Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-24987

Missing Authorization vulnerability in activity-log.com WP System Log winterlock allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP System Log: from n/a through <= 1.2.7.

PUBLISHED
Vendor
activity-log.com
Product
WP System Log
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24986

Cross-Site Request Forgery (CSRF) vulnerability in wp.insider Simple Membership WP user Import simple-membership-wp-user-import allows Cross Site Request Forgery.This issue affects Simple Membership WP user Import: from n/a through <= 1.9.1.

PUBLISHED
Vendor
wp.insider
Product
Simple Membership WP user Import
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24985

Missing Authorization vulnerability in approveme WP Forms Signature Contract Add-On wp-forms-signature-contract-add-on allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Forms Signature Contract Add-On: from n/a through <= 1.8.2.

PUBLISHED
Vendor
approveme
Product
WP Forms Signature Contract Add-On
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24984

Missing Authorization vulnerability in Brecht Visual Link Preview visual-link-preview allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Visual Link Preview: from n/a through <= 2.2.9.

PUBLISHED
Vendor
Brecht
Product
Visual Link Preview
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24983

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UpSolution UpSolution Core us-core allows Reflected XSS.This issue affects UpSolution Core: from n/a through <= 8.41.

PUBLISHED
Vendor
UpSolution
Product
UpSolution Core
Provider severity
HIGH
Conflicts
0

CVE-2026-24982

Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.17.

PUBLISHED
Vendor
Brainstorm Force
Product
Spectra
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24981

Deserialization of Untrusted Data vulnerability in NooTheme Visionary Core noo-visionary-core allows Object Injection.This issue affects Visionary Core: from n/a through <= 1.4.9.

PUBLISHED
Vendor
NooTheme
Product
Visionary Core
Provider severity
HIGH
Conflicts
0

CVE-2026-24980

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Visionary Core noo-visionary-core allows Reflected XSS.This issue affects Visionary Core: from n/a through <= 1.4.9.

PUBLISHED
Vendor
NooTheme
Product
Visionary Core
Provider severity
HIGH
Conflicts
0

CVE-2026-2498

The WP Social Meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has bee

PUBLISHED
Vendor
bulktheme
Product
WP Social Meta
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24979

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobica Core jobica-core allows Reflected XSS.This issue affects Jobica Core: from n/a through <= 1.4.1.

PUBLISHED
Vendor
NooTheme
Product
Jobica Core
Provider severity
HIGH
Conflicts
0

CVE-2026-24978

Deserialization of Untrusted Data vulnerability in NooTheme Jobica Core jobica-core allows Object Injection.This issue affects Jobica Core: from n/a through <= 1.4.1.

PUBLISHED
Vendor
NooTheme
Product
Jobica Core
Provider severity
HIGH
Conflicts
0

CVE-2026-24977

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Organici Library noo-organici-library allows Blind SQL Injection.This issue affects Organici Library: from n/a through <= 2.1.2.

PUBLISHED
Vendor
NooTheme
Product
Organici Library
Provider severity
HIGH
Conflicts
0

CVE-2026-24976

Deserialization of Untrusted Data vulnerability in NooTheme Organici Library noo-organici-library allows Object Injection.This issue affects Organici Library: from n/a through <= 2.1.2.

PUBLISHED
Vendor
NooTheme
Product
Organici Library
Provider severity
HIGH
Conflicts
0

CVE-2026-24975

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Organici Library noo-organici-library allows Reflected XSS.This issue affects Organici Library: from n/a through <= 2.1.2.

PUBLISHED
Vendor
NooTheme
Product
Organici Library
Provider severity
HIGH
Conflicts
0

CVE-2026-24974

Deserialization of Untrusted Data vulnerability in NooTheme CitiLights noo-citilights allows Object Injection.This issue affects CitiLights: from n/a through <= 3.7.1.

