🚨 CVE-2026-19438
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Mint Workbench I.
This issue affects Mint Workbench I: through 5876.
🎖@cveNotify
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Mint Workbench I.
This issue affects Mint Workbench I: through 5876.
🎖@cveNotify
🚨 CVE-2026-75799
The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.
🎖@cveNotify
The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.
🎖@cveNotify
WPScan
YAHMAN Add-ons < 0.9.31 - Unauthenticated Arbitrary File Upload via Blog Card Cache
See details on YAHMAN Add-ons < 0.9.31 - Unauthenticated Arbitrary File Upload via Blog Card Cache CVE 2026-75799. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-77765
The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant's configured fixed price before building the gateway charge, allowing unauthenticated users to pay an arbitrary reduced amount for a fixed-price item.
🎖@cveNotify
The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant's configured fixed price before building the gateway charge, allowing unauthenticated users to pay an arbitrary reduced amount for a fixed-price item.
🎖@cveNotify
WPScan
Better Payment < 2.3.4 - Unauthenticated Payment Amount Manipulation
See details on Better Payment < 2.3.4 - Unauthenticated Payment Amount Manipulation CVE 2026-77765. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-77766
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting user, allowing users with a subscriber-level account to read every customer's order and payment records.
Versions 8.8.1 to 8.9 are not affected. The endpoint was scoped correctly in 8.8.1 and the unscoped behaviour was reintroduced in 8.9.1.
🎖@cveNotify
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting user, allowing users with a subscriber-level account to read every customer's order and payment records.
Versions 8.8.1 to 8.9 are not affected. The endpoint was scoped correctly in 8.8.1 and the unscoped behaviour was reintroduced in 8.9.1.
🎖@cveNotify
WPScan
Directorist 8.5 - 8.9.4 - Subscriber+ Order and Financial Record Disclosure via REST Orders Endpoint
See details on Directorist 8.5 - 8.9.4 - Subscriber+ Order and Financial Record Disclosure via REST Orders Endpoint CVE 2026-77766. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-80342
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the WooCommerce order being paid unless that PayPal order has already been completed, allowing unauthenticated attackers to have another buyer's approved but uncaptured payment captured against an order of their own.
🎖@cveNotify
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the WooCommerce order being paid unless that PayPal order has already been completed, allowing unauthenticated attackers to have another buyer's approved but uncaptured payment captured against an order of their own.
🎖@cveNotify
WPScan
Payment Plugins for PayPal WooCommerce < 2.0.27 - Unauthenticated Payment Hijacking via Unvalidated PayPal Order ID
See details on Payment Plugins for PayPal WooCommerce < 2.0.27 - Unauthenticated Payment Hijacking via Unvalidated PayPal Order ID CVE 2026-80342. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-81338
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in user-submitted content before storing it and rendering it to other users, allowing users with subscriber-level accounts and above to perform stored HTML injection, such as embedding iframes, that can be leveraged for phishing and content spoofing against other users viewing the content.
🎖@cveNotify
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in user-submitted content before storing it and rendering it to other users, allowing users with subscriber-level accounts and above to perform stored HTML injection, such as embedding iframes, that can be leveraged for phishing and content spoofing against other users viewing the content.
🎖@cveNotify
WPScan
MasterStudy LMS < 3.7.50 - Subscriber+ Stored HTML Injection via Course Discussions
See details on MasterStudy LMS < 3.7.50 - Subscriber+ Stored HTML Injection via Course Discussions CVE 2026-81338. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-81339
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when returning a quiz attempt result, allowing any authenticated user with a minimal (subscriber) role to read other students' quiz grades, pass/fail status and attempt timestamps by referencing an attempt identifier belonging to another user.
🎖@cveNotify
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when returning a quiz attempt result, allowing any authenticated user with a minimal (subscriber) role to read other students' quiz grades, pass/fail status and attempt timestamps by referencing an attempt identifier belonging to another user.
🎖@cveNotify
WPScan
MasterStudy LMS < 3.7.50 - Subscriber+ Quiz Attempt Grade Disclosure via IDOR
See details on MasterStudy LMS < 3.7.50 - Subscriber+ Quiz Attempt Grade Disclosure via IDOR CVE 2026-81339. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-82843
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and above to obtain a validly signed identity assertion for another user, including an administrator, and authenticate as them at any application that uses the site for single sign-on.
