|
4181
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Smart Custom Fields para WordPress es vulnerable al acceso no autorizado de datos debido a una comprobación de capacidad faltante en la función relational_posts_search() en todas las versio…
|
CWE-862
Missing Authorization
|
CVE-2026-4066
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4182
|
8.8 |
HIGH
Network
|
-
|
-
|
The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as well as insufficient file type validation in the upl…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-3533
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4183
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in itsourcecode sanitize or validate this input 1.0. This issue affects some unknown processing of the file /admin/subjects.php of the component Parameter Handler. This…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4614
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4184
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue determinada en itsourcecode sanitize or validate this input 1.0. Este problema afecta algún procesamiento desconocido del archivo /admin/subjects.php del componente Gestor de P…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4614
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4185
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in SourceCodester Online Catering Reservation 1.0. Impacted is an unknown function of the file /search.php. Such manipulation of the argument rcode leads to sql injecti…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4615
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4186
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Jupiter X Core para WordPress es vulnerable a cargas de archivos limitadas debido a la falta de autorización en la función import_popup_templates() así como a una validación insuficiente de…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-3533
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4187
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via the custom pricing formula eval() in the process_…
|
CWE-95
Eval Injection
|
CVE-2026-4001
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4188
|
9.8 |
CRITICAL
Network
|
-
|
-
|
El plugin Woocommerce Custom Product Addons Pro para WordPress es vulnerable a ejecución remota de código en todas las versiones hasta la 5.4.1, inclusive, a través de la fórmula de precios personali…
|
CWE-95
Eval Injection
|
CVE-2026-4001
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4189
|
8.1 |
HIGH
Network
|
-
|
-
|
The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and including, 28.1.5. This is due to the email confirmatio…
|
CWE-287
Improper Authentication
|
CVE-2026-4021
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4190
|
8.1 |
HIGH
Network
|
-
|
-
|
El plugin Contest Gallery para WordPress es vulnerable a una omisión de autenticación que conduce a la toma de control de la cuenta de administrador en todas las versiones hasta la 28.1.5, inclusive.…
|
CWE-287
Improper Authentication
|
CVE-2026-4021
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|