| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Sep 07, 2026, 02:09:58 | ||||
|
MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution
vulnerable
|
Sep 06, 2026, 19:09:09 |
Min -
Max 2.1.70
|
Missing Authorization vulnerability in Kings Plugins MarketKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MarketKing: from n/a through 2.1.60. | |
|
vulnerable
|
Sep 06, 2026, 18:09:16 |
Min -
Max 2.3.33
|
The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress, granted no other security controls are present in the function. | |
|
vulnerable
|
Sep 06, 2026, 17:09:30 |
Min -
Max 1.10.3
|
The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. An unauthenticated attacker can first call the 'updateNonce' action — which is accessible without authentication due to its absence fr... | |
|
Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab
vulnerable
|
Sep 06, 2026, 17:09:16 |
Min -
Max 2.0.5
|
The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before pricing a booking, allowing unauthenticated attackers to manipulate the order total down to zero and place real taxi-booking orders at an arbitrary price. | |
|
vulnerable
|
Sep 06, 2026, 14:09:49 |
Min -
Max 8.4.7
|
The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature. | |
|
vulnerable
|
Sep 06, 2026, 13:09:36 |
Min -
Max 4.21.1
|
The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but never calls openssl_verify() or any equivalent to validate the JWT signature against Google's actual public key certificates. This makes it possible for unauthenticated attackers to ... | |
|
vulnerable
|
Sep 06, 2026, 12:09:45 |
Min -
Max 7.16.1
|
The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to permanently force-delete arbitrary posts of any post type (including pages, administrator-authored posts, and WooCommerce products) and write arbitrary ccf_field_* post meta onto any post reg... | |
|
Directorist – WordPress Business Directory Plugin with Classified Ads Listings
vulnerable
|
Sep 06, 2026, 12:09:15 |
Min -
Max 8.9
|
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above to overwrite image metadata on posts belonging to other users. | |
|
Restaurant Menu and Food Ordering
vulnerable
|
Sep 06, 2026, 11:09:43 |
Min -
Max 2.4.12
|
The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification genuinely originates from PayPal, allowing unauthenticated attackers to forge a payment notification and mark their own order as paid and completed without making any payment. | |
|
vulnerable
|
Sep 06, 2026, 11:09:10 |
Min -
Max 2.12.2
|
The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callback (usces_action_acting_transaction). Unauthenticated attackers can store arbitrary 'reserve' key/value pairs as order metadata during a public checkout, then invoke the callback with an attacker-chosen 'option' parameter to select and unserialize that metadata without any provider signature, source-address, tra... | |