| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Jul 27, 2026, 01:07:24 | ||||
|
Classified Listing – Classified ads & Business Directory Plugin
vulnerable
|
Jul 24, 2026, 01:07:03 |
Min -
Max 5.3.9
|
The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order. | |
|
vulnerable
|
Jul 23, 2026, 23:07:52 |
Min -
Max 8.2.0
|
The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-generation settings handlers, allowing authenticated users with subscriber-level access to modify the WPBot WordPress plugin before 8.2.0's configuration. | |
|
Academy LMS – eLearning and online course solution for WordPress
vulnerable
|
Jul 23, 2026, 23:07:24 |
Min -
Max 3.8.1
|
The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated users with subscriber-level access to read and modify other users' lesson notes and mark other users' lesson content as completed. | |
|
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting
vulnerable
|
Jul 23, 2026, 19:07:46 |
Min -
Max 1.17.6
|
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions. | |
|
vulnerable
|
Jul 23, 2026, 12:07:03 |
Min -
Max 4.0.0
|
The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Tutor LMS and Elementor plugins without proper authorization. | |
|
WordPress Online Booking and Scheduling Plugin – Bookly
vulnerable
|
Jul 23, 2026, 06:07:37 |
Min -
Max 27.8
|
Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.8 CVE-2026-61944 | |
|
WordPress Online Booking and Scheduling Plugin – Bookly
vulnerable
|
Jul 23, 2026, 06:07:37 |
Min -
Max 27.8
|
Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.8 CVE-2026-61949 | |
|
WP Travel – Best Travel Booking WordPress Plugin, Tour Management Engine
vulnerable
|
Jul 23, 2026, 05:07:19 |
Min -
Max 11.7.1
|
The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site. | |
|
vulnerable
|
Jul 23, 2026, 05:07:06 |
Min -
Max 8.2.2
|
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders. | |
|
vulnerable
|
Jul 23, 2026, 05:07:06 |
Min -
Max 8.2.2
|
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some configurations, to modify order statuses. | |