π¨ CVE-2026-82841
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration state, allowing any authenticated user, such as a subscriber, to retrieve the credentials of the configured backup destinations, such as passwords and secret keys.
π@cveNotify
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration state, allowing any authenticated user, such as a subscriber, to retrieve the credentials of the configured backup destinations, such as passwords and secret keys.
π@cveNotify
WPScan
UpdraftPlus 1.23.8 - 1.26.7 - Subscriber+ Remote Storage Credential Disclosure via Migration Notice
See details on UpdraftPlus 1.23.8 - 1.26.7 - Subscriber+ Remote Storage Credential Disclosure via Migration Notice CVE 2026-82841. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-84069
The WebFacingβ’ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate a user-supplied path before using it to include a local file, allowing unauthenticated users to perform Local File Inclusion.
π@cveNotify
The WebFacingβ’ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate a user-supplied path before using it to include a local file, allowing unauthenticated users to perform Local File Inclusion.
π@cveNotify
WPScan
WebFacing Email Accounts for cPanel 5.3 - 5.3.6 - Unauthenticated LFI via assets/index.php
See details on WebFacing Email Accounts for cPanel 5.3 - 5.3.6 - Unauthenticated LFI via assets/index.php CVE 2026-84069. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-85002
The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post.
π@cveNotify
The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post.
π@cveNotify
WPScan
EmbedPress < 4.6.7 - Contributor+ Stored XSS via Instagram Carousel Block Attributes
See details on EmbedPress < 4.6.7 - Contributor+ Stored XSS via Instagram Carousel Block Attributes CVE 2026-85002. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-86609
The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature.
π@cveNotify
The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature.
π@cveNotify
WPScan
Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription
See details on Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription CVE 2026-86609. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-86839
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information.
π@cveNotify
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information.
π@cveNotify
WPScan
Bookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and Deletion via IDOR
See details on Bookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and Deletion via IDOR CVE 2026-86839. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-86841
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly assign, to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets.
π@cveNotify
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly assign, to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets.
π@cveNotify
WPScan
Bookly 23.2 - 28.2 - Bookly Administrator+ PHP Object Injection via Diagnostics Advanced Options
See details on Bookly 23.2 - 28.2 - Bookly Administrator+ PHP Object Injection via Diagnostics Advanced Options CVE 2026-86841. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-89000
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to internal-only resources and read the responses back.
π@cveNotify
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to internal-only resources and read the responses back.
π@cveNotify
WPScan
WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run
See details on WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run CVE 2026-89000. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-89001
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing users with contributor-level access and above to publish posts live and set any registered user, including an administrator, as the post author.
π@cveNotify
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing users with contributor-level access and above to publish posts live and set any registered user, including an administrator, as the post author.
π@cveNotify
WPScan
WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Post Publication and Author Spoofing via Campaign Settings
See details on WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Post Publication and Author Spoofing via Campaign Settings CVE 2026-89001. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-89003
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses back.
π@cveNotify
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses back.
π@cveNotify
WPScan
WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Preview
See details on WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Preview CVE 2026-89003. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-89006
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
π@cveNotify
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
π@cveNotify
WPScan
WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import
See details on WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import CVE 2026-89006. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-92436
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents.
π@cveNotify
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents.
π@cveNotify
WPScan
Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via IDOR
See details on Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via IDOR CVE 2026-92436. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-101041
The account recovery (password reset) functionality in the vulnerability-lookup web application contains a time-of-check-to-time-of-use (TOCTOU) race condition in the consumption of single-use recovery tokens. The original implementation verified the token nonce against the stored digest and then consumed (cleared) it in separate database operations. Two concurrent HTTP requests presenting the same valid recovery token could both pass the verification check before either transaction committed, allowing both to set their own password on the target account. The last transaction to commit overwrites the first, enabling an attacker who possesses a valid recovery token to replace the legitimate user's password with one of their choosing.
A secondary defect in the same endpoint (confirm_account) allowed a valid recovery link to be used to set an empty or trivially short password (e.g., three characters). The view handler performed only a manual equality comparison between the two password fields and never invoked the form's validation logic, bypassing the intended minimum-length and complexity constraints.
