Search

Find a vulnerability

Search criteria

    11108 vulnerabilities by Unknown

    CVE-2026-97219 (GCVE-0-2026-97219)

    Vulnerability from nvd – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter
    Summary
    The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying.
    References
    URL Tags
    https://wpscan.com/vulnerability/0787d00b-2263-46… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown MStore API Affected: 4.21.1 , < 4.22.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "product": "MStore API",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "4.22.1",
                  "status": "affected",
                  "version": "4.21.1",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "cyberkareem"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:54.228Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/0787d00b-2263-465f-8f46-906741bf6629/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via \u0027status\u0027 Parameter",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-97219",
        "datePublished": "2026-10-02T06:56:54.228Z",
        "dateReserved": "2026-09-24T09:16:57.925Z",
        "dateUpdated": "2026-10-02T06:56:54.228Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92924 (GCVE-0-2026-92924)

    Vulnerability from nvd – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    Unlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data
    Summary
    The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have arbitrary WordPress shortcodes executed on the site. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.
    References
    URL Tags
    https://wpscan.com/vulnerability/28be6bd7-311d-43… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Unlimited Elements for Elementor Affected: 0 , < 2.0.21 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "product": "Unlimited Elements for Elementor",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "2.0.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jakub Herman"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have arbitrary WordPress shortcodes executed on the site. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:53.564Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/28be6bd7-311d-4338-8256-7378e268c0f8/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Unlimited Elements For Elementor \u003c 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-92924",
        "datePublished": "2026-10-02T06:56:53.564Z",
        "dateReserved": "2026-09-17T11:19:22.002Z",
        "dateUpdated": "2026-10-02T06:56:53.564Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91020 (GCVE-0-2026-91020)

    Vulnerability from nvd – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    WebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amount Manipulation via wt_credit_amount
    Summary
    The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying.
    References
    URL Tags
    https://wpscan.com/vulnerability/998db4a0-693c-47… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown WebToffee Gift Cards for WooCommerce Affected: 0 , < 1.3.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "product": "WebToffee Gift Cards for WooCommerce",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "1.3.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "berke bodur"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-472 External Control of Assumed-Immutable Web Parameter",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:52.902Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/998db4a0-693c-4701-a37e-ec33002e1417/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "WebToffee Gift Cards for WooCommerce \u003c 1.3.1 - Unauthenticated Gift Card Amount Manipulation via wt_credit_amount",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-91020",
        "datePublished": "2026-10-02T06:56:52.902Z",
        "dateReserved": "2026-09-14T16:53:32.098Z",
        "dateUpdated": "2026-10-02T06:56:52.902Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-90987 (GCVE-0-2026-90987)

    Vulnerability from nvd – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    Easy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied Price
    Summary
    The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.
    References
    URL Tags
    https://wpscan.com/vulnerability/7c1faee8-628a-41… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Easy PayPal & Stripe Buy Now Button Affected: 1.8 , < 2.0.6 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "product": "Easy PayPal \u0026 Stripe Buy Now Button",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "2.0.6",
                  "status": "affected",
                  "version": "1.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "JunHee CHO"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Easy PayPal \u0026 Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-472 External Control of Assumed-Immutable Web Parameter",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:52.240Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/7c1faee8-628a-41dc-a5f0-afbc56480a18/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Easy PayPal \u0026 Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied Price",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-90987",
        "datePublished": "2026-10-02T06:56:52.240Z",
        "dateReserved": "2026-09-14T13:55:59.930Z",
        "dateUpdated": "2026-10-02T06:56:52.240Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-90952 (GCVE-0-2026-90952)

