified Steam OpenID Assertion CVE 2026-82183. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-3850
The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_contact_form` shortcode in all versions up to, and including, 4.27.6. This is due to the `redirect_url` attribute being sanitized with `esc_attr()` instead of `esc_url()` before being rendered into the `data-redirect_url` HTML data attribute. Additionally, `redirect_url` is absent from the hardcoded `$url_options` array in `class-et-builder-element.php`, so it does not receive `esc_url_raw()` sanitization during shortcode parsing. After a successful form submission, client-side JavaScript reads this data attribute and passes it directly to `window.location.href`, executing arbitrary JavaScript from a `javascript:` URI. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that execute whenever a user submits the contact form.
π@cveNotify
The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_contact_form` shortcode in all versions up to, and including, 4.27.6. This is due to the `redirect_url` attribute being sanitized with `esc_attr()` instead of `esc_url()` before being rendered into the `data-redirect_url` HTML data attribute. Additionally, `redirect_url` is absent from the hardcoded `$url_options` array in `class-et-builder-element.php`, so it does not receive `esc_url_raw()` sanitization during shortcode parsing. After a successful form submission, client-side JavaScript reads this data attribute and passes it directly to `window.location.href`, executing arbitrary JavaScript from a `javascript:` URI. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that execute whenever a user submits the contact form.
π@cveNotify
π¨ CVE-2026-82883
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS.
This issue affects Login With Ajax: from n/a through 4.5.1.
π@cveNotify
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS.
This issue affects Login With Ajax: from n/a through 4.5.1.
π@cveNotify
π¨ CVE-2026-4378
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Software Technologies Ltd. E-Commerce Pack allows Stored XSS.
This issue affects E-Commerce Pack: from 4.5.001 before 4.6.001.
π@cveNotify
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Software Technologies Ltd. E-Commerce Pack allows Stored XSS.
This issue affects E-Commerce Pack: from 4.5.001 before 4.6.001.
π@cveNotify
siberguvenlik.gov.tr
T.C. Siber GΓΌvenlik BaΕkanlΔ±ΔΔ±
TΓΌrkiye Cumhuriyeti CumhurbaΕkanlΔ±ΔΔ± Siber GΓΌvenlik BaΕkanlΔ±ΔΔ± resmi web sitesi.
π¨ CVE-2025-7963
The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer() function in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
π@cveNotify
The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer() function in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
π@cveNotify
π¨ CVE-2026-14828
Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.
π@cveNotify
Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.
π@cveNotify
Manageengine
SQL Injection Vulnerability in Password Manager Pro, PAM360 and Access Manager Plus