Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-25436

Missing Authorization vulnerability in WProyal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal Elementor Addons: from n/a before 1.7.1053.

PUBLISHED
Vendor
WProyal
Product
Royal Elementor Addons
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25435

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Stored XSS.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.36.

PUBLISHED
Vendor
wpdevart
Product
Booking calendar, Appointment Booking System
Provider severity
HIGH
Conflicts
0

CVE-2026-25432

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omnipressteam Omnipress omnipress allows Stored XSS.This issue affects Omnipress: from n/a through <= 1.6.7.

PUBLISHED
Vendor
omnipressteam
Product
Omnipress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25431

Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hustle: through 7.8.10.1.

PUBLISHED
Vendor
WPMU DEV
Product
Hustle
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25430

Missing Authorization vulnerability in CRM Perks Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms cf7-mailchimp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through <= 1.2.2.

PUBLISHED
Vendor
CRM Perks
Product
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2543

A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects unknown code of the file inc/mod/pages.php of the component Password Change Handler. The manipulation of the argument Password leads to unverified password change. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
vichan-devel
Product
vichan
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-25429

Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue affects Nexa Blocks: from n/a through <= 1.1.1.

PUBLISHED
Vendor
wpdive
Product
Nexa Blocks
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25428

Server-Side Request Forgery (SSRF) vulnerability in totalsoft TS Poll poll-wp allows Server Side Request Forgery.This issue affects TS Poll: from n/a through <= 2.5.5.

PUBLISHED
Vendor
totalsoft
Product
TS Poll
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25427

Subscriber Broken Access Control in eRoom <= 1.7.1 versions.

PUBLISHED
Vendor
DigitalME
Product
eRoom
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25426

Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.0.1.

PUBLISHED
Vendor
Magepeople inc.
Product
Taxi Booking Manager for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25425

Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions.

PUBLISHED
Vendor
ThemeGrill
Product
User Registration
Provider severity
HIGH
Conflicts
0

CVE-2026-25424

Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.

PUBLISHED
Vendor
mediavine
Product
Mediavine Control Panel
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25423

Missing Authorization vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real 3D FlipBook: from n/a through <= 4.19.1.

PUBLISHED
Vendor
creativeinteractivemedia
Product
Real 3D FlipBook
Provider severity
LOW
Conflicts
0

CVE-2026-25422

Cross-Site Request Forgery (CSRF) vulnerability in Themes4WP Popularis Extra popularis-extra allows Cross Site Request Forgery.This issue affects Popularis Extra: from n/a through <= 1.2.10.

PUBLISHED
Vendor
Themes4WP
Product
Popularis Extra
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25420

Missing Authorization vulnerability in MailerLite MailerLite official-mailerlite-sign-up-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MailerLite: from n/a through <= 1.7.18.

PUBLISHED
Vendor
MailerLite
Product
MailerLite
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2542

A weakness has been identified in Total VPN 0.5.29.0 on Windows. Affected by this vulnerability is an unknown functionality of the file C:\Program Files\Total VPN\win-service.exe. Executing a manipulation can lead to unquoted search path. It is possible to launch the attack on the local host. This attack is characterized by high complexity. The exploitation appears to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
n/a
Product
Total VPN
Provider severity
HIGH
Conflicts
2

CVE-2026-25419

Missing Authorization vulnerability in flycart UpsellWP checkout-upsell-and-order-bumps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UpsellWP: from n/a through <= 2.2.5.

PUBLISHED
Vendor
flycart
Product
UpsellWP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25418

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form bit-form allows SQL Injection.This issue affects Bit Form: from n/a through <= 2.21.10.

PUBLISHED
Vendor
Bit Apps
Product
Bit Form
Provider severity
HIGH
Conflicts
0

CVE-2026-25417

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Stored XSS.This issue affects ProfileGrid : from n/a through <= 5.9.8.1.

PUBLISHED
Vendor
Metagauss
Product
ProfileGrid
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25416

Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects News Kit Elementor Addons: from n/a through <= 1.4.2.