    Vulnerability from nvd – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass via REST API
    Summary
    The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site's access mode was configured to hide.
    References
    URL Tags
    https://wpscan.com/vulnerability/8cc260a9-f335-4d… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown WP Edit Password Protected Affected: 2.0.0 , < 2.0.7 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "product": "WP Edit Password Protected",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "2.0.7",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Artus KG"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site\u0027s access mode was configured to hide."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:51.595Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/8cc260a9-f335-4d8c-a1e0-f942f0963bcf/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass via REST API",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-90952",
        "datePublished": "2026-10-02T06:56:51.595Z",
        "dateReserved": "2026-09-14T11:51:41.339Z",
        "dateUpdated": "2026-10-02T06:56:51.595Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-85005 (GCVE-0-2026-85005)

    Vulnerability from nvd – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization
    Summary
    The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service.
    References
    URL Tags
    https://wpscan.com/vulnerability/bddba59e-ab36-42… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Popup Maker WP Affected: 1.2.2.1 , ≤ 1.4.5 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unknown",
              "product": "Popup Maker WP",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThanOrEqual": "1.4.5",
                  "status": "affected",
                  "version": "1.2.2.1",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Artus KG"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:50.943Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/bddba59e-ab36-427f-9b21-98144bf783ff/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-85005",
        "datePublished": "2026-10-02T06:56:50.943Z",
        "dateReserved": "2026-09-02T18:30:07.352Z",
        "dateUpdated": "2026-10-02T06:56:50.943Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84740 (GCVE-0-2026-84740)

    Vulnerability from nvd – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    The Events Calendar 6.12.0 - 6.17.5 - Unauthenticated Arbitrary Shortcode Execution via 'view_data' Parameter
    Summary
    The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
    References
    URL Tags
    https://wpscan.com/vulnerability/3381a51e-beaa-44… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown The Events Calendar Affected: 6.12.0 , < 6.17.5.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "product": "The Events Calendar",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "6.17.5.1",
                  "status": "affected",
                  "version": "6.12.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jakub Herman"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthenticated users to execute arbitrary shortcodes registered on the site."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:50.295Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/3381a51e-beaa-4420-a33b-6a68612a2e8a/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "The Events Calendar 6.12.0 - 6.17.5 - Unauthenticated Arbitrary Shortcode Execution via \u0027view_data\u0027 Parameter",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-84740",
        "datePublished": "2026-10-02T06:56:50.295Z",
        "dateReserved": "2026-09-02T08:41:15.939Z",
        "dateUpdated": "2026-10-02T06:56:50.295Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-79618 (GCVE-0-2026-79618)

    Vulnerability from nvd – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form
    Summary
    The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.
    References
    URL Tags
    https://wpscan.com/vulnerability/a11bf097-3829-4b… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown WP User Frontend Affected: 0 , < 4.3.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "product": "WP User Frontend",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "4.3.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Erwan LR (WPScan)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form\u0027s configuration, immediately publish posts through forms restricted to paying subscribers."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:49.629Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/a11bf097-3829-4baa-878c-80b113c5a744/"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "WP User Frontend \u003c 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-79618",
        "datePublished": "2026-10-02T06:56:49.629Z",
        "dateReserved": "2026-08-25T08:06:20.113Z",
        "dateUpdated": "2026-10-02T06:56:49.629Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-1661 (GCVE-0-2026-1661)

    Vulnerability from nvd – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection
    Summary
    The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log screens, allowing unauthenticated users to inject styled content and links, for example through a public contact form, that can deceive an administrator viewing the log and send their browser to an attacker-controlled page.
    References
    URL Tags
    https://wpscan.com/vulnerability/dde19119-7ea8-4d… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown WP Mail Logging Affected: 0 , < 1.17.0 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "product": "WP Mail Logging",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "1.17.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Kasia Sok"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log screens, allowing unauthenticated users to inject styled content and links, for example through a public contact form, that can deceive an administrator viewing the log and send their browser to an attacker-controlled page."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-79 Cross-Site Scripting (XSS)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:48.984Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/dde19119-7ea8-4d02-bf89-7a6b0ca010b5/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "WP Mail Logging \u003c 1.17.0 - Unauthenticated HTML Injection",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-1661",
        "datePublished": "2026-10-02T06:56:48.984Z",
        "dateReserved": "2026-01-29T20:06:22.522Z",
        "dateUpdated": "2026-10-02T06:56:48.984Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-13413 (GCVE-0-2026-13413)

