| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Sep 19, 2026, 09:09:16 | ||||
|
vulnerable
|
Sep 19, 2026, 14:09:09 |
Min -
Max 2.5.4
|
Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions. | |
|
vulnerable
|
Sep 19, 2026, 14:09:09 |
Min -
Max 2.5.2
|
The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1. This is due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query in the WPIMItem::get_all() function — parse_custom_where() only performs html_entity_decode(), strips semicolons, and does field-label name replacements, without using $wpdb->prepare() or a whitelis... | |
|
Printcart Web to Print Product Designer for WooCommerce
vulnerable
|
Sep 19, 2026, 14:09:06 |
Min -
Max 2.8.6
|
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. A valid nonce is obtainable by unauthenticated users via the companion nbd_check_use_logged_in nopriv AJAX endpoint, which freely mints and returns a nbdesigner-get-data no... | |
|
vulnerable
|
Sep 19, 2026, 13:09:59 |
Min -
Max 1.24.0
|
The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function. This is due to the function performing no nonce verification, no capability check, and no allowlist validation on the meta key supplied via the `acf-photo-gallery-groups` POST parameter before passing both the meta key and its corresponding value directly to `update_user_meta()`. This makes it possible for authenticated attackers, with Subsc... | |
|
vulnerable
|
Sep 19, 2026, 13:09:43 |
Min -
Max 1.4.2
|
TikTok [tiktok-for-business] < 1.4.2 CVE-2026-18346 | |
|
vulnerable
|
Sep 19, 2026, 13:09:42 |
Min -
Max 4.6.6
|
The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'unique' parameter in all versions up to, and including, 4.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This... | |
|
Robokassa payment gateway for Woocommerce
vulnerable
|
Sep 19, 2026, 13:09:30 |
Min -
Max 1.8.9
|
The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature. | |
|
WordPress Filter Gallery Plugin
vulnerable
|
Sep 19, 2026, 12:09:56 |
Min -
Max 1.1.5
|
The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete any arbitrary Filter Gallery records — including all associated filters, image mappings, settings, and details options — by supplying attacker-controlled gallery IDs. The nonce bypass requir... | |
|
WordPress Filter Gallery Plugin
vulnerable
|
Sep 19, 2026, 12:09:56 |
Min -
Max 1.1.5
|
The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the title and content of arbitrary WordPress posts, write the _wp_attachment_image_alt meta key on arbitrary posts, and create or overwrite arbitrary ufg_gallery_* options. | |
|
wpShopGermany IT-RECHT KANZLEI
vulnerable
|
Sep 19, 2026, 11:09:40 |
Min -
Max 2.4
|
The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating it as a side effect of the check that is supposed to validate it, allowing unauthenticated attackers to predict the token and use the access it grants to write arbitrary files, leading to remote code execution. | |