Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-40778

Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through <= 1.1.2.

PUBLISHED
Vendor
Majestic Support
Product
Majestic Support
Provider severity
MEDIUM
Conflicts
1

CVE-2026-40776

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions.

PUBLISHED
Vendor
Arraytics
Product
WP Event SOlution
Provider severity
HIGH
Conflicts
0

CVE-2026-40775

Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions.

PUBLISHED
Vendor
Royal Plugins
Product
Royal MCP
Provider severity
HIGH
Conflicts
0

CVE-2026-40774

Unauthenticated Broken Access Control in Booking Package <= 1.7.06 versions.

PUBLISHED
Vendor
SaasProject
Product
Booking Package
Provider severity
HIGH
Conflicts
0

CVE-2026-40773

Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions.

PUBLISHED
Vendor
rtCamp Inc.
Product
rtMedia for WordPress, BuddyPress and bbPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40772

Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.

PUBLISHED
Vendor
Ahmad
Product
GeekyBot
Provider severity
CRITICAL
Conflicts
0

CVE-2026-40771

Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.

PUBLISHED
Vendor
Wasiliy Strecker
Product
Contest Gallery
Provider severity
CRITICAL
Conflicts
0

CVE-2026-40770

Unauthenticated Cross Site Scripting (XSS) in Coupon Affiliates <= 7.5.3 versions.

PUBLISHED
Vendor
RelyWP
Product
Coupon Affiliates
Provider severity
HIGH
Conflicts
0

CVE-2026-4077

The Ecover Builder For Dummies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'ecover' shortcode in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping on the user-supplied 'id' shortcode attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
miguelmartinezlopez
Product
Ecover Builder For Dummies
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40769

Unauthenticated Arbitrary File Deletion in Contact Form Extender for Divi &#8211; Save Entries, File Upload &amp; Country Code Field <= 1.0.6 versions.

PUBLISHED
Vendor
Satinder Singh
Product
Contact Form Extender for Divi &#8211; Save Entries, File Upload &amp; Country Code Field
Provider severity
HIGH
Conflicts
0

CVE-2026-40768

Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.

PUBLISHED
Vendor
Dimitri Grassi
Product
Salon booking system
Provider severity
HIGH
Conflicts
0

CVE-2026-40767

Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions.

PUBLISHED
Vendor
Tomdever
Product
wpForo Forum
Provider severity
HIGH
Conflicts
0

CVE-2026-40766

Subscriber SQL Injection in MasterStudy LMS <= 3.7.25 versions.

PUBLISHED
Vendor
StylemixThemes
Product
MasterStudy LMS
Provider severity
HIGH
Conflicts
0

CVE-2026-40765

Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions.

PUBLISHED
Vendor
collectchat
Product
collectchat
Provider severity
HIGH
Conflicts
0

CVE-2026-40764

Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Request Forgery.This issue affects Contact Form by WPForms: from n/a through <= 1.10.0.2.

PUBLISHED
Vendor
Syed Balkhi
Product
Contact Form by WPForms
Provider severity
HIGH
Conflicts
1

CVE-2026-40763

Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1056.

PUBLISHED
Vendor
WP Royal
Product
Royal Elementor Addons
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40762

Unauthenticated SQL Injection in WPGraphQL < 2.11.1 versions.

PUBLISHED
Vendor
WPGraphQL
Product
WPGraphQL
Provider severity
HIGH
Conflicts
0

CVE-2026-40761

Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.

PUBLISHED
Vendor
Edge-Themes
Product
Valeska
Provider severity
HIGH
Conflicts
0

CVE-2026-40760

Unauthenticated PHP Object Injection in Behold <= 1.5 versions.

PUBLISHED
Vendor
Edge-Themes
Product
Behold
Provider severity
HIGH
Conflicts
0

CVE-2026-4076

The Slider Bootstrap Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'category' and 'template' shortcode attributes in all versions up to and including 1.0.7. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. The plugin uses extract() on shortcode_atts() to parse attributes, then directly outputs the $category variable into multiple HTML attributes (id, data-target, href) on lines 38, 47, 109, and 113 with

PUBLISHED
Vendor
felipermendes
Product
Slider Bootstrap Carousel
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40759

Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.

PUBLISHED
Vendor
Mikado-Themes
Product
Esmée
Provider severity
HIGH
Conflicts
0

CVE-2026-40758

Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.

PUBLISHED
Vendor
Elated-Themes
Product
Léonie
Provider severity
HIGH
Conflicts
0

CVE-2026-40757

Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.

PUBLISHED
Vendor
Mikado-Themes
Product
Château
Provider severity
HIGH
Conflicts
0

CVE-2026-40756

Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.

PUBLISHED
Vendor
Mikado-Themes
Product
Zoya
Provider severity
HIGH
Conflicts
0

CVE-2026-40755

Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.

PUBLISHED
Vendor
Mikado-Themes
Product
TechLink
Provider severity
HIGH
Conflicts
0

CVE-2026-40754

Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.