    Vulnerability from nvd – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    CMP - Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode Bypass via Login URL Match
    Summary
    The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing unauthenticated visitors to bypass the coming-soon page and reach the otherwise hidden site, including hidden published pages, by shaping the request so it is mistaken for a login request.
    References
    URL Tags
    https://wpscan.com/vulnerability/706afdef-4935-44… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown CMP – Coming Soon & Maintenance Affected: 0 , < 4.1.20 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "product": "CMP \u2013 Coming Soon \u0026 Maintenance",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "4.1.20",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Meher Sudhakar Abbireddi"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The CMP \u2013 Coming Soon \u0026 Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing unauthenticated visitors to bypass the coming-soon page and reach the otherwise hidden site, including hidden published pages, by shaping the request so it is mistaken for a login request."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-284 Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:48.326Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/706afdef-4935-44d9-ab09-68c80f3bfef9/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "CMP - Coming Soon \u0026 Maintenance \u003c 4.1.20 - Unauthenticated Maintenance Mode Bypass via Login URL Match",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-13413",
        "datePublished": "2026-10-02T06:56:48.326Z",
        "dateReserved": "2026-06-26T11:40:04.990Z",
        "dateUpdated": "2026-10-02T06:56:48.326Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-97318 (GCVE-0-2026-97318)

    Vulnerability from nvd – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' Parameter
    Summary
    The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary external site.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/a171b0f1-b2d2-44… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Giveaways and Contests by RafflePress Affected: 0 , < 1.12.27 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Giveaways and Contests by RafflePress",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "1.12.27",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Dick Snel"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Giveaways and Contests by RafflePress  WordPress plugin before 1.12.27 does not properly validate a giveaway\u0027s parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site\u0027s own giveaway confirmation and referral links redirect visitors to an arbitrary external site."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-601 URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:27.170Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/a171b0f1-b2d2-4482-b44f-bd4a1f3b223b/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Giveaways and Contests by RafflePress \u003c 1.12.27 - Unauthenticated Stored Open Redirect via \u0027parent_url\u0027 Parameter",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-97318",
        "datePublished": "2026-10-02T06:00:27.170Z",
        "dateReserved": "2026-09-24T11:27:52.068Z",
        "dateUpdated": "2026-10-02T06:00:27.170Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-97317 (GCVE-0-2026-97317)

    Vulnerability from nvd – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page
    Summary
    The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/f8779fd4-f362-40… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Giveaways and Contests by RafflePress Affected: 0 , < 1.12.27 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Giveaways and Contests by RafflePress",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "1.12.27",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Dmitrii Ignatyev"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Giveaways and Contests by RafflePress  WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-200 Information Exposure",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:26.940Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/f8779fd4-f362-40c4-8df1-145620c69103/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Giveaways and Contests by RafflePress \u003c 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-97317",
        "datePublished": "2026-10-02T06:00:26.940Z",
        "dateReserved": "2026-09-24T11:27:48.588Z",
        "dateUpdated": "2026-10-02T06:00:26.940Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-94298 (GCVE-0-2026-94298)

    Vulnerability from nvd – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    BuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content Parameter
    Summary
    The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/6f6c8718-7e7e-47… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown BuildKit Affected: 0 , < 1.0.29 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "BuildKit",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "1.0.29",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Naiches"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The BuildKit  WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-89 SQL Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:26.412Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/6f6c8718-7e7e-4700-a4c2-ee177c44b7ea/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "BuildKit \u003c 1.0.29 - Contributor+ Stored SQLi via list_content Parameter",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-94298",
        "datePublished": "2026-10-02T06:00:26.412Z",
        "dateReserved": "2026-09-21T09:44:15.108Z",
        "dateUpdated": "2026-10-02T06:00:26.412Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91828 (GCVE-0-2026-91828)