PUBLISHED
Vendor
NooTheme
Product
CitiLights
Provider severity
HIGH
Conflicts
0

CVE-2026-24973

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme CitiLights noo-citilights allows Reflected XSS.This issue affects CitiLights: from n/a through <= 3.7.1.

PUBLISHED
Vendor
NooTheme
Product
CitiLights
Provider severity
HIGH
Conflicts
0

CVE-2026-24972

Missing Authorization vulnerability in Elated-Themes Elated Listing eltd-listing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elated Listing: from n/a through <= 1.4.

PUBLISHED
Vendor
Elated-Themes
Product
Elated Listing
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24971

Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n/a through <= 2.8.

PUBLISHED
Vendor
Elated-Themes
Product
Search & Go
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24970

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Energox energox allows Path Traversal.This issue affects Energox: from n/a through <= 1.2.

PUBLISHED
Vendor
designingmedia
Product
Energox
Provider severity
HIGH
Conflicts
0

CVE-2026-24969

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Instant VA instantva allows Path Traversal.This issue affects Instant VA: from n/a through <= 1.0.1.

PUBLISHED
Vendor
designingmedia
Product
Instant VA
Provider severity
HIGH
Conflicts
0

CVE-2026-24968

Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a through <= 7.1.0.30.

PUBLISHED
Vendor
Xagio SEO
Product
Xagio SEO
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24967

Missing Authorization vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through <= 1.2.38.

PUBLISHED
Vendor
ameliabooking
Product
Amelia
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24966

Cross-Site Request Forgery (CSRF) vulnerability in Copyscape Copyscape Premium copyscape-premium allows Cross Site Request Forgery.This issue affects Copyscape Premium: from n/a through <= 1.4.1.

PUBLISHED
Vendor
Copyscape
Product
Copyscape Premium
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24965

Missing Authorization vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contest Gallery: from n/a through <= 28.1.1.

PUBLISHED
Vendor
Wasiliy Strecker / ContestGallery developer
Product
Contest Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24964

Server-Side Request Forgery (SSRF) vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Server Side Request Forgery.This issue affects Contest Gallery: from n/a through <= 28.1.2.1.

PUBLISHED
Vendor
Wasiliy Strecker / ContestGallery developer
Product
Contest Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24963

Incorrect Privilege Assignment vulnerability in ameliabooking Amelia ameliabooking allows Privilege Escalation.This issue affects Amelia: from n/a through <= 1.2.38.

PUBLISHED
Vendor
ameliabooking
Product
Amelia
Provider severity
HIGH
Conflicts
0

CVE-2026-24962

Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Sigmize sigmize allows Cross Site Request Forgery.This issue affects Sigmize: from n/a through <= 0.0.9.

PUBLISHED
Vendor
Brainstorm Force
Product
Sigmize
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24961

Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Server Side Request Forgery.This issue affects Grand Blog: from n/a through < 3.1.5.

PUBLISHED
Vendor
ThemeGoods
Product
Grand Blog
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24960

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Charety charety allows Using Malicious Files.This issue affects Charety: from n/a through < 2.0.2.

PUBLISHED
Vendor
zozothemes
Product
Charety
Provider severity
CRITICAL
Conflicts
0

CVE-2026-2496

The Ed's Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `eds_font_awesome` shortcode in all versions up to, and including, 2.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
waianaeboy702
Product
Ed's Font Awesome
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24959

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL Injection.This issue affects JS Help Desk: from n/a through <= 3.0.1.

PUBLISHED
Vendor
JoomSky
Product
JS Help Desk
Provider severity
HIGH
Conflicts
0

CVE-2026-24958

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows DOM-Based XSS.This issue affects JetElements For Elementor: from n/a through <= 2.7.12.2.

PUBLISHED
Vendor
Crocoblock
Product
JetElements For Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24957

Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Strong Testimonials: from n/a through <= 3.2.20.

