Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-12144

The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User::add_role()`, with no allowlist validation against permitted wholesale roles and no capability check such as `current_user_can('promote_users')` or `current_user_can('manage_options')`. This makes it

PUBLISHED
Vendor
saadiqbal
Product
Wholesale for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-12143

form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the atta

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, form-data, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift GitOps, Red Hat Enterprise Linux 9, Red Hat OpenShift Service Mesh 3.1, Red Hat Quay 3.1, Red Hat Enterprise Linux 10, Cluster Observability Operator 1.5.0, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 8, form-data, Red Hat OpenShift Service Mesh 3.0, Red Hat AMQ Broker 7, Red Hat OpenShift Service Mesh 3.3, Cluster Observability Operator 1.5.0, Red Hat 3scale API Management Platform 2, Red Hat Ansible Automation Platform 2, Red Hat JBoss Enterprise Application Platform 7, OpenShift Pipelines, Self-service automation portal 2, Red Hat Developer Hub 1.9, OpenShift Pipelines, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Enterprise Linux 8, Red Hat Data Grid 8.6.2, Migration Toolkit for Applications 8, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Hardened Images, OpenShift Service Mesh 3, Red Hat Quay 3.16, Node HealthCheck Operator, Cluster Observability Operator 1.5.0, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Container Platform 4.2, Red Hat OpenShift Container Platform 4, Red Hat Build of Podman Desktop - Tech Preview, Red Hat Hardened Images, Red Hat Enterprise Linux 8, Cluster Observability Operator 1.5.0, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Network Observability Operator, Red Hat Ansible Automation Platform 2, Red Hat JBoss Enterprise Application Platform Expansion Pack, Cluster Observability Operator 1.5.0, Red Hat Migration Toolkit 1.8, Cluster Observability Operator 1.5.0, Red Hat OpenShift Service Mesh 3.2, Cryostat 4 on RHEL 9, Red Hat build of Apicurio Registry 3, Red Hat Discovery 2, Red Hat Enterprise Linux 9, Red Hat Build of Podman Desktop - Tech Preview, Red Hat OpenShift Service Mesh 2.6, OpenShift Pipelines, Self-service automation portal 2, Red Hat Enterprise Linux 9, Red Hat OpenShift Service Mesh 3.0, Network Observability Operator, Cluster Observability Operator 1.5.0, Red Hat Quay 3.15, Red Hat build of Apache Camel - HawtIO 4, Cluster Observability Operator 1.5.0, OpenShift Pipelines, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6, Red Hat Enterprise Linux AI (RHEL AI) 3, Node HealthCheck Operator, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 10, Network Observability Operator, Red Hat OpenShift GitOps, Red Hat 3scale API Management Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 8, Red Hat Trusted Artifact Signer, Red Hat Enterprise Linux 8, Red Hat JBoss Enterprise Application Platform 8, Red Hat Openshift Data Foundation 4, Red Hat Ansible Automation Platform 2, Multicluster Engine for Kubernetes, Red Hat OpenShift AI (RHOAI), Node HealthCheck Operator, Red Hat OpenShift AI (RHOAI), Red Hat Developer Hub 1.10, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Spaces 3.29, Red Hat Enterprise Linux 7, Red Hat Quay 3.12, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), Red Hat Build of Podman Desktop - Tech Preview, Red Hat Advanced Cluster Security for Kubernetes 4.10, Node HealthCheck Operator, Red Hat 3scale API Management Platform 2, Cluster Observability Operator 1.5.0, Red Hat OpenShift Container Platform 4, Cryostat 4, OpenShift Pipelines, Red Hat Enterprise Linux 9, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Service Mesh 2.6, Red Hat Satellite 6, Red Hat OpenShift Container Platform 4.21, Red Hat OpenShift Service Mesh 3.3, Red Hat Quay 3.9, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Service Mesh 3.1, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Service Mesh 3.2, Cluster Observability Operator 1.5.0, Red Hat build of Apicurio Registry 3, Red Hat Build of Podman Desktop, Migration Toolkit for Applications 8, Cluster Observability Operator 1.5.0, Red Hat Advanced Cluster Security 4.9, Red Hat Satellite 6, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 8, OpenShift Service Mesh 3, Red Hat Ansible Automation Platform 2, Cluster Observability Operator 1.5.0, Red Hat Satellite 6, Red Hat OpenShift AI (RHOAI), Cryostat 4, Red Hat Fuse 7, Red Hat 3scale API Management Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Trusted Profile Analyzer, Red Hat OpenShift Dev Spaces 3.29
Provider severity
HIGH
Conflicts
3