    Vulnerability from nvd – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    OMGF < 6.3.11 - Unauthenticated DoS via do_optimize
    Summary
    The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site's PHP worker pool and make the entire site unavailable.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/be25f7b5-5790-4d… exploitvdb-entrytechnical-description
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "6.3.11",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "\u00c1ngel Santana"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site\u0027s PHP worker pool and make the entire site unavailable."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-400 Uncontrolled Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:25.216Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/be25f7b5-5790-4db7-9056-b43b538a7183/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "OMGF \u003c 6.3.11 - Unauthenticated DoS via do_optimize",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-91828",
        "datePublished": "2026-10-02T06:00:25.216Z",
        "dateReserved": "2026-09-15T08:11:48.154Z",
        "dateUpdated": "2026-10-02T06:00:25.216Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91023 (GCVE-0-2026-91023)

    Vulnerability from nvd – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    Motors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured
    Summary
    The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/c2400c65-5d77-45… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Motors Affected: 0 , < 1.4.124 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Motors",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "1.4.124",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Yaswanth Reddy Sunkara"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Motors  WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors  WordPress plugin before 1.4.124\u0027s paid featured-listing option is enabled, neither of which is a default configuration."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:25.876Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/c2400c65-5d77-454c-9691-5e664556341b/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Motors \u2013 Car Dealership \u0026 Classified Listings \u003c 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-91023",
        "datePublished": "2026-10-02T06:00:25.876Z",
        "dateReserved": "2026-09-14T17:07:28.393Z",
        "dateUpdated": "2026-10-02T06:00:25.876Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91022 (GCVE-0-2026-91022)

    Vulnerability from nvd – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    Motors < 1.4.124 - Listing Manager+ Stored XSS via Badge Color
    Summary
    The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/72672806-e2f3-41… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Motors Affected: 0 , < 1.4.124 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Motors",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "1.4.124",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Yaswanth Reddy Sunkara"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Motors  WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-79 Cross-Site Scripting (XSS)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:25.652Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/72672806-e2f3-417e-83c0-854c604028e4/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Motors \u003c 1.4.124 - Listing Manager+ Stored XSS via Badge Color",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-91022",
        "datePublished": "2026-10-02T06:00:25.652Z",
        "dateReserved": "2026-09-14T17:07:10.725Z",
        "dateUpdated": "2026-10-02T06:00:25.652Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-90988 (GCVE-0-2026-90988)

    Vulnerability from nvd – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    Request a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum
    Summary
    The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/6c02759e-b37e-43… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Request a Quote Affected: 0 , ≤ 2.5.6 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Request a Quote",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThanOrEqual": "2.5.6",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Artus KG"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Request a Quote  WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-200 Information Exposure",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:24.780Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/6c02759e-b37e-43ce-a4f4-467e8af63a17/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Request a Quote \u003c= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-90988",
        "datePublished": "2026-10-02T06:00:24.780Z",
        "dateReserved": "2026-09-14T13:58:23.882Z",
        "dateUpdated": "2026-10-02T06:00:24.780Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-85016 (GCVE-0-2026-85016)

    Vulnerability from nvd – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    Unlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter
    Summary
    The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/1d488c84-2797-4c… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Unlimited Elements for Elementor Affected: 0 , < 2.0.21 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Unlimited Elements for Elementor",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "2.0.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Revanth Hari Narayana Matte"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-79 Cross-Site Scripting (XSS)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:25.438Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/1d488c84-2797-4c02-8c13-54b80e4128dc/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Unlimited Elements For Elementor \u003c 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-85016",
        "datePublished": "2026-10-02T06:00:25.438Z",
        "dateReserved": "2026-09-02T19:18:47.849Z",
        "dateUpdated": "2026-10-02T06:00:25.438Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-85004 (GCVE-0-2026-85004)

