7.2

CVSS3.1

CVE-2026-3231 - Checkout Field Editor (Checkout Manager) for WooCommerce <= 2.1.7 - Unauthenticated Stored Cross-Si…

The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom radio and checkboxgroup field values submitted through the WooCommerce Block Checkout Store API in all versions up to, and including, 2.1.7. This is due to the `…

📅 Published: March 11, 2026, 9:25 a.m. 🔄 Last Modified: April 22, 2026, 9:27 p.m.

4.3

CVSS3.1

CVE-2026-3906 - WordPress 6.9 - 6.9.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Note Creatio…

WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collaboration annotations) was introduced in WordPress 6.9 to allow editorial comments directly on posts in the block editor. However, the REST API `create_item_permissions_check()` met…

📅 Published: March 11, 2026, 9:25 a.m. 🔄 Last Modified: April 22, 2026, 9:27 p.m.

6.4

CVSS3.1

CVE-2026-3492 - Gravity Forms <= 2.9.28.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.28.1. This is due to a compound failure involving missing authorization on the `create_from_template` AJAX endpoint (allowing any authenticated user to create forms), insuff…

📅 Published: March 11, 2026, 9:25 a.m. 🔄 Last Modified: April 22, 2026, 9:27 p.m.

8.8

CVSS3.1

CVE-2026-1992 - ExactMetrics 8.6.0 - 9.0.2 - Authenticated (Custom) Insecure Direct Object Reference to Arbitrary P…

The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in versions 8.6.0 through 9.0.2. This is due to the `store_settings()` method in the `ExactMetrics_Onboarding` class accepting a user-supplied `triggered_by` parameter that is used i…

📅 Published: March 11, 2026, 9:25 a.m. 🔄 Last Modified: April 22, 2026, 9:27 p.m.

8.8

CVSS3.1

CVE-2026-1993 - ExactMetrics 7.1.0 - 9.0.2 - Authenticated (Custom) Improper Privilege Management to Role Privilege…

The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in versions 7.1.0 through 9.0.2. This is due to the `update_settings()` function accepting arbitrary plugin setting names without a whitelist of allowed settings. This makes it possible…

📅 Published: March 11, 2026, 9:25 a.m. 🔄 Last Modified: April 22, 2026, 9:27 p.m.

7.2

CVSS3.1

CVE-2026-1454 - Responsive Contact Form Builder & Lead Generation Plugin <= 2.0.1 - Unauthenticated Stored Cross-Si…

The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.1 via form field submissions. This is due to insufficient input sanitization in the lfb_lead_sanitize() function which omits certa…

📅 Published: March 11, 2026, 8:24 a.m. 🔄 Last Modified: April 22, 2026, 9:27 p.m.

2

CVSS4.0

CVE-2024-14026 - QTS, QuTS hero

A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the…

📅 Published: March 11, 2026, 8:02 a.m. 🔄 Last Modified: March 20, 2026, 2:37 p.m.

0.1

CVSS4.0

CVE-2024-14025 - Video Station

An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the follow…

📅 Published: March 11, 2026, 8:02 a.m. 🔄 Last Modified: March 20, 2026, 2:37 p.m.

0.1

CVSS4.0

CVE-2024-14024 - Video Station

An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerabi…

📅 Published: March 11, 2026, 8:02 a.m. 🔄 Last Modified: March 20, 2026, 2:37 p.m.

5.4

CVSS3.1

CVE-2026-2917 - Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contribut…

The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_duplicate_thing` admin action handler. This is due to the `can_clone()` method only checking `current_user_can('edit_posts')` (a general cap…

📅 Published: March 11, 2026, 7:36 a.m. 🔄 Last Modified: April 22, 2026, 9:27 p.m.
Total resulsts: 349182
Page 1185 of 34,919
« previous page » next page
Filters