5.3

CVSS3.1

CVE-2026-1938 - YayMail <= 4.3.2 - Missing Authorization to Authenticated (Shop Manager+) License Key Deletion via …

The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized license key deletion due to a missing authorization check on the `/yaymail-license/v1/license/delete` REST endpoint in versions up to, and including, 4.3.2. This makes it possible for authenticated attacke…

📅 Published: Feb. 18, 2026, 7:25 a.m. 🔄 Last Modified: April 8, 2026, 4:59 p.m.

4.3

CVSS3.1

CVE-2026-1655 - EventPrime <= 4.2.8.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Event Modifi…

The EventPrime plugin for WordPress is vulnerable to unauthorized post modification due to missing authorization checks in all versions up to, and including, 4.2.8.4. This is due to the save_frontend_event_submission function accepting a user-controlled event_id parameter and updating the correspon…

📅 Published: Feb. 18, 2026, 7:25 a.m. 🔄 Last Modified: April 8, 2026, 4:35 p.m.

2.7

CVSS3.1

CVE-2026-2419 - WP-DownloadManager <= 1.69 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read v…

The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'download_path' configuration parameter. This is due to insufficient validation of the download path setting, which allows directory traversal sequences to bypass the WP_CO…

📅 Published: Feb. 18, 2026, 7:25 a.m. 🔄 Last Modified: April 8, 2026, 4:34 p.m.

4.8

CVSS4.0

CVE-2026-2644 - niklasso minisat DIMACS File SolverTypes.h value out-of-bounds

A weakness has been identified in niklasso minisat up to 2.2.0. This issue affects the function Solver::value in the library core/SolverTypes.h of the component DIMACS File Parser. This manipulation of the argument variable index with the input 2147483648 causes out-of-bounds read. The attack needs…

📅 Published: Feb. 18, 2026, 7:02 a.m. 🔄 Last Modified: Feb. 23, 2026, 10:17 a.m.

7.2

CVSS3.1

CVE-2026-2296 - Product Addons for Woocommerce – Product Options with Custom Fields <= 3.1.0 - Authenticated (Shop …

The Product Addons for Woocommerce – Product Options with Custom Fields plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 3.1.0. This is due to insufficient input validation of the 'operator' field in conditional logic rules within the evalConditions() funct…

📅 Published: Feb. 18, 2026, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 5:16 p.m.

4.3

CVSS3.1

CVE-2026-2633 - Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Missing Authorization to Authenticated (Contribut…

The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.6.1. This is due to a missing capability check in the `process_image_data_ajax_callback()` function which handles the `kadence_import_process_image_data` AJ…

📅 Published: Feb. 18, 2026, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 5:11 p.m.

4.4

CVSS3.1

CVE-2026-2281 - Private Comment <= 0.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via Label Tex…

The Private Comment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Label text' setting in all versions up to, and including, 0.0.4. This is due to insufficient input sanitization and output escaping on the plugin's label text option. This makes it possible for authentica…

📅 Published: Feb. 18, 2026, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 5:09 p.m.

4.3

CVSS3.1

CVE-2026-1640 - Taskbuilder <= 5.0.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Project/Task …

The Taskbuilder – WordPress Project Management & Task Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.0.2. This is due to missing authorization checks on the project and task comment submission functions (AJAX actions: wppm_submit_proj_c…

📅 Published: Feb. 18, 2026, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 4:57 p.m.

6.4

CVSS3.1

CVE-2026-1807 - InteractiveCalculator for WordPress <= 1.0.3 - Authenticated (Contributor+) Stored Cross-Site Scrip…

The InteractiveCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'interactivecalculator' shortcode in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

📅 Published: Feb. 18, 2026, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 4:55 p.m.

7.2

CVSS3.1

CVE-2026-1937 - YayMail <= 4.3.2 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Options Update …

The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the `yaymail_import_state` AJAX action in all versions up to, and including, 4.3.2. This makes it possible fo…

📅 Published: Feb. 18, 2026, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 6:25 p.m.
Total resulsts: 343935
Page 1073 of 34,394
« previous page » next page
Filters