PUBLISHED
Vendor
blazethemes
Product
News Kit Elementor Addons
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25415

Missing Authorization vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPBookit Pro: from n/a through <= 1.6.18.

PUBLISHED
Vendor
iqonicdesign
Product
WPBookit Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25414

Incorrect Privilege Assignment vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Privilege Escalation.This issue affects WPBookit Pro: from n/a through <= 1.6.18.

PUBLISHED
Vendor
iqonicdesign
Product
WPBookit Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-25413

Unrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Malicious Files.This issue affects WPBookit Pro: from n/a through <= 1.6.18.

PUBLISHED
Vendor
iqonicdesign
Product
WPBookit Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25411

Cross-Site Request Forgery (CSRF) vulnerability in themastercut Revision Manager TMC revision-manager-tmc allows Cross Site Request Forgery.This issue affects Revision Manager TMC: from n/a through <= 2.8.22.

PUBLISHED
Vendor
themastercut
Product
Revision Manager TMC
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25410

Missing Authorization vulnerability in tstephenson WP-CORS wp-cors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-CORS: from n/a through <= 0.2.2.

PUBLISHED
Vendor
tstephenson
Product
WP-CORS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2541

The Micca KE700 system relies on a 6-bit portion of an identifier for authentication within rolling codes, providing only 64 possible combinations. This low entropy allows an attacker to perform a brute-force attack against one component of the rolling code. Successful exploitation simplify an attacker to predict the next valid rolling code, granting unauthorized access to the vehicle.

PUBLISHED
Vendor
Micca Auto Electronics Co., Ltd.
Product
Car Alarm System KE700
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25409

Missing Authorization vulnerability in crgeary JAMstack Deployments wp-jamstack-deployments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JAMstack Deployments: from n/a through <= 1.1.1.

PUBLISHED
Vendor
crgeary
Product
JAMstack Deployments
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25408

Missing Authorization vulnerability in PluginRx Broken Link Notifier broken-link-notifier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Broken Link Notifier: from n/a through <= 1.3.5.

PUBLISHED
Vendor
PluginRx
Product
Broken Link Notifier
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25407

Missing Authorization vulnerability in cookiebot Cookiebot cookiebot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cookiebot: from n/a through <= 4.6.4.

PUBLISHED
Vendor
cookiebot
Product
Cookiebot
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25406

Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeum Tutor LMS Pro tutor-pro allows Authentication Abuse.This issue affects Tutor LMS Pro: from n/a through <= 3.9.4.

PUBLISHED
Vendor
Themeum
Product
Tutor LMS Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-25405

Contributor SQL Injection in eRoom <= 1.7.1 versions.

PUBLISHED
Vendor
DigitalME
Product
eRoom
Provider severity
HIGH
Conflicts
0

CVE-2026-25404

Missing Authorization vulnerability in Automattic WP Job Manager wp-job-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Manager: from n/a through <= 2.4.0.

PUBLISHED
Vendor
Automattic
Product
WP Job Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25402

Missing Authorization vulnerability in echoplugins Knowledge Base for Documentation, FAQs with AI Assistance echo-knowledge-base allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Knowledge Base for Documentation, FAQs with AI Assistance: from n/a through <= 16.011.0.

PUBLISHED
Vendor
echoplugins
Product
Knowledge Base for Documentation, FAQs with AI Assistance
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25401

Missing Authorization vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCargo Track & Trace: from n/a through <= 8.0.2.

PUBLISHED
Vendor
Arni Cinco
Product
WPCargo Track & Trace
Provider severity
HIGH
Conflicts
0

CVE-2026-25400

Deserialization of Untrusted Data vulnerability in thememount Apicona apicona allows Object Injection.This issue affects Apicona: from n/a through <= 24.1.0.

