全部
最新采集的全量资讯流
-
CVE-2026-14189 | WPBot Plugin up to 8.5.1 on WordPress sql injection
A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/wpbot_plugin">WPBot Plugin up to 8.5.1</a> on WordPress. This impacts an unknown function. The manipulation results in sql injection. This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-14189">CVE-20…
A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/wpbot_plugin">WPBot Plugin up to 8.5.1</a> on WordPress. This impacts an unknown function. The manipulation results in sql injection. This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-14189">CVE-20A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/wpbot_plugin">WPBot Plugin up to 8.5.1</a> on WordPress. This impacts an unknown function. The manipulation results in sql injection. This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-14189">CVE-2026-14189</a>. It is possible to launch the attack remotely. No exploit is available. It is advisable to upgrade the affected component.扩展字段
{ "raw_pub_date": "Mon, 27 Jul 2026 08:48:37 +0200" } -
CVE-2026-13597 | 微信二维码登陆 Plugin up to 1.3 on WordPress improper authentication
A vulnerability was found in <a href="https://vuldb.com/product/___________plugin">微信二维码登陆 Plugin up to 1.3</a> on WordPress. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown function. The manipulation leads to improper authentication. This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-13597…
A vulnerability was found in <a href="https://vuldb.com/product/___________plugin">微信二维码登陆 Plugin up to 1.3</a> on WordPress. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown function. The manipulation leads to improper authentication. This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-13597A vulnerability was found in <a href="https://vuldb.com/product/___________plugin">微信二维码登陆 Plugin up to 1.3</a> on WordPress. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown function. The manipulation leads to improper authentication. This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-13597">CVE-2026-13597</a>. It is possible to initiate the attack remotely. There is no exploit available.扩展字段
{ "raw_pub_date": "Mon, 27 Jul 2026 08:47:48 +0200" } -
CVE-2026-14289 | FacturaONE para WooCommerce con VeriFactu Plugin up to 5.36 on WordPress code injection
A vulnerability was found in <a href="https://vuldb.com/product/facturaone_para_woocommerce_con_verifactu_plugin">FacturaONE para WooCommerce con VeriFactu Plugin up to 5.36</a> on WordPress. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. The impacted element is an unknown function. Executing a manipulation can lead to code injecti…
A vulnerability was found in <a href="https://vuldb.com/product/facturaone_para_woocommerce_con_verifactu_plugin">FacturaONE para WooCommerce con VeriFactu Plugin up to 5.36</a> on WordPress. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. The impacted element is an unknown function. Executing a manipulation can lead to code injectiA vulnerability was found in <a href="https://vuldb.com/product/facturaone_para_woocommerce_con_verifactu_plugin">FacturaONE para WooCommerce con VeriFactu Plugin up to 5.36</a> on WordPress. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. The impacted element is an unknown function. Executing a manipulation can lead to code injection. This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-14289">CVE-2026-14289</a>. The attack may be performed from remote. There is no available exploit. It is recommended to upgrade the affected component.扩展字段
{ "raw_pub_date": "Mon, 27 Jul 2026 08:46:47 +0200" } -
CVE-2026-13714 | Realtyna Organic IDX Plugin/WPL Real Estate Plugin unrestricted upload
A vulnerability was found in <a href="https://vuldb.com/product/realtyna_organic_idx_plugin">Realtyna Organic IDX Plugin and WPL Real Estate Plugin up to 5.2.x</a> on WordPress. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. The affected element is an unknown function. Performing a manipulation results in unrestricted upload. Th…
A vulnerability was found in <a href="https://vuldb.com/product/realtyna_organic_idx_plugin">Realtyna Organic IDX Plugin and WPL Real Estate Plugin up to 5.2.x</a> on WordPress. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. The affected element is an unknown function. Performing a manipulation results in unrestricted upload. ThA vulnerability was found in <a href="https://vuldb.com/product/realtyna_organic_idx_plugin">Realtyna Organic IDX Plugin and WPL Real Estate Plugin up to 5.2.x</a> on WordPress. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. The affected element is an unknown function. Performing a manipulation results in unrestricted upload. This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-13714">CVE-2026-13714</a>. The attack is possible to be carried out remotely. No exploit exists. Upgrading the affected component is recommended.扩展字段
{ "raw_pub_date": "Mon, 27 Jul 2026 08:45:36 +0200" } -
CVE-2026-13400 | Simply Schedule Appointments Plugin up to 1.6.12.2 on WordPress Notification Rendering wp_kses_post cross site scripting
