{"resultsPerPage":51,"startIndex":0,"totalResults":51,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-10T11:05:28.357","vulnerabilities":[{"cve":{"id":"CVE-2026-17519","sourceIdentifier":"security@synology.com","published":"2026-08-10T06:16:42.693","lastModified":"2026-08-10T06:16:42.693","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: none"}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-12570","sourceIdentifier":"security@huntr.dev","published":"2026-08-10T07:16:44.370","lastModified":"2026-08-10T07:16:44.370","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving/saving_lib.py does not validate the shape or size of datasets, leading to unbounded memory allocation. A specially crafted .keras file can exploit this flaw to trigger an out-of-memory (OOM) condition, causing the process to be terminated (exit code 137). This issue bypasses the fix for CVE-2026-0897, which only addressed a similar vulnerability in KerasFileEditor. The attack vector includes poisoned models from public repositories or malicious model registries, posing a risk to machine learning pipelines that process untrusted models."}],"affected":[{"source":"security@huntr.dev","affectedData":[{"vendor":"keras-team","product":"keras-team/keras","versions":[{"version":"unspecified","lessThan":"3.12.3, 3.15.0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"security@huntr.dev","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}]},"weaknesses":[{"source":"security@huntr.dev","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://github.com/keras-team/keras/commit/4933ea4a5b3fcc24ceacdc276f5bb5dfbd06756c","source":"security@huntr.dev"},{"url":"https://huntr.com/bounties/a064f475-780a-409a-82f7-678512f27ad8","source":"security@huntr.dev"}]}},{"cve":{"id":"CVE-2026-12971","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:46.043","lastModified":"2026-08-10T07:16:46.043","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The LearnPress  WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"LearnPress","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.4.4","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/ef69bd9d-ec2a-4526-b2b9-51948fa76980/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-13133","sourceIdentifier":"dl_cve@linecorp.com","published":"2026-08-10T07:16:46.173","lastModified":"2026-08-10T07:16:46.173","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate System32 copy."}],"affected":[{"source":"dl_cve@linecorp.com","affectedData":[{"vendor":"LY Corporation","product":"LINE for Windows","defaultStatus":"affected","versions":[{"version":"26.4.0","lessThan":"*","versionType":"custom","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"dl_cve@linecorp.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"references":[{"url":"https://line.github.io/security-advisory-blog/CVE-2026-13133/","source":"dl_cve@linecorp.com"}]}},{"cve":{"id":"CVE-2026-13170","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:46.360","lastModified":"2026-08-10T07:16:46.360","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Eventin  WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Eventin","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.1.20","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/c7bdaa80-a446-4c72-be79-bfc5022a4eca/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-13600","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:46.473","lastModified":"2026-08-10T07:16:46.473","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-synchronization task. On server configurations where the scheduled task executes before the HTTP response is committed, an unauthenticated attacker who triggers the due task can receive the administrator's session cookie and gain administrator access without credentials."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"AutoNetTV Relay","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.0.14","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/2f69e28f-cc9f-422e-a014-662f3fddfad3/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-13701","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:46.597","lastModified":"2026-08-10T07:16:46.597","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it on the front end of the site, which could allow administrators (including those without the unfiltered_html capability, such as on multisite) to perform Stored Cross-Site Scripting attacks that execute in the context of any visitor viewing affected pages."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Advanced Excerpt","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.5","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/2710686c-055c-460c-8480-573e394f24d8/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14206","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:46.710","lastModified":"2026-08-10T07:16:46.710","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The HT Contact Form  WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"HT Contact Form","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.9.3","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/36ae857c-6812-46e0-a0e7-6c868108ef39/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14211","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:46.827","lastModified":"2026-08-10T07:16:46.827","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Booking for Appointments and Events Calendar  WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Booking for Appointments and Events Calendar","defaultStatus":"unaffected","versions":[{"version":"9.0","lessThan":"9.7","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/511d2d53-34c5-4457-bc25-6f9105b57825/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14237","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:46.937","lastModified":"2026-08-10T07:16:46.937","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The vitepos WordPress plugin before 3.6.0, Vitepos  WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"vitepos","defaultStatus":"unaffected","versions":[{"version":"3.4.0","lessThan":"3.6.0","versionType":"semver","status":"affected"}]},{"vendor":"Unknown","product":"Vitepos","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.5.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/7f1eb6ec-c4fb-4c0d-887d-1812a84e29c0/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14238","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:47.053","lastModified":"2026-08-10T07:16:47.053","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body before using it in a database query in one of its report endpoints, allowing users with administrator-level access to perform SQL injection."