Common Vulnerabilities and Exposures (CVE)

CVE-2026-87918

Sep 12, 2026 06:00:13 UTC

The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls, an...

CVE-2026-87916

Sep 12, 2026 06:00:13 UTC

The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every cha...

CVE-2026-87894

Sep 12, 2026 06:00:13 UTC

The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing un...

CVE-2026-87892

Sep 12, 2026 06:00:13 UTC

The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bo...

CVE-2026-87891

Sep 12, 2026 06:00:12 UTC

The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unava...

CVE-2026-87888

Sep 12, 2026 06:00:12 UTC

The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an adm...

CVE-2026-87842

Sep 12, 2026 06:00:12 UTC

The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's...

CVE-2026-87797

Sep 12, 2026 06:00:12 UTC

The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber to ...

CVE-2026-87759

Sep 12, 2026 06:00:12 UTC

The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber...

CVE-2026-86790

Sep 12, 2026 06:00:11 UTC

The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cros...

CVE-2026-85681

Sep 12, 2026 06:00:11 UTC

The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowin...

CVE-2026-84171

Sep 12, 2026 06:00:11 UTC

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execu...

CVE-2026-84099

Sep 12, 2026 06:00:11 UTC

The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject...

CVE-2026-84047

Sep 12, 2026 06:00:11 UTC

The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

CVE-2026-84025

Sep 12, 2026 06:00:10 UTC

The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product info...