A vulnerability was found in <a href="https://vuldb.com/product/simply_schedule_appointments_plugin">Simply Schedule Appointments Plugin up to 1.6.12.2</a> on WordPress and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Impacted is the function <code>wp_kses_post</code> of the component <em>Notification Rendering</em>. Such manipulation l…
A vulnerability was found in <a href="https://vuldb.com/product/simply_schedule_appointments_plugin">Simply Schedule Appointments Plugin up to 1.6.12.2</a> on WordPress and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Impacted is the function <code>wp_kses_post</code> of the component <em>Notification Rendering</em>. Such manipulation lA vulnerability was found in <a href="https://vuldb.com/product/simply_schedule_appointments_plugin">Simply Schedule Appointments Plugin up to 1.6.12.2</a> on WordPress and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Impacted is the function <code>wp_kses_post</code> of the component <em>Notification Rendering</em>. Such manipulation leads to cross site scripting. This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-13400">CVE-2026-13400</a>. The attack can be executed remotely. There is not any exploit available. It is suggested to upgrade the affected component.扩展字段
{ "raw_pub_date": "Mon, 27 Jul 2026 08:37:53 +0200" } -
CVE-2026-12982 | Document Gallery Plugin up to 5.1.0 on WordPress cross site scripting
A vulnerability has been found in <a href="https://vuldb.com/product/document_gallery_plugin">Document Gallery Plugin up to 5.1.0</a> on WordPress and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects some unknown processing. This manipulation causes cross site scripting. This vulnerability is registered as <a href="https…
A vulnerability has been found in <a href="https://vuldb.com/product/document_gallery_plugin">Document Gallery Plugin up to 5.1.0</a> on WordPress and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects some unknown processing. This manipulation causes cross site scripting. This vulnerability is registered as <a href="httpsA vulnerability has been found in <a href="https://vuldb.com/product/document_gallery_plugin">Document Gallery Plugin up to 5.1.0</a> on WordPress and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects some unknown processing. This manipulation causes cross site scripting. This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-12982">CVE-2026-12982</a>. Remote exploitation of the attack is possible. No exploit is available. The affected component should be upgraded.扩展字段
{ "raw_pub_date": "Mon, 27 Jul 2026 08:36:37 +0200" } -
CVE-2025-15662 | Printcart Web to Print Product Designer Plugin up to 2.5.2 on WordPress server-side request forgery
A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/printcart:web_to_print_product_designer_plugin">Printcart Web to Print Product Designer Plugin up to 2.5.2</a> on WordPress. This vulnerability affects unknown code. The manipulation results in server-side request forgery…
A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/printcart:web_to_print_product_designer_plugin">Printcart Web to Print Product Designer Plugin up to 2.5.2</a> on WordPress. This vulnerability affects unknown code. The manipulation results in server-side request forgeryA vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/printcart:web_to_print_product_designer_plugin">Printcart Web to Print Product Designer Plugin up to 2.5.2</a> on WordPress. This vulnerability affects unknown code. The manipulation results in server-side request forgery. This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2025-15662">CVE-2025-15662</a>. The attack may be launched remotely. There is no exploit available. You should upgrade the affected component.扩展字段
{ "raw_pub_date": "Mon, 27 Jul 2026 08:35:46 +0200" } -
CVE-2026-13390 | The Events Calendar Plugin up to 6.8.2.1 on WordPress Event Aggregator Import authorization
A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/the_events_calendar_plugin">The Events Calendar Plugin up to 6.8.2.1</a> on WordPress. This affects an unknown part of the component <em>Event Aggregator Import</em>. The manipulation leads to missing authorization. …
A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/the_events_calendar_plugin">The Events Calendar Plugin up to 6.8.2.1</a> on WordPress. This affects an unknown part of the component <em>Event Aggregator Import</em>. The manipulation leads to missing authorization.A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/the_events_calendar_plugin">The Events Calendar Plugin up to 6.8.2.1</a> on WordPress. This affects an unknown part of the component <em>Event Aggregator Import</em>. The manipulation leads to missing authorization. This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-13390">CVE-2026-13390</a>. The attack may be initiated remotely. There is no available exploit. It is advisable to upgrade the affected component.扩展字段
{ "raw_pub_date": "Mon, 27 Jul 2026 08:34:39 +0200" }