    Vulnerability from nvd – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    Popup Maker WP <= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect
    Summary
    The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker WordPress plugin through 1.4.5 option (the linked service account and API configuration) that should only be modifiable by administrators.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/38041b58-7738-47… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Popup Maker Affected: 0 , ≤ 1.4.5 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Popup Maker",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThanOrEqual": "1.4.5",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Artus KG"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Popup Maker  WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker  WordPress plugin through 1.4.5 option (the linked service account and API configuration) that should only be modifiable by administrators."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-284 Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:24.239Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/38041b58-7738-4710-a1b6-4005e9ec2c01/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Popup Maker WP \u003c= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-85004",
        "datePublished": "2026-10-02T06:00:24.239Z",
        "dateReserved": "2026-09-02T18:30:03.819Z",
        "dateUpdated": "2026-10-02T06:00:24.239Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-81740 (GCVE-0-2026-81740)

    Vulnerability from nvd – Published: 2026-10-02 06:00 – Updated: 2026-10-02 06:00
    VLAI
    Title
    Paytm Payment Gateway < 2.8.9 - Unauthenticated Order Status Manipulation via Payment Callback
    Summary
    The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders, including marking unpaid orders as paid and reducing stock.
    Severity
    No CVSS data available.
    References
    URL Tags
    https://wpscan.com/vulnerability/13767875-5010-49… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Paytm Payment Gateway Affected: 0 , < 2.8.9 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Paytm Payment Gateway",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "2.8.9",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Artus KG"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders, including marking unpaid orders as paid and reducing stock."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-287 Improper Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:00:24.014Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/13767875-5010-494a-b3ed-133d58b8ecea/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Paytm Payment Gateway \u003c 2.8.9 - Unauthenticated Order Status Manipulation via Payment Callback",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-81740",
        "datePublished": "2026-10-02T06:00:24.014Z",
        "dateReserved": "2026-08-27T11:47:22.935Z",
        "dateUpdated": "2026-10-02T06:00:24.014Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-97219 (GCVE-0-2026-97219)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter
    Summary
    The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying.
    References
    URL Tags
    https://wpscan.com/vulnerability/0787d00b-2263-46… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown MStore API Affected: 4.21.1 , < 4.22.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "product": "MStore API",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "4.22.1",
                  "status": "affected",
                  "version": "4.21.1",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "cyberkareem"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:54.228Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/0787d00b-2263-465f-8f46-906741bf6629/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via \u0027status\u0027 Parameter",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-97219",
        "datePublished": "2026-10-02T06:56:54.228Z",
        "dateReserved": "2026-09-24T09:16:57.925Z",
        "dateUpdated": "2026-10-02T06:56:54.228Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92924 (GCVE-0-2026-92924)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    Unlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data
    Summary
    The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have arbitrary WordPress shortcodes executed on the site. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.
    References
    URL Tags
    https://wpscan.com/vulnerability/28be6bd7-311d-43… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Unlimited Elements for Elementor Affected: 0 , < 2.0.21 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "product": "Unlimited Elements for Elementor",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "2.0.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jakub Herman"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have arbitrary WordPress shortcodes executed on the site. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:53.564Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/28be6bd7-311d-4338-8256-7378e268c0f8/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Unlimited Elements For Elementor \u003c 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-92924",
        "datePublished": "2026-10-02T06:56:53.564Z",
        "dateReserved": "2026-09-17T11:19:22.002Z",
        "dateUpdated": "2026-10-02T06:56:53.564Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91020 (GCVE-0-2026-91020)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    WebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amount Manipulation via wt_credit_amount
    Summary
    The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying.
    References
    URL Tags
    https://wpscan.com/vulnerability/998db4a0-693c-47… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown WebToffee Gift Cards for WooCommerce Affected: 0 , < 1.3.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "product": "WebToffee Gift Cards for WooCommerce",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "1.3.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "berke bodur"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-472 External Control of Assumed-Immutable Web Parameter",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:52.902Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/998db4a0-693c-4701-a37e-ec33002e1417/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "WebToffee Gift Cards for WooCommerce \u003c 1.3.1 - Unauthenticated Gift Card Amount Manipulation via wt_credit_amount",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-91020",
        "datePublished": "2026-10-02T06:56:52.902Z",
        "dateReserved": "2026-09-14T16:53:32.098Z",
        "dateUpdated": "2026-10-02T06:56:52.902Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-90987 (GCVE-0-2026-90987)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    Easy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied Price
    Summary
    The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.
    References
    URL Tags
    https://wpscan.com/vulnerability/7c1faee8-628a-41… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Easy PayPal & Stripe Buy Now Button Affected: 1.8 , < 2.0.6 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "product": "Easy PayPal \u0026 Stripe Buy Now Button",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "2.0.6",
