Total CVEs

150,976

Critical Severity

5,036

High Severity

17,677

Last 7 Days

2,131
Quick preset (or use dates below)
Clear Filters
Showing 2,521 - 2,540 of 150,976 CVEs
CVE-2026-16078 MEDIUM - 6.5

The WCPOS โ€“ Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9.8 via the 'type' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access and above, to ...

Vendor: kilbot
Product: WCPOS โ€“ Point of Sale (POS) plugin for WooCommerce
Published: Jul 23, 2026
Source: NVD
CVE-2026-15906 MEDIUM - 6.5

The Premium Packages โ€“ Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the ex...

Vendor: codename065
Product: Premium Packages โ€“ Sell Digital Products Securely
Published: Jul 23, 2026
Source: NVD
CVE-2026-15827 MEDIUM - 5.3

The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/gutenkit/v1/mailchimp/get/lists and /wp-json/gutenkit/v1/mailchimp/get/interests REST API endpoints in versions up to, and including, 2.4.12. Both endpoints are reg...

Vendor: ataurr
Product: GutenKit โ€“ Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor
Published: Jul 23, 2026
Source: NVD
CVE-2026-15794 MEDIUM - 6.4

The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

Vendor: berocket
Product: Grid/List View for WooCommerce
Published: Jul 23, 2026
Source: NVD
CVE-2026-15786 MEDIUM - 4.9

The WP Encryption โ€“ One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for authenticated at...

Vendor: gowebsmarty
Product: WP Encryption โ€“ Lifetime Free SSL Cert & HTTPS, Force SSL / HTTPS Redirect, SSL Security
Published: Jul 23, 2026
Source: NVD
CVE-2026-15761 MEDIUM - 6.5

The Tickera โ€“ Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...

Vendor: tickera
Product: Tickera โ€“ Sell Tickets & Manage Events
Published: Jul 23, 2026
Source: NVD
CVE-2026-15647 MEDIUM - 4.4

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

Vendor: berocket
Product: Brands for WooCommerce
Published: Jul 23, 2026
Source: NVD
CVE-2026-15646 MEDIUM - 6.4

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with cont...

Vendor: berocket
Product: Brands for WooCommerce
Published: Jul 23, 2026
Source: NVD
CVE-2026-15448 MEDIUM - 6.5

The Tickera โ€“ Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...

Vendor: tickera
Product: Tickera โ€“ Sell Tickets & Manage Events
Published: Jul 23, 2026
Source: NVD
CVE-2026-15404 MEDIUM - 6.4

The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.5.7. This is due to insufficient input sanitization and output escaping in the lpagery_add_filter_text_template_post() function, which is hooked to admin_footer and echoe...

Vendor: niklaslindemann
Product: Bulk Page Generator โ€“ LPagery
Published: Jul 23, 2026
Source: NVD
CVE-2026-15394 MEDIUM - 6.4

The Header Footer Script Adder โ€“ Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code' Snippet Meta in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possib...

Vendor: mahethekiller
Product: Header Footer Script Adder
Published: Jul 23, 2026
Source: NVD
CVE-2026-15348 MEDIUM - 6.3

The Premium Packages โ€“ Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via the `wpdmppdl` parameter. This is due to the `download()` function โ€” hooked to the unauthenticated WordPress `wp` action โ€” decoding the at...

Vendor: codename065
Product: Premium Packages โ€“ Sell Digital Products Securely
Published: Jul 23, 2026
Source: NVD
CVE-2026-15017 HIGH - 8.8

The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined wit...

Vendor: mdjm
Product: MDJM Event Management
Published: Jul 23, 2026
Source: NVD
CVE-2026-15015 CRITICAL - 9.8

The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to...

Vendor: cascadiawebservices
Product: MountDev AI MCP Connector for WordPress
Published: Jul 23, 2026
Source: NVD
CVE-2026-15011 CRITICAL - 9.8

The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation. This makes...

Vendor: emarket-design
Product: Customer Support Ticket System & Helpdesk
Published: Jul 23, 2026
Source: NVD
CVE-2026-14481 MEDIUM - 6.4

The Equalize Digital Accessibility Checker โ€“ WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'html' parameter in all versions up to, and including, 1.46.0 due to insufficient input sanitization and output escaping. This ma...

Vendor: equalizedigital
Product: Equalize Digital Accessibility Checker โ€“ WCAG, ADA, EAA and Section 508 compliance
Published: Jul 23, 2026
Source: NVD
CVE-2026-14282 CRITICAL - 9.8

The GoDAM โ€“ Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This is due to insufficient file type validation in the save_video_file() functi...

Vendor: rtcamp
Product: GoDAM โ€“ Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more
Published: Jul 23, 2026
Source: NVD
CVE-2026-13119 MEDIUM - 6.5

The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard&...

Vendor: roundupwp
Product: Registrations for the Events Calendar โ€“ Event Registration Plugin
Published: Jul 23, 2026
Source: NVD
CVE-2026-13009 MEDIUM - 6.5

The AI Copilot โ€“ Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query....

Vendor: wupsales
Product: AI Copilot โ€“ Content Generator
Published: Jul 23, 2026
Source: NVD
CVE-2026-52688 HIGH - 7.5

RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation

Vendor: PowerDNS
Product: Recursor
Published: Jul 23, 2026
Source: NVD