CVE-2026-12142

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '_name[]' Array Parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The wp_kses() output filtering pass provides no mitigation because NEXForms_allowed_tags() ex

PUBLISHED
Vendor
webaways
Product
NEX-Forms – Ultimate Forms Plugin for WordPress
Provider severity
HIGH
Conflicts
0

CVE-2026-12141

The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_tooltip_text' parameter in all versions up to, and including, 4.11.84 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected paylo

PUBLISHED
Vendor
leap13
Product
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12139

Tanium addressed an information disclosure vulnerability in Connect.

PUBLISHED
Vendor
Tanium
Product
Connect
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12137

The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 4.3.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Because

PUBLISHED
Vendor
phppoet
Product
SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12136

The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysbasics_user_avatar' shortcode in versions up to, and including, 4.3.6. This is due to insufficient input sanitization and output escaping on user supplied attributes (min_height, min_width, max_height, max_width) in the wcmamtx_get_avatar_default() function, which are concatenated unescaped into the get_avatar() extra_attr style attribute. This makes it possible for authenticate

PUBLISHED
Vendor
phppoet
Product
SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12135

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute in all versions up to, and including, 7.5.51.7212 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
foliovision
Product
FV Flowplayer Video Player
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12134

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.7.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary season groups or modify existing group names, participants, and round-type options. Exploitation requires obtaining the

PUBLISHED
Vendor
beardev
Product
JoomSport – for Sports: Team & League, Football, Hockey & more
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12133

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Group Deletion in versions up to, and including, 5.7.8. This is due to a missing capability check in the joomsport_season_groupdel() AJAX handler, which only verifies a nonce before executing a DELETE query on attacker-supplied group IDs. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary JoomSport

PUBLISHED
Vendor
beardev
Product
JoomSport – for Sports: Team & League, Football, Hockey & more
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12131

A weakness has been identified in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function Invoice of the file \application\controllers\Payroll.php of the component Payroll Invoice Module. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
CodeAstro
Product
Human Resource Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-12130

A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of the file /Projects/Add_Projects of the component Projects Management Page. The manipulation of the argument protitle results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

PUBLISHED
Vendor
CodeAstro
Product
Human Resource Management System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-1213

All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modify the profile picture of other application users.This issue affects askbot: 0.12.2.

PUBLISHED
Vendor
askbot
Product
askbot
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12129

A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/add_tod of the component Dashboard Interface. The manipulation of the argument todo_data leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
CodeAstro
Product
Human Resource Management System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-12127

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 1.10.2 This is due to `get_reply_to_address()` processing the Reply-To display name through smart-tag expansion with context `'notification'` instead of `'notification-reply-to'`, which bypasses email-address validation while `wpforms_sanitize_textarea_field()` intenti

PUBLISHED
Vendor
smub
Product
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12126

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'post_title' in all versions up to, and including, 3.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Vendor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. An attacker can plant the payload by uploading a

PUBLISHED
Vendor
wclovers
Product
WCFM Marketplace – Multivendor Marketplace for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12124

The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the serveTemplatePdfAjax() function and the serveTemplatePdf() REST route (which is registered with `permission_callback => '__return_true'`) in versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to download stored template PDFs — which may contain cus

PUBLISHED
Vendor
wpeverest
Product
PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12123

The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.8.5 via the 'vdl' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. A Subscriber-level attacker can plant an internal or loopback URL in the `mp4` post meta of

PUBLISHED
Vendor
plugins360
Product
All-in-One Video Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12122

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.11 via the get_single_symbol. This makes it possible for unauthenticated attackers to extract the full builder metadata and rendered HTML of any kirki_symbol post — including unpublished drafts — by supplying a sequential WordPress post ID.

