Filtered by vendor Wordpress Subscriptions
Filtered by product Wordpress Subscriptions
Total 15907 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-77785 2 Rank Math Seo, Wordpress 2 Rank Math Seo, Wordpress 2026-09-02 2.7 Low
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to read the specific post referenced in a request before returning its content and SEO metadata, allowing users with the Author role and above to read the title, body and metadata of other users' non-public posts.
CVE-2026-77782 2 Rank Math Seo, Wordpress 2 Rank Math Seo, Wordpress 2026-09-02 5.3 Medium
The Rank Math SEO WordPress plugin before 1.0.277.1 does not check whether a post is password protected before using its content to build publicly generated SEO metadata, allowing unauthenticated users to read the content of password-protected posts.
CVE-2026-77764 2 Gamipress, Wordpress 2 Gamipress, Wordpress 2026-09-02 4.3 Medium
The GamiPress WordPress plugin before 7.9.9.6 does not properly restrict its video watch-tracking functionality, allowing users with a role as low as Subscriber to award the configured gamification points, achievements and ranks to arbitrary users including administrators, and to accrue them without limit.
CVE-2026-24370 2 Theme-one, Wordpress 2 The Grid, Wordpress 2026-09-01 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeOne The Grid allows Stored XSS. This issue affects The Grid: from n/a through 2.8.0.
CVE-2026-13611 2 Kivicare, Wordpress 2 Kivicare, Wordpress 2026-09-01 5.3 Medium
The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient roster and, when a payment gateway is configured, the payment gateway secret key.
CVE-2026-74916 2 Wordpress, Wpfastestcache 2 Wordpress, Wp Fastest Cache 2026-09-01 6.5 Medium
The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have a page rendered under their own request context stored under, and served from, the clean URL's cache entry to every subsequent visitor.
CVE-2026-78363 2 Mw Wp Form Project, Wordpress 2 Mw Wp Form, Wordpress 2026-09-01 4.8 Medium
The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes in user-submitted values from being executed when it merges those values into a message that it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site. Exploitation requires the site to have been configured to echo a submitted value back to the visitor after submission.
CVE-2026-81280 2 Ukr Solution, Wordpress 2 Print Barcode Labels For Your Woocommerce Products/orders, Wordpress 2026-09-01 6.5 Medium
Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions.
CVE-2026-81768 2 Highwarden, Wordpress 2 Super Store Finder, Wordpress 2026-09-01 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
CVE-2026-81297 2 Wordpress, Wpmanageninja 2 Wordpress, Fluent Forms Pro Add On Pack 2026-09-01 7.5 High
Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
CVE-2026-81763 2 Wordpress, ウェブ屋のさとーさん 2 Wordpress, Throws Spam Away 2026-09-01 9.3 Critical
Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
CVE-2026-82225 2 Metagauss, Wordpress 2 Registrationmagic, Wordpress 2026-09-01 7.4 High
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.
CVE-2026-81758 2 Ownerrez, Wordpress 2 Ownerrez Api, Wordpress 2026-09-01 6.3 Medium
Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.
CVE-2026-81278 2 Wordpress, Wpexperts 2 Wordpress, Post Smtp 2026-09-01 5.4 Medium
Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post SMTP: from 4.0.0 through beta.1.
CVE-2026-81287 2 Syed Balkhi, Wordpress 2 Charitable, Wordpress 2026-09-01 8.5 High
Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.
CVE-2026-81293 2 Passionate Programmer Peter, Wordpress 2 Wp Data Access, Wordpress 2026-09-01 9.3 Critical
Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.
CVE-2026-81780 2 Hashthemes, Wordpress 2 Hash Form, Wordpress 2026-09-01 10 Critical
Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
CVE-2026-82228 2 Siteground, Wordpress 2 Siteground Security, Wordpress 2026-09-01 8.1 High
Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.
CVE-2026-77194 2 Wordpress, Wpinsider-1 2 Wordpress, Simple Membership 2026-09-01 5.3 Medium
The Simple Membership plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in versions up to, and including, 4.8.0. This is due to improper identity verification during the public registration flow in WordPress Multisite environments, where the plugin binds new Simple Membership records to existing global WordPress users based solely on matching username and email, without requiring password verification or ownership proof, and fails to properly detect Administrator roles on child sites. This makes it possible for unauthenticated attackers to take over Administrator accounts on child sites in a Multisite network by registering a Simple Membership account with a victim's credentials on a site where public registration is enabled, then updating the victim's global WordPress password through the profile edit functionality. The vulnerability was partially patched in version 4.8.1.
CVE-2026-17589 2 Levelfourstorefront, Wordpress 2 Shopping Cart \& Ecommerce Store, Wordpress 2026-09-01 4.9 Medium
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order' parameter in all versions up to, and including, 5.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order SQL injection: the payload is written to the ec_pageoption table via the ec_ajax_save_page_options handler — which applies no sanitization to raw $_POST values — and is later retrieved with stripslashes() (bypassing WordPress magic-quotes protection) before being concatenated directly into SQL on every store page render.