The affected component is the user account recovery endpoint (/user/confirm_account/<token>) and the associated token verification and consumption logic in the User model (website/models/user.py) and the view layer (website/web/views/user.py).
π@cveNotify
The account recovery (password reset) functionality in the vulnerability-lookup web application contains a time-of-check-to-time-of-use (TOCTOU) race condition in the consumption of single-use recovery tokens. The original implementation verified the token nonce against the stored digest and then consumed (cleared) it in separate database operations. Two concurrent HTTP requests presenting the same valid recovery token could both pass the verification check before either transaction committed, allowing both to set their own password on the target account. The last transaction to commit overwrites the first, enabling an attacker who possesses a valid recovery token to replace the legitimate user's password with one of their choosing.
A secondary defect in the same endpoint (confirm_account) allowed a valid recovery link to be used to set an empty or trivially short password (e.g., three characters). The view handler performed only a manual equality comparison between the two password fields and never invoked the form's validation logic, bypassing the intended minimum-length and complexity constraints.
The affected component is the user account recovery endpoint (/user/confirm_account/<token>) and the associated token verification and consumption logic in the User model (website/models/user.py) and the view layer (website/web/views/user.py).
π@cveNotify
GitHub
Fix recovery token consumption race Β· vulnerability-lookup/vulnerability-lookup@5462bab
Vulnerability-Lookup facilitates quick correlation of vulnerabilities from various sources, independent of vulnerability IDs, and streamlines the management of Coordinated Vulnerability Disclosure (CVD). - Fix recovery token consumption race Β· vulnerabilityβ¦
π¨ CVE-2026-84744
The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts.
π@cveNotify
The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts.
π@cveNotify
WPScan
WPForms Lite 1.5.0.1 - 2.0.2 - Unauthenticated Arbitrary Shortcode Execution via Form Field Repopulation
See details on WPForms Lite 1.5.0.1 - 2.0.2 - Unauthenticated Arbitrary Shortcode Execution via Form Field Repopulation CVE 2026-84744. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-86838
The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step.
π@cveNotify
The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step.
π@cveNotify
WPScan
Bookly < 28.3 - Unauthenticated Payment Bypass via Booking Price Manipulation
See details on Bookly < 28.3 - Unauthenticated Payment Bypass via Booking Price Manipulation CVE 2026-86838. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-88828
The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded.
π@cveNotify
The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded.
π@cveNotify
WPScan
Blacklist Manager for WooCommerce 1.3.0 - 2.3.1 - Blocked User Restriction Bypass via XML-RPC and Application Passwords
See details on Blacklist Manager for WooCommerce 1.3.0 - 2.3.1 - Blocked User Restriction Bypass via XML-RPC and Application Passwords CVE 2026-88828. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-89300
The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate limited either.
π@cveNotify
The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate limited either.
π@cveNotify
WPScan
WP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to Arbitrary Recipients
See details on WP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to Arbitrary Recipients CVE 2026-89300. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-89303
The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.
π@cveNotify
The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.
π@cveNotify
WPScan
Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter
See details on Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter CVE 2026-89303. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-89411
The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it.
π@cveNotify
The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it.
π@cveNotify
WPScan
Paymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe PaymentIntent
See details on Paymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe PaymentIntent CVE 2026-89411. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-92996
The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users to mark any order as paid.
π@cveNotify
The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users to mark any order as paid.
π@cveNotify
WPScan
Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done
See details on Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done CVE 2026-92996. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-93000
The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.
π@cveNotify
The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.
π@cveNotify
WPScan
SPS-Suite <= 1.4.0 - Unauthenticated Time-Based SQLi via Search
See details on SPS-Suite <= 1.4.0 - Unauthenticated Time-Based SQLi via Search CVE 2026-93000. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-52748
The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time.
This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
π@cveNotify
The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time.
This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
π@cveNotify
cert.pl
Vulnerabilities in Kaon AR2140 routers
CERT Polska has received a report about 2 vulnerabilities (CVE-2026-52748 and CVE-2026-52749) found in Kaon AR2140 routers.