🎖@cveNotify
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and above to obtain a validly signed identity assertion for another user, including an administrator, and authenticate as them at any application that uses the site for single sign-on.
🎖@cveNotify
WPScan
WP OAuth Server < 6.4.0 - Subscriber+ Cross-User Account Takeover via OIDC ID Token Substitution
See details on WP OAuth Server < 6.4.0 - Subscriber+ Cross-User Account Takeover via OIDC ID Token Substitution CVE 2026-82843. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-83555
The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token before changing a subscriber's subscription status, allowing unauthenticated users to force-unsubscribe or force-confirm an arbitrary subscriber whose email address they know.
🎖@cveNotify
The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token before changing a subscriber's subscription status, allowing unauthenticated users to force-unsubscribe or force-confirm an arbitrary subscriber whose email address they know.
🎖@cveNotify
WPScan
Email Subscribers by Icegram Express < 5.9.35 - Unauthenticated Subscription Status Change via Missing Token Verification
See details on Email Subscribers by Icegram Express < 5.9.35 - Unauthenticated Subscription Status Change via Missing Token Verification CVE 2026-83555. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84026
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restrict access to a REST endpoint that returns user records, allowing unauthenticated attackers to read registered users' private contact details.
🎖@cveNotify
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restrict access to a REST endpoint that returns user records, allowing unauthenticated attackers to read registered users' private contact details.
🎖@cveNotify
WPScan
Directorist 8.1 - 8.9.4 - Unauthenticated Sensitive Data Disclosure via REST Users Endpoint
See details on Directorist 8.1 - 8.9.4 - Unauthenticated Sensitive Data Disclosure via REST Users Endpoint CVE 2026-84026. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84027
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, allowing users with the subscriber role and above to create paid order and payment records with arbitrary amounts and attribute them to other users.
🎖@cveNotify
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, allowing users with the subscriber role and above to create paid order and payment records with arbitrary amounts and attribute them to other users.
🎖@cveNotify
WPScan
Directorist 8.9.1 - 8.9.4 - Subscriber+ Paid Order and Payment Record Forgery via REST Orders Endpoint
See details on Directorist 8.9.1 - 8.9.4 - Subscriber+ Paid Order and Payment Record Forgery via REST Orders Endpoint CVE 2026-84027. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84046
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validate a user-supplied URL before fetching it server-side, allowing users with the subscriber role and above to make the server issue requests to internal addresses.
🎖@cveNotify
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validate a user-supplied URL before fetching it server-side, allowing users with the subscriber role and above to make the server issue requests to internal addresses.
🎖@cveNotify
WPScan
Directorist < 8.9.5 - Subscriber+ SSRF via Avatar URL
See details on Directorist < 8.9.5 - Subscriber+ SSRF via Avatar URL CVE 2026-84046. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84098
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated attackers with Subscriber-level access and above to delete arbitrary listings, including ones belonging to other users.
This is an incomplete fix of CVE-2023-1889 / CVE-2023-35052: a separate, unaddressed listing-deletion path allows the same impact, from at least version 3.1.0 through the current release.
🎖@cveNotify
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated attackers with Subscriber-level access and above to delete arbitrary listings, including ones belonging to other users.
This is an incomplete fix of CVE-2023-1889 / CVE-2023-35052: a separate, unaddressed listing-deletion path allows the same impact, from at least version 3.1.0 through the current release.
🎖@cveNotify
WPScan
Directorist 3.1.0 - 8.9.4 - Subscriber+ Arbitrary Listing Deletion via remove_listing
See details on Directorist 3.1.0 - 8.9.4 - Subscriber+ Arbitrary Listing Deletion via remove_listing CVE 2026-84098. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84150
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not verify that the target user of a REST route matches the authenticated caller before reading and modifying that user's saved favorites, allowing any authenticated user with subscriber-level access to view and alter another user's favorites.