PUBLISHED
Vendor
Elated-Themes
Product
Roisin
Provider severity
HIGH
Conflicts
0

CVE-2026-40753

Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.

PUBLISHED
Vendor
Mikado-Themes
Product
EasyMeals
Provider severity
HIGH
Conflicts
0

CVE-2026-40752

Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.

PUBLISHED
Vendor
Select-Themes
Product
Manufaktur Solutions
Provider severity
HIGH
Conflicts
0

CVE-2026-40751

Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.

PUBLISHED
Vendor
Mikado-Themes
Product
Ashtanga
Provider severity
HIGH
Conflicts
0

CVE-2026-40750

Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9.

PUBLISHED
Vendor
themagnifico52
Product
Kids Online Store
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4075

The BWL Advanced FAQ Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'baf_sbox' shortcode in all versions up to and including 1.1.1. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes such as 'sbox_id', 'sbox_class', 'placeholder', 'highlight_color', 'highlight_bg', and 'cont_ext_class'. These attributes are directly interpolated into HTML element attributes without any esc_attr() escaping in the baf_sbo

PUBLISHED
Vendor
xenioushk
Product
BWL Advanced FAQ Manager Lite
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40749

Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.

PUBLISHED
Vendor
themagnifico52
Product
Charity Zone
Provider severity
CRITICAL
Conflicts
0

CVE-2026-40748

Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.

PUBLISHED
Vendor
themagnifico52
Product
Kids Gift Shop
Provider severity
CRITICAL
Conflicts
0

CVE-2026-40747

Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.

PUBLISHED
Vendor
themagnifico52
Product
Ecommerce Zone
Provider severity
CRITICAL
Conflicts
0

CVE-2026-40746

Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.

PUBLISHED
Vendor
themagnifico52
Product
Restaurant Zone
Provider severity
CRITICAL
Conflicts
0

CVE-2026-40745

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bdthemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Blind SQL Injection.This issue affects Element Pack Elementor Addons: from n/a through <= 8.4.2.

PUBLISHED
Vendor
bdthemes
Product
Element Pack Elementor Addons
Provider severity
HIGH
Conflicts
0

CVE-2026-40744

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beaver Builder Beaver Builder beaver-builder-lite-version allows Blind SQL Injection.This issue affects Beaver Builder: from n/a through <= 2.10.1.2.

PUBLISHED
Vendor
Beaver Builder
Product
Beaver Builder
Provider severity
HIGH
Conflicts
0

CVE-2026-40743

Unauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions.

PUBLISHED
Vendor
Themeum
Product
Tutor LMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40742

Missing Authorization vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nelio AB Testing: from n/a through <= 8.2.8.

PUBLISHED
Vendor
Nelio Software
Product
Nelio AB Testing
Provider severity
MEDIUM
Conflicts
1

CVE-2026-40741

Unauthenticated Broken Access Control in Redsys for WooCommerce Light <= 7.0.0 versions.

PUBLISHED
Vendor
Jose Conti
Product
Redsys for WooCommerce Light
Provider severity
HIGH
Conflicts
0

CVE-2026-40740

Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.7.

PUBLISHED
Vendor
Themeum
Product
Tutor LMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4074

The Quran Live Multilanguage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cheikh' and 'lang' shortcode attributes in all versions up to, and including, 1.0.3. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. The quran_live_render() function of quran-live.php receives shortcode attributes and passes them directly through shortcode_atts() and extract() without any sanitization. These values are then passed to Re

PUBLISHED
Vendor
karim42
Product
Quran Live Multilanguage
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40739

Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.

PUBLISHED
Vendor
Mikado-Themes
Product
LuxeDrive
Provider severity
HIGH
Conflicts
0

CVE-2026-40738

Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.

PUBLISHED
Vendor
Edge-Themes
Product
Eldon
Provider severity
HIGH
Conflicts
0

CVE-2026-40737

Authorization Bypass Through User-Controlled Key vulnerability in VillaTheme COMPE compe-woo-compare-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects COMPE: from n/a through <= 1.1.4.

PUBLISHED
Vendor
VillaTheme
Product
COMPE
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40736

Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.

PUBLISHED
Vendor
Edge-Themes
Product
Laurits
Provider severity
HIGH
Conflicts
0

CVE-2026-40735

Unauthenticated PHP Object Injection in Reina <= 2.1 versions.

PUBLISHED
Vendor
Edge-Themes
Product
Reina
Provider severity
HIGH
Conflicts
0

CVE-2026-40734

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zahlan Categories Images categories-images allows DOM-Based XSS.This issue affects Categories Images: from n/a through <= 3.3.1.

PUBLISHED
Vendor
Zahlan
Product
Categories Images
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40733

Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.

PUBLISHED
Vendor
Mikado-Themes
Product
ShiftUp
Provider severity
HIGH
Conflicts
0

CVE-2026-40732

Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5 versions.

PUBLISHED
Vendor
rainafarai
Product
Notification for Telegram
Provider severity
HIGH
Conflicts
0