Search
442 CVEs · published 2026-08-12 to 2026-08-12
CVEs (442)
Showing 376–400 of 442
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-18048 | HIGH | Patched | 7.5 | 2026-08-12 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a file path in one of its public endpoint actions, and … |
| CVE-2026-18046 | MEDIUM | Patched | 4.3 | 2026-08-12 | The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability check on the REST route that stores its geolocation… |
| CVE-2026-18035 | MEDIUM | Patched | 5.3 | 2026-08-12 | The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content o… |
| CVE-2026-17013 | MEDIUM | Patched | 6.1 | 2026-08-12 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into an inline script block, which could allow unau… |
| CVE-2026-16977 | HIGH | Patched | 8.1 | 2026-08-12 | The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a dat… |
| CVE-2026-16737 | MEDIUM | Patched | 5.3 | 2026-08-12 | The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unaut… |
| CVE-2026-16538 | CRITICAL | Patched | 9.1 | 2026-08-12 | The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wallet, allowing customers … |
| CVE-2026-16294 | HIGH | Patched | 7.1 | 2026-08-12 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side reques… |
| CVE-2026-16253 | HIGH | Patched | 7.5 | 2026-08-12 | The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-restore functionality and exposes it to unauthenticated u… |
| CVE-2026-16066 | MEDIUM | Patched | 5.4 | 2026-08-12 | The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it on the product pages, allowing users with the Author… |
| CVE-2026-16051 | CRITICAL | Patched | 9.8 | 2026-08-12 | The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those request… |
| CVE-2026-15388 | MEDIUM | Patched | 4.3 | 2026-08-12 | The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability check on its consent-settings REST routes, so they … |
| CVE-2026-15249 | MEDIUM | 5.4 | 2026-08-12 | The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts it into the page, allowing users with a role as low a… | |
| CVE-2026-15039 | CRITICAL | Patched | 9.8 | 2026-08-12 | The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload arbitrary file… |
| CVE-2026-14925 | HIGH | Patched | 7.5 | 2026-08-12 | The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file download handlers, allowing unauthenticated attackers to d… |
| CVE-2026-14859 | MEDIUM | Patched | 4.3 | 2026-08-12 | The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX actions, allowing any authenticated users such as Sub… |
| CVE-2026-14858 | MEDIUM | Patched | 4.3 | 2026-08-12 | The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing any authenticated users such as Subscribers to re… |
| CVE-2026-14857 | MEDIUM | Patched | 4.3 | 2026-08-12 | The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update history to be modified and a notification email sent to… |
| CVE-2026-13613 | HIGH | Patched | 8.8 | 2026-08-12 | The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users wi… |
| CVE-2026-13612 | MEDIUM | Patched | 4.3 | 2026-08-12 | The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, allowing authenticated patient-level users to read oth… |
| CVE-2026-13177 | MEDIUM | Patched | 4.3 | 2026-08-12 | The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing users with contributor-level access and above to read ot… |
| CVE-2026-13171 | HIGH | Patched | 8.2 | 2026-08-12 | The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordP… |
| CVE-2026-13168 | MEDIUM | Patched | 6.5 | 2026-08-12 | The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users with contributor-level access and above to read oth… |
| CVE-2026-12976 | MEDIUM | Patched | 6.5 | 2026-08-12 | The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-assistant requests against that course's lesson conte… |
| CVE-2026-64954 | HIGH | 8.2 | 2026-08-12 | Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, t… |