CVE Vulnerability Database

Search and browse 375,788 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-18962MEDIUM4.3The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload int...
CVE-2026-18943MEDIUM6.5The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allow...
CVE-2026-18789HIGH7.5The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, ...
CVE-2026-18474HIGH8.6The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta...
CVE-2026-18391CRITICAL9.8The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stor...
CVE-2026-18366CRITICAL9.8The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access ...
CVE-2026-18230HIGH8.1The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta...
CVE-2026-18057HIGH8.1The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it i...
CVE-2026-18049HIGH7.5The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its ...
CVE-2026-18048HIGH7.5The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a f...
CVE-2026-18046MEDIUM4.3The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability...
CVE-2026-18035MEDIUM5.3The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allo...
CVE-2026-17013MEDIUM6.1The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it...
CVE-2026-16977HIGH8.1The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is ...
CVE-2026-16737MEDIUM5.3The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a ca...
CVE-2026-16538CRITICAL9.1The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top...
CVE-2026-16294HIGH7.1The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode...
CVE-2026-16253HIGH7.5The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-resto...
CVE-2026-16066MEDIUM5.4The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it ...
CVE-2026-16051CRITICAL9.8The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its re...
CVE-2026-15388MEDIUM4.3The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability...
CVE-2026-15249MEDIUM5.4The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts i...
CVE-2026-15039CRITICAL9.8The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, all...
CVE-2026-14925HIGH7.5The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file downlo...
CVE-2026-14859MEDIUM4.3The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX a...