                  "status": "affected",
                  "version": "1.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "JunHee CHO"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Easy PayPal \u0026 Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-472 External Control of Assumed-Immutable Web Parameter",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:52.240Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/7c1faee8-628a-41dc-a5f0-afbc56480a18/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Easy PayPal \u0026 Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied Price",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-90987",
        "datePublished": "2026-10-02T06:56:52.240Z",
        "dateReserved": "2026-09-14T13:55:59.930Z",
        "dateUpdated": "2026-10-02T06:56:52.240Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-90952 (GCVE-0-2026-90952)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass via REST API
    Summary
    The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site's access mode was configured to hide.
    References
    URL Tags
    https://wpscan.com/vulnerability/8cc260a9-f335-4d… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown WP Edit Password Protected Affected: 2.0.0 , < 2.0.7 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "product": "WP Edit Password Protected",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "2.0.7",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Artus KG"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site\u0027s access mode was configured to hide."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:51.595Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/8cc260a9-f335-4d8c-a1e0-f942f0963bcf/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass via REST API",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-90952",
        "datePublished": "2026-10-02T06:56:51.595Z",
        "dateReserved": "2026-09-14T11:51:41.339Z",
        "dateUpdated": "2026-10-02T06:56:51.595Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-85005 (GCVE-0-2026-85005)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization
    Summary
    The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service.
    References
    URL Tags
    https://wpscan.com/vulnerability/bddba59e-ab36-42… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown Popup Maker WP Affected: 1.2.2.1 , ≤ 1.4.5 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unknown",
              "product": "Popup Maker WP",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThanOrEqual": "1.4.5",
                  "status": "affected",
                  "version": "1.2.2.1",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Artus KG"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:50.943Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/bddba59e-ab36-427f-9b21-98144bf783ff/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-85005",
        "datePublished": "2026-10-02T06:56:50.943Z",
        "dateReserved": "2026-09-02T18:30:07.352Z",
        "dateUpdated": "2026-10-02T06:56:50.943Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84740 (GCVE-0-2026-84740)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    The Events Calendar 6.12.0 - 6.17.5 - Unauthenticated Arbitrary Shortcode Execution via 'view_data' Parameter
    Summary
    The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
    References
    URL Tags
    https://wpscan.com/vulnerability/3381a51e-beaa-44… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown The Events Calendar Affected: 6.12.0 , < 6.17.5.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "product": "The Events Calendar",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "6.17.5.1",
                  "status": "affected",
                  "version": "6.12.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jakub Herman"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthenticated users to execute arbitrary shortcodes registered on the site."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:50.295Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/3381a51e-beaa-4420-a33b-6a68612a2e8a/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "The Events Calendar 6.12.0 - 6.17.5 - Unauthenticated Arbitrary Shortcode Execution via \u0027view_data\u0027 Parameter",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-84740",
        "datePublished": "2026-10-02T06:56:50.295Z",
        "dateReserved": "2026-09-02T08:41:15.939Z",
        "dateUpdated": "2026-10-02T06:56:50.295Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-79618 (GCVE-0-2026-79618)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form
    Summary
    The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.
    References
    URL Tags
    https://wpscan.com/vulnerability/a11bf097-3829-4b… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown WP User Frontend Affected: 0 , < 4.3.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "product": "WP User Frontend",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "4.3.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Erwan LR (WPScan)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form\u0027s configuration, immediately publish posts through forms restricted to paying subscribers."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:49.629Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/a11bf097-3829-4baa-878c-80b113c5a744/"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "WP User Frontend \u003c 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-79618",
        "datePublished": "2026-10-02T06:56:49.629Z",
        "dateReserved": "2026-08-25T08:06:20.113Z",
        "dateUpdated": "2026-10-02T06:56:49.629Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-1661 (GCVE-0-2026-1661)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection
    Summary
    The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log screens, allowing unauthenticated users to inject styled content and links, for example through a public contact form, that can deceive an administrator viewing the log and send their browser to an attacker-controlled page.
    References
    URL Tags
    https://wpscan.com/vulnerability/dde19119-7ea8-4d… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown WP Mail Logging Affected: 0 , < 1.17.0 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "product": "WP Mail Logging",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "1.17.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Kasia Sok"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log screens, allowing unauthenticated users to inject styled content and links, for example through a public contact form, that can deceive an administrator viewing the log and send their browser to an attacker-controlled page."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-79 Cross-Site Scripting (XSS)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:48.984Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/dde19119-7ea8-4d02-bf89-7a6b0ca010b5/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "WP Mail Logging \u003c 1.17.0 - Unauthenticated HTML Injection",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-1661",
        "datePublished": "2026-10-02T06:56:48.984Z",
        "dateReserved": "2026-01-29T20:06:22.522Z",
        "dateUpdated": "2026-10-02T06:56:48.984Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-13413 (GCVE-0-2026-13413)