PUBLISHED
Vendor
themeum
Product
Kirki – Freeform Page Builder, Website Builder & Customizer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12120

The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.7 via the 'form_id' parameter. This makes it possible for unauthenticated attackers to extract download a full CSV export of all form submissions — including any personally identifiable information submitted by users — for any arbitrary form_id.

PUBLISHED
Vendor
fireplugins
Product
FireBox Popups – Increase Sales and Grow Your Email List
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12119

The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization check on the 'frontmanage' shortcode attribute in all versions up to, and including, 6.3.7. This makes it possible for authenticated attackers, with contributor-level access and above, to perform arbitrary file operations including deletion, move, folder creation, and download. An attacker can create a draft post containing the 'eeSFL' shortcode, render it via the post preview e

PUBLISHED
Vendor
eemitch
Product
Simple File List
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12118

IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

PUBLISHED
Vendor
IBM
Product
webMethods Integration (on prem)
Provider severity
CRITICAL
Conflicts
0

CVE-2026-12117

Improper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated vault member to enumerate social login entry metadata to which they are not authorized via a crafted API request.

PUBLISHED
Vendor
Devolutions
Product
Devolutions Server
Provider severity
MEDIUM
Conflicts
1

CVE-2026-12116

A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.

PUBLISHED
Vendor
Xerte, Xerte
Product
Xerte Online Tools, Xerte Online Tools
Provider severity
CRITICAL
Conflicts
1

CVE-2026-12115

The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is ins

PUBLISHED
Vendor
wpcalc
Product
Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12114

The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installa

PUBLISHED
Vendor
wpmart
Product
Team Members – Multi Language Supported Team Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12113

The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, with contributor-level access and above, to extract customer names, email addresses, phone numbers, appointment comments, and other booking personally identifiable information.

PUBLISHED
Vendor
codepeople
Product
Appointment Booking Calendar
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12112

A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of authenticated client connections, by trusting a non-secret session ID without re-validating authentication tokens and by logging all newly created session IDs to standard logs. This issue can result in privilege escalation and infrastructure-wide code execution.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Satellite 6.19, Red Hat Satellite 6.18, Red Hat Satellite 6.19, Red Hat Satellite 6.18
Provider severity
HIGH
Conflicts
1

CVE-2026-12111

The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.4.01. This is due to insufficient authorization and missing per-calendar ownership checks in the cpabc_appointments_calendar_load2() function, which is reachable via the cpabc_calendar_load2=1 query parameter in wp-admin and only checks is_admin() && current_user_can('edit_posts'), a capability available to Contributor-level users and above. This makes it poss

PUBLISHED
Vendor
codepeople
Product
Appointment Booking Calendar
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12110

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'task_search' parameter in all versions up to, and including, 5.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can

PUBLISHED
Vendor
taskbuilder
Product
Taskbuilder – Project Management & Task Management Tool With Kanban Board
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12108

The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_htm

PUBLISHED
Vendor
looswebstudio
Product
Highlighting Code Block
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12105

Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions.

PUBLISHED
Vendor
Devolutions
Product
Devolutions Server
Provider severity
MEDIUM
Conflicts
1

CVE-2026-12104

OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.7.5 on Linux allows an authenticated attacker with configuration write access to execute arbitrary operating-system commands via crafted configuration values passed to server-side scripts.