PUBLISHED
Vendor
WP Chill
Product
Strong Testimonials
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24956

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada Download Manager Addons for Elementor wpdm-elementor allows Blind SQL Injection.This issue affects Download Manager Addons for Elementor: from n/a through <= 1.3.0.

PUBLISHED
Vendor
Shahjada
Product
Download Manager Addons for Elementor
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24955

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fox-themes Whizz Plugins whizz-plugins allows Reflected XSS.This issue affects Whizz Plugins: from n/a through <= 1.9.

PUBLISHED
Vendor
fox-themes
Product
Whizz Plugins
Provider severity
HIGH
Conflicts
0

CVE-2026-24954

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.0.8.

PUBLISHED
Vendor
magepeopleteam
Product
WpEvently
Provider severity
HIGH
Conflicts
0

CVE-2026-24953

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitchell Bennis Simple File List simple-file-list allows Path Traversal.This issue affects Simple File List: from n/a through <= 6.1.15.

PUBLISHED
Vendor
Mitchell Bennis
Product
Simple File List
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24952

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Stored XSS.This issue affects Seriously Simple Podcasting: from n/a through <= 3.14.1.

PUBLISHED
Vendor
Craig Hewitt
Product
Seriously Simple Podcasting
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24951

Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 2.9.7.3.

PUBLISHED
Vendor
Saad Iqbal
Product
myCred
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24950

Authorization Bypass Through User-Controlled Key vulnerability in themeplugs Authorsy authorsy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Authorsy: from n/a through <= 1.0.6.

PUBLISHED
Vendor
themeplugs
Product
Authorsy
Provider severity
HIGH
Conflicts
0

CVE-2026-2495

The WPNakama – Team and multi-Client Collaboration, Editorial and Project Management plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the '/wp-json/WPNakama/v1/boards' REST API endpoint in all versions up to, and including, 0.6.5. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing

PUBLISHED
Vendor
qdonow
Product
WPNakama – Team and multi-Client Collaboration, Editorial and Project Management
Provider severity
HIGH
Conflicts
0

CVE-2026-24949

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods PhotoMe photome allows DOM-Based XSS.This issue affects PhotoMe: from n/a through <= 5.7.1.

PUBLISHED
Vendor
ThemeGoods
Product
PhotoMe
Provider severity
HIGH
Conflicts
0

CVE-2026-24948

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fox-themes Reflector reflector-plugins allows Reflected XSS.This issue affects Reflector: from n/a through <= 1.2.2.

PUBLISHED
Vendor
fox-themes
Product
Reflector
Provider severity
HIGH
Conflicts
0

CVE-2026-24947

Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through < 1.5.6.3.

PUBLISHED
Vendor
LA-Studio
Product
LA-Studio Element Kit for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24946

Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.8.0.

PUBLISHED
Vendor
tychesoftwares
Product
Print Invoice & Delivery Notes for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24945

Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for Contact Form 7: from n/a through <= 3.5.34.

PUBLISHED
Vendor
Themefic
Product
Ultimate Addons for Contact Form 7
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24944

Missing Authorization vulnerability in weDevs Subscribe2 subscribe2 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscribe2: from n/a through <= 10.44.

PUBLISHED
Vendor
weDevs
Product
Subscribe2
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24943

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Conference grandconference allows Reflected XSS.This issue affects Grand Conference: from n/a through <= 5.3.4.

PUBLISHED
Vendor
ThemeGoods
Product
Grand Conference
Provider severity
HIGH
Conflicts
0

CVE-2026-24942

Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam WpEvently mage-eventpress allows Cross Site Request Forgery.This issue affects WpEvently: from n/a through <= 5.1.1.

PUBLISHED
Vendor
magepeopleteam
Product
WpEvently
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24941

Missing Authorization vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Portal: from n/a through <= 2.4.4.

PUBLISHED
Vendor
wpjobportal
Product
WP Job Portal
Provider severity
HIGH
Conflicts
0