Base locale WP Commander

Vulnérabilités WordPress connues

Recherchez une extension, un thème, une version de WordPress ou une référence CVE dans la base synchronisée localement.

37 748 vulnérabilités indexées · 44 218 plages de versions · mise à jour le 22/07/2026 à 02:19

41 069 résultats

Page 1 sur 3423

CVE-2025-13146 Moyenne · 6,5
Contact Form 7 – Dynamic Text Extension

Contact Form 7 – Dynamic Text Extension <= 5.0.6 – Unauthenticated Arbitrary Shortcode Execution

The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.6. This is due to the software allowing users to execute an action…

Versions affectées

*-5.0.3

Correctif

Non indiqué

Publication

22/07/2026

CVE-2026-15787 Moyenne · 6,4
Ultimate Addons for Elementor

Ultimate Addons for Elementor <= 2.9.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes

The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-2.9.1

Correctif

2.9.2

Publication

21/07/2026

CVE-2026-15802 Élevée · 8,1
WP Foodbakery

WP Foodbakery <= 4.9 – Authenticated (Subscriber+) Arbitrary File Deletion via via delete_locations_backup_file AJAX Action

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with…

Versions affectées

*-4.9

Correctif

Non indiqué

Publication

21/07/2026

CVE-2026-15145 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 6.6.11 – Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and…

Versions affectées

*-6.6.11

Correctif

6.7.0

Publication

20/07/2026

CVE-2026-1372 Moyenne · 4,3
Tutor LMS Elementor Addons

Tutor LMS Elementor Addons <= 4.0.0 – Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin Activation

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers.…

Versions affectées

*-4.0.0

Correctif

Non indiqué

Publication

20/07/2026

CVE-2026-1771 Élevée · 7,2
MapSVG – Vector maps, Image maps, Google Maps

MapSVG <= 8.14.0 – Authenticated (Administrator+) Arbitrary File Upload via '/mapsvg/v1/svgfile' Endpoint

The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up to, and including, 8.14.0 This is due to an incorrect conditional check that…

Versions affectées

*-8.14.0

Correctif

8.14.1

Publication

20/07/2026

CVE-2026-13439 Critique · 9,8
Easy Form Builder by WhiteStudio – Drag & Drop Form Builder

Easy Form Builder by WhiteStudio <= 4.0.11 – Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint

The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid')…

Versions affectées

*-4.0.11

Correctif

4.0.12

Publication

20/07/2026

CVE-2026-15782 Moyenne · 4,9
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

WPForms <= 2.0.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content

The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content in all versions…

Versions affectées

*-2.0.0.1

Correctif

2.0.0.2

Publication

20/07/2026

CVE-2026-15156 Moyenne · 6,4
Essential Addons for Elementor – Popular Elementor Templates & Widgets

Essential Addons for Elementor <= 6.6.11 – Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input…

Versions affectées

*-6.6.11

Correctif

6.7.0

Publication

20/07/2026

CVE-2026-12900 Moyenne · 6,4
Spectra Legacy – Gutenberg Blocks

Spectra Gutenberg Blocks <= 2.19.28 – Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in all versions up to, and including, 2.19.28 due to insufficient input sanitization and…

Versions affectées

*-2.19.28

Correctif

2.19.29

Publication

20/07/2026

CVE-2026-63030 Critique · 9,8
WordPress

WordPress Core 6.9 – 7.0.1 – Remote Code Execution via REST API Batch Request Route Confusion

WordPress Core is vulnerable to Remote Code Execution in all versions 6.9 to 7.0.1 via the REST API batch request endpoint (/wp-json/batch/v1). This is due to a route/validation desynchronization that allows a validated sub-request to be dispatched to…

Versions affectées

[6.9, 6.9.5), [7.0, 7.0.2)

Correctif

6.9.5, 7.0.2

Publication

17/07/2026

Les résultats proviennent de la base de vulnérabilités synchronisée sur ce site. Une absence de résultat ne garantit pas qu’un composant est exempt de faille.