π¨ CVE-2026-102913
A security flaw has been discovered in SourceCodester Car Driving School Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_enrollment. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
π@cveNotify
A security flaw has been discovered in SourceCodester Car Driving School Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_enrollment. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
π@cveNotify
GitHub
SourceCodester Car Driving School Management System in PHP OOP Master.php save_enrollment Dynamic POST Field Name SQL Injectionβ¦
SourceCodester Car Driving School Management System in PHP OOP Master.php save_enrollment Dynamic POST Field Name SQL Injection NAME OF AFFECTED PRODUCT(S) Car Driving School Management System Vend...
π¨ CVE-2026-103111
PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.
π@cveNotify
PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.
π@cveNotify
GitHub
PCRE2: out-of-bounds write in JIT matching with large stack allocations
## PCRE2 maintainer report
### Summary
A regular expression can cause JIT-compiled matching to write outside the maximum memory area of a growable JIT stack. A sufficiently large single stack...
### Summary
A regular expression can cause JIT-compiled matching to write outside the maximum memory area of a growable JIT stack. A sufficiently large single stack...
π¨ CVE-2026-54812
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors motors-car-dealership-classified-listings allows Blind SQL Injection.This issue affects Motors: from n/a through 1.4.109.
π@cveNotify
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors motors-car-dealership-classified-listings allows Blind SQL Injection.This issue affects Motors: from n/a through 1.4.109.
π@cveNotify
Patchstack
SQL Injection in WordPress Motors Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-100143
The FluentCart A New Era of eCommerce WordPress plugin before 1.6.5 does not verify that the person placing a guest checkout controls the email address supplied, allowing unauthenticated attackers who know an existing guest customer's email to obtain a logged-in account bearing that address together with the customer's stored record.
π@cveNotify
The FluentCart A New Era of eCommerce WordPress plugin before 1.6.5 does not verify that the person placing a guest checkout controls the email address supplied, allowing unauthenticated attackers who know an existing guest customer's email to obtain a logged-in account bearing that address together with the customer's stored record.
π@cveNotify
WPScan
FluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Checkout Email
See details on FluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Checkout Email CVE 2026-100143. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-75823
The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor.
This affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained this way.
π@cveNotify
The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor.
This affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained this way.
π@cveNotify
WPScan
WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration Role Encryption
See details on WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration Role Encryption CVE 2026-75823. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-75824
The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled.
The created account receives the site's default role.
π@cveNotify
The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled.
The created account receives the site's default role.
π@cveNotify
WPScan
WP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Registration Disabled
See details on WP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Registration Disabled CVE 2026-75824. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-75873
The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution.
π@cveNotify
The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution.
π@cveNotify
WPScan
Zella Theme < 2.6.3 - Unauthenticated Arbitrary File Upload
See details on Zella Theme < 2.6.3 - Unauthenticated Arbitrary File Upload CVE 2026-75873. View the latest Theme Vulnerabilities on WPScan.
π¨ CVE-2026-80333
The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of any type that WordPress would otherwise not serve.
π@cveNotify
The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of any type that WordPress would otherwise not serve.
π@cveNotify
WPScan
Solace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure via Preview Routes
See details on Solace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure via Preview Routes CVE 2026-80333. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-82127
The Schema & Structured Data for WP & AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, nor escape them when outputting them back, allowing users with the editor role and above to inject arbitrary web scripts that execute when a higher privileged user views the affected screen. This is only exploitable on multisite installs, where editors do not hold the unfiltered_html capability.
π@cveNotify
The Schema & Structured Data for WP & AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, nor escape them when outputting them back, allowing users with the editor role and above to inject arbitrary web scripts that execute when a higher privileged user views the affected screen. This is only exploitable on multisite installs, where editors do not hold the unfiltered_html capability.
π@cveNotify
WPScan
Schema & Structured Data for WP & AMP < 1.67 - Editor+ Stored XSS via Taxonomy Term Fields
See details on Schema & Structured Data for WP & AMP < 1.67 - Editor+ Stored XSS via Taxonomy Term Fields CVE 2026-82127. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-83560
The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.
π@cveNotify
The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.
π@cveNotify
WPScan
New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier API Key Bypass
See details on New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier API Key Bypass CVE 2026-83560. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-85001
The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed.
π@cveNotify
The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed.
π@cveNotify
WPScan
EmbedPress 4.4.9 - 4.6.6 - Contributor+ Stored XSS via Elementor Widget showTitle Attribute
See details on EmbedPress 4.4.9 - 4.6.6 - Contributor+ Stored XSS via Elementor Widget showTitle Attribute CVE 2026-85001. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-85415
The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or editor reviewing the post).
