Vulnerabilities in Unknown

5,639 results
CVE-2025-6790MEDIUMQSM < 10.2.3 - Template Creation via CSRFEPSS 0.1%CVE-2026-87973LOWIf-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion NameEPSS 0.1%CVE-2026-87070MEDIUMForminator Forms < 1.57.2.1 - Unauthenticated Poll Vote Limit Bypass via IP SpoofingEPSS 0.1%CVE-2026-17520MEDIUMNewsletters < 4.17 - Unauthenticated API Access via Predictable API KeyEPSS 0.1%CVE-2026-15046MEDIUMLitExtension: Store to WooCommerce Migration <= 1.2.5 - Connector Token Takeover via CSRFEPSS 0.1%CVE-2026-88848MEDIUMMasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Category Restriction BypassEPSS 0.1%CVE-2025-10684MEDIUMConstruction Light < 1.6.8 - Subscriber+ Arbitrary Plugin ActivationEPSS 0.1%CVE-2026-87978MEDIUMPaymob for WooCommerce < 4.1.14 - Unauthenticated Payment Bypass via Unverified Subscription Transaction CallbackEPSS 0.1%CVE-2026-89411MEDIUMPaymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe PaymentIntentEPSS 0.1%CVE-2026-92996MEDIUMVerge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_doneEPSS 0.1%CVE-2026-1128MEDIUMWP eCommerce <= 3.15.1 - Coupon Deletion via CSRFEPSS 0.1%CVE-2026-13159MEDIUMReal Estate Papi <= 1.0.5 - Subscriber+ Plugin InstallationEPSS 0.1%CVE-2026-81338MEDIUMMasterStudy LMS < 3.7.50 - Subscriber+ Stored HTML Injection via Course DiscussionsEPSS 0.1%CVE-2026-17522MEDIUMNewsletters < 4.17 - Arbitrary Plugin Option Update via CSRFEPSS 0.1%CVE-2026-91832HIGHWP Mobile Menu 2.7.4 - 2.8.8 - Stored XSS via CSRFEPSS 0.1%CVE-2026-105193MEDIUMBooking Calendar < 11.8 - Unauthenticated Booking Information Disclosure and Modification via Predictable Booking HashEPSS —CVE-2026-104671MEDIUMTutorStarter < 4.0.4 - Unauthenticated User Registration Bypass via AJAXEPSS —CVE-2026-86828MEDIUMBackWPup < 5.7.7 - Admin+ Path Traversal to RCE via Restore PclZip FallbackEPSS —CVE-2026-105260MEDIUMDatabase Addon For WPForms < 1.1.1 - Arbitrary Form Entry Deletion via CSRFEPSS —CVE-2026-105194MEDIUMEasy Digital Downloads < 3.7.1 - Subscriber+ Sensitive Information Disclosure via User Downloads BlockEPSS —