    Vulnerability from cvelistv5 – Published: 2026-10-02 06:56 – Updated: 2026-10-02 06:56
    VLAI
    Title
    CMP - Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode Bypass via Login URL Match
    Summary
    The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing unauthenticated visitors to bypass the coming-soon page and reach the otherwise hidden site, including hidden published pages, by shaping the request so it is mistaken for a login request.
    References
    URL Tags
    https://wpscan.com/vulnerability/706afdef-4935-44… exploitvdb-entrytechnical-description
    Impacted products
    Vendor Product Version
    Unknown CMP – Coming Soon & Maintenance Affected: 0 , < 4.1.20 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "product": "CMP \u2013 Coming Soon \u0026 Maintenance",
              "vendor": "Unknown",
              "versions": [
                {
                  "lessThan": "4.1.20",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Meher Sudhakar Abbireddi"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "WPScan"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The CMP \u2013 Coming Soon \u0026 Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing unauthenticated visitors to bypass the coming-soon page and reach the otherwise hidden site, including hidden published pages, by shaping the request so it is mistaken for a login request."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-284 Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T06:56:48.326Z",
            "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
            "shortName": "WPScan"
          },
          "references": [
            {
              "tags": [
                "exploit",
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://wpscan.com/vulnerability/706afdef-4935-44d9-ab09-68c80f3bfef9/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "CMP - Coming Soon \u0026 Maintenance \u003c 4.1.20 - Unauthenticated Maintenance Mode Bypass via Login URL Match",
          "x_generator": {
            "engine": "WPScan CVE Generator"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "assignerShortName": "WPScan",
        "cveId": "CVE-2026-13413",
        "datePublished": "2026-10-02T06:56:48.326Z",
        "dateReserved": "2026-06-26T11:40:04.990Z",
        "dateUpdated": "2026-10-02T06:56:48.326Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }