| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Aug 23, 2026, 00:08:44 | ||||
|
myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin
vulnerable
|
Aug 23, 2026, 05:08:09 |
Min -
Max 3.2.5
|
The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification matches the site's configured merchant account, allowing unauthenticated attackers to have arbitrary amounts of the site's in-site currency credited to an account by completing a payment for the expected amount to a gateway account they control rather than the site's. | |
|
vulnerable
|
Aug 23, 2026, 01:08:58 |
Min -
Max 4.17.1
|
The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before rendering them on public pages, allowing unauthenticated attackers to store shortcodes that are then executed when the page is viewed, disclosing a chosen user's email address, login and registration date. | |
|
Advanced Product Fields (Product Addons) for WooCommerce
vulnerable
|
Aug 23, 2026, 01:08:37 |
Min -
Max 1.6.22
|
The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid addons and complete purchases at the base product price only, effectively stealing products by paying a fraction of the intended total. The vulnerability was partially patched in version 1.6.19. | |
|
vulnerable
|
Aug 22, 2026, 23:08:52 |
Min -
Max 5.0.14
|
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some of its admin REST API routes, checking only for a WooCommerce management capability instead of the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14-installation capability, allowing users such as Shop Managers to install and activate arbitrary Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPres... | |
|
vulnerable
|
Aug 22, 2026, 23:08:52 |
Min -
Max 5.0.14
|
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vendor's actual outstanding balance when recording a reverse-withdrawal payment, allowing a vendor to credit their reverse-withdrawal ledger with an arbitrary amount and clear their real commission debt without paying. | |
|
vulnerable
|
Aug 22, 2026, 23:08:52 |
Min -
Max 5.0.14
|
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission configuration returned by one of its unauthenticated store REST endpoints, allowing any unauthenticated user to disclose a vendor's commission type and, when category-based commission is configured, the per-category and default commission rates. | |
|
vulnerable
|
Aug 22, 2026, 23:08:52 |
Min -
Max 3.6.1
|
The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing privileged user management operations, allowing users with the Administrator role on a Multisite sub-site to take over any account on the network, including the Network Administrator's. | |
|
Greenshift – animation and page builder blocks
vulnerable
|
Aug 22, 2026, 23:08:22 |
Min -
Max 12.9.0
|
The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 12.8.9. This is due to a missing capability check on the 'gspb_update_global_wp_settings' function that only verifies the 'edit_posts' capability instead of requiring administrative privileges. This makes it possible for authenticated attackers, with contributor-level access and above, to modify global WordPress theme color settings site-wide, leading t... | |
|
vulnerable
|
Aug 22, 2026, 22:08:59 |
Min -
Max 1.5.6
|
The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role to republish another user's password-protected post as publicly readable. | |
|
vulnerable
|
Aug 22, 2026, 22:08:59 |
Min -
Max 1.5.6
|
The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft content. | |