Base locale WP Commander

Vulnérabilités WordPress connues

Recherchez une extension, un thème, une version de WordPress ou une référence CVE dans la base synchronisée localement.

37 748 vulnérabilités indexées · 44 218 plages de versions · mise à jour le 22/07/2026 à 02:19

41 069 résultats

Page 2 sur 3423

CVE-2026-60137 Élevée · 7,5
WordPress

WordPress Core 6.8 – 7.0.1 – Unauthenticated SQL Injection via author__not_in Parameter

WordPress Core is vulnerable to generic SQL Injection via the 'author__not_in' parameter in versions 6.8 – 7.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

Versions affectées

[6.8, 6.8.5), [6.9, 6.9.5), [7.0, 7.0.2)

Correctif

6.8.6, 6.9.5, 7.0.2

Publication

17/07/2026

CVE-2026-9656 Moyenne · 4,3
HubSpot All-In-One Marketing – Forms, Popups, Live Chat

HubSpot All-In-One Marketing <= 11.3.62 – Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Localized Script

The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.62 via the wp_localize_script() / window.leadinConfig JavaScript object. This makes it possible for…

Versions affectées

*-11.3.62

Correctif

11.3.64

Publication

16/07/2026

CVE-2026-14503 Moyenne · 6,5
pCloud WP Backup

pCloud WP Backup <= 2.0.3 – Missing Authorization on the 'start_backup' AJAX Method to Authenticated (Subscriber+) Arbitrary File Read

The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3 via the wp2pcl_ajax_process_request_inner. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract…

Versions affectées

*-2.0.3

Correctif

2.0.4

Publication

16/07/2026

CVE-2026-15759 Moyenne · 6,4
ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form

ChatHelp <= 3.5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes

The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes in all versions up to, and including, 3.5.1…

Versions affectées

*-3.5.1

Correctif

3.5.2

Publication

16/07/2026

CVE-2026-13765 Élevée · 7,5
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

LearnPress <= 4.4.1 – Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated…

Versions affectées

*-4.4.1

Correctif

4.4.2

Publication

16/07/2026

CVE-2026-15349 Moyenne · 4,3
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Company Location Creation via wp_ajax_erp-company-location AJAX Handler

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.17.6. This is due to the plugin not properly verifying that a…

Versions affectées

*-1.17.6

Correctif

1.17.7

Publication

16/07/2026

CVE-2026-13352 Élevée · 8,8
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 – Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function.…

Versions affectées

*-4.16.18

Correctif

4.16.19

Publication

16/07/2026

CVE-2026-15161 Moyenne · 6,4
Ninja Forms – Excel Export

Ninja Forms – Excel Export <= 3.3.6 – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'filter' Parameter

The Ninja Forms – Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.6. This is due to the save_filter() AJAX handler storing the raw $_POST['filter'] array into a WordPress…

Versions affectées

*-3.3.6

Correctif

3.3.7

Publication

16/07/2026

CVE-2026-15457 Moyenne · 4,9
Kirki – Freeform Page Builder, Website Builder & Customizer

Kirki <= 6.0.13 – Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameter

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.0.13 via the 'family' parameter. This makes it possible for authenticated attackers, with…

Versions affectées

*-6.0.13

Correctif

6.0.14

Publication

16/07/2026

CVE-2026-8616 Moyenne · 5,3
Fense Proxy & VPN Blocker

Fense Proxy & VPN Blocker <= 3.0.1 – Missing Authorization to Unauthenticated Plugin Option/Transient Deletion via fense_bpvt_save_settings AJAX Action

The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including, 3.0.1. The…

Versions affectées

*-3.0.1

Correctif

3.0.2

Publication

16/07/2026

CVE-2026-15395 Élevée · 7,2
Kali Forms , Contact Form & Drag-and-Drop Builder

Kali Forms <= 2.4.18 – Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value

The Kali Forms , Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping.…

Versions affectées

*-2.4.18

Correctif

2.4.19

Publication

16/07/2026

Les résultats proviennent de la base de vulnérabilités synchronisée sur ce site. Une absence de résultat ne garantit pas qu’un composant est exempt de faille.