🎖@cveNotify
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not verify that the target user of a REST route matches the authenticated caller before reading and modifying that user's saved favorites, allowing any authenticated user with subscriber-level access to view and alter another user's favorites.
🎖@cveNotify
WPScan
Directorist < 8.9.5 - Subscriber+ Cross-User Favorites Read and Write via REST Favorites Endpoint
See details on Directorist < 8.9.5 - Subscriber+ Cross-User Favorites Read and Write via REST Favorites Endpoint CVE 2026-84150. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84741
The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the contents of records that have never been published.
🎖@cveNotify
The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the contents of records that have never been published.
🎖@cveNotify
WPScan
The Events Calendar 4.5 - 6.17.4.1 - Unauthenticated Non-Public Venue and Organizer Disclosure via REST API
See details on The Events Calendar 4.5 - 6.17.4.1 - Unauthenticated Non-Public Venue and Organizer Disclosure via REST API CVE 2026-84741. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84742
The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, allowing users with a role that cannot normally publish, such as contributor, to publish content directly and bypass editorial review.
🎖@cveNotify
The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, allowing users with a role that cannot normally publish, such as contributor, to publish content directly and bypass editorial review.
🎖@cveNotify
WPScan
The Events Calendar 6.15.0 - 6.17.4.1 - Contributor+ Content Publication via TEC V1 REST API
See details on The Events Calendar 6.15.0 - 6.17.4.1 - Contributor+ Content Publication via TEC V1 REST API CVE 2026-84742. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84743
The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify, unpublish, trash and take ownership of records belonging to other users, including administrators.
🎖@cveNotify
The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify, unpublish, trash and take ownership of records belonging to other users, including administrators.
🎖@cveNotify
WPScan
The Events Calendar 6.15.16.1 - 6.17.4.1 - Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug…
See details on The Events Calendar 6.15.16.1 - 6.17.4.1 - Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug REST Routes CVE 2026-84743. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-85006
The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an HTML attribute, allowing users with Contributor-level access and above to inject event-handler attributes that execute JavaScript in the browser of anyone who views the page, including higher-privileged users reviewing the content, even though such users do not hold the unfiltered_html capability.
🎖@cveNotify
The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an HTML attribute, allowing users with Contributor-level access and above to inject event-handler attributes that execute JavaScript in the browser of anyone who views the page, including higher-privileged users reviewing the content, even though such users do not hold the unfiltered_html capability.
🎖@cveNotify
WPScan
Happy Addons for Elementor < 3.50.0 - Contributor+ Stored XSS via Creative Button Widget
See details on Happy Addons for Elementor < 3.50.0 - Contributor+ Stored XSS via Creative Button Widget CVE 2026-85006. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-86602
The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the full content of unpublished recipes.
🎖@cveNotify
The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the full content of unpublished recipes.
🎖@cveNotify
WPScan
WP Recipe Maker 10.3.0 - 10.8.1 - Subscriber+ Draft and Private Recipe Content Disclosure via wprm_shortcode_preview
See details on WP Recipe Maker 10.3.0 - 10.8.1 - Subscriber+ Draft and Private Recipe Content Disclosure via wprm_shortcode_preview CVE 2026-86602. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-86603
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists.
🎖@cveNotify
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists.
🎖@cveNotify
WPScan
WP Recipe Maker < 10.8.2 - Subscriber+ Non-Public List Title Disclosure via wprm_search_lists
See details on WP Recipe Maker < 10.8.2 - Subscriber+ Non-Public List Title Disclosure via wprm_search_lists CVE 2026-86603. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-86608
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what that route stores, allowing unauthenticated users to write unlimited data into any user's metadata and to permanently prevent that account, including an administrator's, from loading.
🎖@cveNotify
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what that route stores, allowing unauthenticated users to write unlimited data into any user's metadata and to permanently prevent that account, including an administrator's, from loading.
🎖@cveNotify
WPScan
WP Recipe Maker 9.8.0 - 10.8.1 - Unauthenticated DoS via Unbounded User Meta Insertion
See details on WP Recipe Maker 9.8.0 - 10.8.1 - Unauthenticated DoS via Unbounded User Meta Insertion CVE 2026-86608. View the latest Plugin Vulnerabilities on WPScan.