4.3

CVSS3.1

CVE-2026-3903 - Modular Connector <= 2.5.1 - Cross-Site Request Forgery via postConfirmOauth

The Modular DS: Monitor, update, and backup multiple websites plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.1. This is due to missing nonce validation on the postConfirmOauth() function. This makes it possible for unauthenticated attacker…

📅 Published: March 11, 2026, 7:36 a.m. 🔄 Last Modified: April 22, 2026, 9:27 p.m.

7.5

CVSS3.1

CVE-2026-1708 - Appointment Booking Calendar <= 1.6.9.27 - Unauthenticated SQL Injection via 'append_where_sql' Par…

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection in all versions up to, and including, 1.6.9.27. This is due to the `db_where_conditions` method in the `TD_DB_Model` class failing to prevent the `append_where_sq…

📅 Published: March 11, 2026, 7:36 a.m. 🔄 Last Modified: April 22, 2026, 9:27 p.m.

6.4

CVSS3.1

CVE-2026-2918 - Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contribut…

The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_condition_update` AJAX action. This is due to the `validate_reqeust()` method using `current_user_can('edit_posts', $template_id)` instead o…

📅 Published: March 11, 2026, 7:36 a.m. 🔄 Last Modified: April 22, 2026, 9:27 p.m.

6.4

CVSS3.1

CVE-2026-3534 - Astra <= 4.12.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta

The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-content-background-meta` post meta fields in all versions up to, and including, 4.12.3. This is due to insufficient input sanitization on meta registration and missing output escap…

📅 Published: March 11, 2026, 6:45 a.m. 🔄 Last Modified: April 22, 2026, 9:27 p.m.

9.3

CVSS4.0

CVE-2026-3826 - WellChoose|IFTOP - Local File Inclusion

IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.

📅 Published: March 11, 2026, 6:38 a.m. 🔄 Last Modified: March 20, 2026, 2:37 p.m.

5.1

CVSS4.0

CVE-2026-3825 - WellChoose|IFTOP - Reflected Cross-site Scripting

IFTOP developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

📅 Published: March 11, 2026, 6:35 a.m. 🔄 Last Modified: March 20, 2026, 2:37 p.m.

8.7

CVSS4.0

CVE-2026-31844 - Authenticated SQL Injection in Koha displayby parameter of suggestion.pl

An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functionality. A low-privileged staff user can inject arbitrary SQL que…

📅 Published: March 11, 2026, 6:34 a.m. 🔄 Last Modified: May 7, 2026, 6:27 p.m.

5.1

CVSS4.0

CVE-2026-3824 - WellChoose|IFTOP - Open redirect

IFTOP developed by WellChoose has an Open redirect vulnerability, allowing authenticated remote attackers to craft a URL that tricks users into visiting malicious website.

📅 Published: March 11, 2026, 6:31 a.m. 🔄 Last Modified: March 20, 2026, 2:37 p.m.

9.8

CVSS3.1

CVE-2026-2631 - Datalogics Ecommerce Delivery < 2.6.60 - Unauthenticated Privilege Escalation

The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_token` without verification. This token is subsequently used for authentication in a protected endpoint that allows users to perfor…

📅 Published: March 11, 2026, 6 a.m. 🔄 Last Modified: April 15, 2026, 3:05 p.m.

8.1

CVSS3.1

CVE-2026-2626 - Divi Booster < 5.0.2 - Unauthenticated PHP Object Injection

The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated users to modify stored divi-booster WordPress plugin before 5.0.2 options. Furthermore, due to the use of unserialize() on the data, this could be furth…

📅 Published: March 11, 2026, 6 a.m. 🔄 Last Modified: April 15, 2026, 3:05 p.m.
Total resulsts: 349182
Page 1186 of 34,919
« previous page » next page
Filters