PUBLISHED
Vendor
SIMA GmbH
Product
Bondix Server
Provider severity
HIGH
Conflicts
0

CVE-2026-12103

The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to enumerate the login name, email address, and user ID of all WordPress accounts — including administrators — by submitting arbitrary search terms to the AJAX handler. The require

PUBLISHED
Vendor
subratamal
Product
Wallet for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12102

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the 'user_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with editor-level access and above, to reset and permanently delete the avatar or banner image of any arbitrary user, including administrators, by cle

PUBLISHED
Vendor
stiofansisland
Product
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
Provider severity
LOW
Conflicts
0

CVE-2026-12100

The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0 via the 'url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PUBLISHED
Vendor
abhisheksaha11
Product
URL Preview
Provider severity
HIGH
Conflicts
0

CVE-2026-1210

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_elementor_data' meta field in all versions up to, and including, 3.20.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
thehappymonster
Product
Happy Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12098

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed' Episode Meta Field in all versions up to, and including, 11.16.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The embed value is stored via update_post_meta() rather than th

PUBLISHED
Vendor
blubrry
Product
PowerPress Podcasting plugin by Blubrry
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12097

The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the plugin's export field configuration stored in the uiewp_export_field option, controlling which user fields such as password hashes are included in CSV exports and how columns are mapped during imports.

PUBLISHED
Vendor
saadiqbal
Product
User Management
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12095

The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2 via the 'api_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. The script echoes internal API response data (specifically the value of any 'auth' key in a JSON response body) verbatim back to the attacker

PUBLISHED
Vendor
bytuncay
Product
Kargo Takip
Provider severity
HIGH
Conflicts
0

CVE-2026-12094

The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the cf7cdb_ajax_delete_user() function in versions up to, and including, 1.0.0. The handler is registered against both `wp_ajax_cf7cdb_delete` and `wp_ajax_nopriv_cf7cdb_delete`, and it performs no nonce verification, no capability check, and no ownership check before invoking `$wpdb->delete()` against the `wp_cf7cdb_data` table with an attacker-suppli

PUBLISHED
Vendor
iamranit
Product
Advanced Contact Form 7 – Compact DB
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12093

The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to deactivate arbitrary member accounts by forging a charge.refunded webhook event containing a victim's subscription ID, setting the target member's account_state to 'inactive' and triggering cancellation hooks, transaction

PUBLISHED
Vendor
wpinsider-1
Product
Simple Membership
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12090

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'wppm_proj_filter' parameter in all versions up to, and including, 5.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that

PUBLISHED
Vendor
taskbuilder
Product
Taskbuilder – Project Management & Task Management Tool With Kanban Board
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12089

The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 3.3.19. This is due to the combine_current_css() function trusting <link rel="stylesheet" href="..."> values harvested from page HTML and converting same-site URLs to absolute filesystem paths before reading them with file_get_contents()/Minify\CSS::add(), without enforcing that the resolved path stay within ABSPATH or have a .css extension. This

PUBLISHED
Vendor
aurelienlws
Product
LWS Optimize – All-in-One Speed Booster & Cache Tools
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12087

Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is

PUBLISHED
Vendor
PEVANS
Product
Socket
Provider severity
CRITICAL
Conflicts
1

CVE-2026-12086

IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy stores potentially sensitive information in log files that could be read by a local user.

PUBLISHED
Vendor
IBM, IBM
Product
UCD - IBM DevOps Deploy, UCD - IBM UrbanCode Deploy
Provider severity
MEDIUM
Conflicts
1

CVE-2026-12085

IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.

PUBLISHED
Vendor
IBM, IBM
Product
UCD - IBM UrbanCode Deploy, UCD - IBM DevOps Deploy
Provider severity
MEDIUM
Conflicts
1

CVE-2026-12084

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.

PUBLISHED
Vendor
IBM
Product
UCD - IBM DevOps Deploy
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12083

The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before 8.8.4 does not perform authentication, authorization, or nonce checks on a role-restoration request handler, allowing unauthenticated attackers to restore a previously demoted administrator account back to the administrator role. This is an incomplete fix of CVE-2024-43333 / CVE-2025-24648, which closed the issue for only one of the demotion paths the WordPress role API expose

PUBLISHED
Vendor
Unknown, Unknown
Product
admin-site-enhancements-pro, Admin and Site Enhancements (ASE)
Provider severity
HIGH
Conflicts
1

CVE-2026-12082

The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.

PUBLISHED
Vendor
Unknown
Product
Praison AI SEO
Provider severity
HIGH
Conflicts
1