PUBLISHED
Vendor
thememount
Product
Apicona
Provider severity
HIGH
Conflicts
0

CVE-2026-2540

The Micca KE700 system contains flawed resynchronization logic and is vulnerable to replay attacks. This attack requires sending two previously captured codes in a specific sequence. As a result, the system can be forced to accept previously used (stale) rolling codes and execute a command. Successful exploitation allows an attacker to clone the alarm key. This grants the attacker unauthorized access to the vehicle to unlock or lock the doors.

PUBLISHED
Vendor
Micca Auto Electronics Co., Ltd.
Product
Car Alarm System KE700
Provider severity
HIGH
Conflicts
1

CVE-2026-25399

Missing Authorization vulnerability in CryoutCreations Serious Slider cryout-serious-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Serious Slider: from n/a through <= 1.2.7.

PUBLISHED
Vendor
CryoutCreations
Product
Serious Slider
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25398

Missing Authorization vulnerability in Webilia Inc. Vertex Addons for Elementor addons-for-elementor-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vertex Addons for Elementor: from n/a through <= 1.6.4.

PUBLISHED
Vendor
Webilia Inc.
Product
Vertex Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25397

Path Traversal: '.../...//' vulnerability in Snowray Software File Uploader for WooCommerce file-uploader-for-woocommerce allows Path Traversal.This issue affects File Uploader for WooCommerce: from n/a through <= 1.0.4.

PUBLISHED
Vendor
Snowray Software
Product
File Uploader for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-25396

Missing Authorization vulnerability in CoderPress Commerce Coinbase For WooCommerce commerce-coinbase-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Commerce Coinbase For WooCommerce: from n/a through <= 1.6.6.

PUBLISHED
Vendor
CoderPress
Product
Commerce Coinbase For WooCommerce
Provider severity
HIGH
Conflicts
1

CVE-2026-25395

Missing Authorization vulnerability in ikreatethemes Business Roy business-roy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Roy: from n/a through <= 1.1.4.

PUBLISHED
Vendor
ikreatethemes
Product
Business Roy
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25394

Missing Authorization vulnerability in sparklewpthemes Fitness FSE fitness-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fitness FSE: from n/a through <= 1.0.6.

PUBLISHED
Vendor
sparklewpthemes
Product
Fitness FSE
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25393

Missing Authorization vulnerability in sparklewpthemes Hello FSE hello-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hello FSE: from n/a through <= 1.0.6.

PUBLISHED
Vendor
sparklewpthemes
Product
Hello FSE
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25392

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in KaizenCoders Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress update-urls allows Phishing.This issue affects Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress: from n/a through <= 1.4.3.

PUBLISHED
Vendor
KaizenCoders
Product
Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25391

Missing Authorization vulnerability in WP Grids WP Wand ai-content-generation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Wand: from n/a through <= 1.3.07.

PUBLISHED
Vendor
WP Grids
Product
WP Wand
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25390

Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects New User Approve: from n/a through <= 3.2.3.

PUBLISHED
Vendor
Saad Iqbal
Product
New User Approve
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2539

The RF communication protocol in the Micca KE700 car alarm system does not encrypt its data frames. An attacker with a radio interception tool (e.g., SDR) can capture the random number and counters transmitted in cleartext, which is sensitive information required for authentication.

PUBLISHED
Vendor
Micca Auto Electronics Co., Ltd.
Product
Car Alarm System KE700
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25389

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Retrieve Embedded Sensitive Data.This issue affects EventPrime: from n/a through <= 4.2.8.3.

PUBLISHED
Vendor
Metagauss
Product
EventPrime
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25388

Missing Authorization vulnerability in scripteo Ads Pro ap-plugin-scripteo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ads Pro: from n/a through <= 5.0.

PUBLISHED
Vendor
scripteo
Product
Ads Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25387

Missing Authorization vulnerability in Elementor Image Optimizer by Elementor image-optimization allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Optimizer by Elementor: from n/a through <= 1.7.1.

PUBLISHED
Vendor
Elementor
Product
Image Optimizer by Elementor
Provider severity
MEDIUM
Conflicts
0