π@cveNotify
The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or editor reviewing the post).
π@cveNotify
WPScan
Audio Player Block 1.1.0 - 1.6.2 - Contributor+ Stored XSS via Audio Download URL
See details on Audio Player Block 1.1.0 - 1.6.2 - Contributor+ Stored XSS via Audio Download URL CVE 2026-85415. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-85573
The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them.
π@cveNotify
The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them.
π@cveNotify
WPScan
All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SVG Upload
See details on All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SVG Upload CVE 2026-85573. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-85576
The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them.
π@cveNotify
The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them.
π@cveNotify
WPScan
All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings Update
See details on All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings Update CVE 2026-85576. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-86789
The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers to retrieve directory entries that are marked private or unlisted, or that are still pending moderation, including entry names, organizations, biographies, internal notes and street addresses.
The Connections Business Directory WordPress plugin through 10.4.67 has been closed on WordPress.org and no fixed version is available, so site owners should remove it or restrict unauthenticated access to its REST API routes.
π@cveNotify
The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers to retrieve directory entries that are marked private or unlisted, or that are still pending moderation, including entry names, organizations, biographies, internal notes and street addresses.
The Connections Business Directory WordPress plugin through 10.4.67 has been closed on WordPress.org and no fixed version is available, so site owners should remove it or restrict unauthenticated access to its REST API routes.
π@cveNotify
WPScan
Connections Business Directory <= 10.4.67 - Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST Routes
See details on Connections Business Directory <= 10.4.67 - Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST Routes CVE 2026-86789. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-87777
The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content in the editor.
π@cveNotify
The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content in the editor.
π@cveNotify
WPScan
Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attribute
See details on Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attribute CVE 2026-87777. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-88791
The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.
π@cveNotify
The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.
π@cveNotify
WPScan
Safe Redirect Manager < 2.3.0 - Open Redirect via Wildcard Redirect Rules
See details on Safe Redirect Manager < 2.3.0 - Open Redirect via Wildcard Redirect Rules CVE 2026-88791. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-88797
The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any hosted on the WordPress.org repository.
π@cveNotify
The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any hosted on the WordPress.org repository.
π@cveNotify
WPScan
Vayu X < 1.0.6 - Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation
See details on Vayu X < 1.0.6 - Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation CVE 2026-88797. View the latest Theme Vulnerabilities on WPScan.
π¨ CVE-2026-89190
The Robin Image Optimizer WordPress plugin before 2.0.8 does not check the user's capabilities before dispatching one of its bundled admin framework's request handlers, allowing users with a subscriber-level account to render admin-only Robin Image Optimizer WordPress plugin before 2.0.8 pages and disclose the Robin Image Optimizer WordPress plugin before 2.0.8's stored settings.
π@cveNotify
The Robin Image Optimizer WordPress plugin before 2.0.8 does not check the user's capabilities before dispatching one of its bundled admin framework's request handlers, allowing users with a subscriber-level account to render admin-only Robin Image Optimizer WordPress plugin before 2.0.8 pages and disclose the Robin Image Optimizer WordPress plugin before 2.0.8's stored settings.
π@cveNotify
WPScan
Robin Image Optimizer < 2.0.8 - Subscriber+ Plugin Settings Disclosure via fy_ajax
See details on Robin Image Optimizer < 2.0.8 - Subscriber+ Plugin Settings Disclosure via fy_ajax CVE 2026-89190. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-89193
The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.
π@cveNotify
The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.
π@cveNotify
WPScan
Robin Image Optimizer 2.0.0 - 2.0.7 - Unauthenticated Stored XSS via WebP URL Delivery HTML Parser
See details on Robin Image Optimizer 2.0.0 - 2.0.7 - Unauthenticated Stored XSS via WebP URL Delivery HTML Parser CVE 2026-89193. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-90953
The Image Optimizer WordPress plugin before 1.7.7 does not enforce its intended capability check on several of its read REST routes, allowing any authenticated user to read attachment metadata and site-wide statistics that should be restricted to administrators.
π@cveNotify
The Image Optimizer WordPress plugin before 1.7.7 does not enforce its intended capability check on several of its read REST routes, allowing any authenticated user to read attachment metadata and site-wide statistics that should be restricted to administrators.
π@cveNotify
WPScan
Image Optimizer by Elementor < 1.7.7 - Subscriber+ Attachment Metadata and Site Statistics Disclosure via Discarded REST Permissionβ¦
See details on Image Optimizer by Elementor < 1.7.7 - Subscriber+ Attachment Metadata and Site Statistics Disclosure via Discarded REST Permission Callbacks CVE 2026-90953. View the latest Plugin Vulnerabilities on WPScan.