Search Results (643 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-96662 2 Latepoint, Wordpress-extensions 2 Appointment Booking Plugin – Latepoint | Calendar & Scheduling For Wordpress, Appointment Booking Plugin 2026-10-11 7.5 High
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to generic SQL Injection via 'booking[service_id]' Parameter in all versions up to, and including, 5.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-96563 2 Stylemixthemes, Wordpress-extensions 2 Motors - Car Dealer\, Classifieds \& Listing, Motors 2026-10-11 6.4 Medium
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'stm_f_s' parameter in all versions up to, and including, 1.4.123 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce required by the stm_ajax_add_a_car AJAX handler is emitted in wp_footer on every page, making it accessible to any authenticated user and removing any practical barrier to exploitation at the Subscriber level.
CVE-2026-93945 2 Axiomthemes, Wordpress-extensions 2 Balance, Balance 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.
CVE-2026-93944 2 Themerex Group, Wordpress-extensions 2 Camelia, Camelia 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15.
CVE-2026-93943 2 Themerex Group, Wordpress-extensions 2 Convex, Convex 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0.
CVE-2026-93942 2 Themerex Group, Wordpress-extensions 2 Dwell, Dwell 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a through 1.16.0.
CVE-2026-93941 2 Themerex Group, Wordpress-extensions 2 Edema, Edema 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.
CVE-2026-93940 2 Themerex Group, Wordpress-extensions 2 Greeny, Greeny 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.
CVE-2026-93938 2 Themerex Group, Wordpress-extensions 2 Hogwords, Hogwords 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.
CVE-2026-93937 2 Themerex Group, Wordpress-extensions 2 Hygia, Hygia 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0.
CVE-2026-93936 2 Themerex Group, Wordpress-extensions 2 Ipharm, Ipharm 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4.
CVE-2026-93935 2 Themerex Group, Wordpress-extensions 2 Let's Play, Let's Play 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play playhockey allows Object Injection.This issue affects Let's Play: from n/a through 1.1.15.
CVE-2026-93934 2 Themerex Group, Wordpress-extensions 2 Partiso, Partiso 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Partiso partiso allows Object Injection.This issue affects Partiso: from n/a through 1.1.13.
CVE-2026-93933 2 Themerex Group, Wordpress-extensions 2 Rosalinda, Rosalinda 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Rosalinda rosalinda allows Object Injection.This issue affects Rosalinda: from n/a through 1.2.4.
CVE-2026-93932 2 Themerex Group, Wordpress-extensions 2 Smart Casa, Smart Casa 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Smart Casa smart-casa allows Object Injection.This issue affects Smart Casa: from n/a through 1.0.12.
CVE-2026-93931 2 Themerex Group, Wordpress-extensions 2 Smash, Smash 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Smash smash allows Object Injection.This issue affects Smash: from n/a through 1.12.0.
CVE-2026-62046 2 Themerex Group, Wordpress-extensions 2 Gutentype, Gutentype 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12.
CVE-2026-62045 2 Themerex Group, Wordpress-extensions 2 Booklovers, Booklovers 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0.
CVE-2026-14335 2 Smub, Wordpress-extensions 3 Easy Digital Downloads, Easy Digital Downloads – Ecommerce Payments And Subscriptions Made Easy, Easy Digital Downloads 2026-10-11 7.2 High
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PayPal IPN Parameters in all versions up to, and including, 3.6.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-100147 2 Funnelkit, Wordpress-extensions 2 Funnelkit, Funnelkit 2026-10-11 7.2 High
The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shipping_first_name' parameter in all versions up to, and including, 3.16.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.