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"vitepos","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.6.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/d526b352-74a4-444c-a251-75468863b444/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14293","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:47.160","lastModified":"2026-08-10T07:16:47.160","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Autopay","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/99fa208c-1a6f-4379-847c-388b9cec349e/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14860","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:47.270","lastModified":"2026-08-10T07:16:47.270","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Podcast Player  WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing unauthenticated attackers to make the server issue requests to arbitrary hosts and read back responses that parse as RSS/XML."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Podcast Player","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"8.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/ea752266-9bff-4c36-91aa-9aca0232c7af/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14941","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:47.383","lastModified":"2026-08-10T07:16:47.383","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin before 5.116.0 options, and disclose store configuration."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Customer Reviews for WooCommerce","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.116.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/572ba4a2-1b51-4631-9c28-7cc3d44f0761/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-15047","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:47.493","lastModified":"2026-08-10T07:16:47.493","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The s2Member  WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS)."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"s2Member","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"260805","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/79e830c3-232b-4eff-8cf1-d25c5310984c/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-15229","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:47.607","lastModified":"2026-08-10T07:16:47.607","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Pinpoint Booking System  WordPress plugin through 2.9.9.6.9 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Pinpoint Booking System","defaultStatus":"unknown","versions":[{"version":"0","lessThanOrEqual":"2.9.9.6.9","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/be12c266-dee7-463d-ae71-9f7b7e0258ee/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-15237","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:47.720","lastModified":"2026-08-10T07:16:47.720","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"MotoPress Hotel Booking","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"6.2.3","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/b312a323-808c-497f-b67e-3b0acfcb8932/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-15238","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:47.830","lastModified":"2026-08-10T07:16:47.830","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"MotoPress Hotel Booking","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"6.2.3","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/7283a28a-7241-4b9e-8fc5-5b427191c80e/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16257","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:47.933","lastModified":"2026-08-10T07:16:47.933","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been configured, allowing them to create arbitrary posts and pages and to disclose author account and taxonomy information."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Arvow AI SEO Writer","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.5.4","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/89c32854-1cf1-4fe9-a6d0-6244be2dcc03/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16298","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:48.050","lastModified":"2026-08-10T07:16:48.050","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"FoodBoxBooker","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.0.7","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/d554361c-e6c7-4843-a9cc-005b08685a5b/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16299","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:48.163","lastModified":"2026-08-10T07:16:48.163","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Single Sign On For TNG","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.2.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/06532a5a-ad34-421e-81e3-b4e44e8023ab/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16949","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:48.273","lastModified":"2026-08-10T07:16:48.273","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Term Pages","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/3e07356a-5ac8-4d9f-bef2-65aaecbf1419/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16985","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:48.380","lastModified":"2026-08-10T07:16:48.380","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Squeeze  WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-update actions, allowing users with the upload_files capability (Author and above) to write an executable PHP file into the uploads directory and achieve remote code execution."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Squeeze","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.7.12","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/045a15f3-5750-4c4e-977d-e1283e3c967d/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-17010","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:48.493","lastModified":"2026-08-10T07:16:48.493","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before outputting them, allowing users with contributor-level access and above to inject stored Cross-Site Scripting payloads that execute in the browser of a higher-privileged user who reviews the content."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Saitama Addon Pack","defaultStatus":"unknown","versions":[{"version":"0","lessThanOrEqual":"1.0.8","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/1e760dbf-7efc-4511-9a05-2d1476eb3dfb/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-17012","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:48.600","lastModified":"2026-08-10T07:16:48.600","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Accept PayPal & Stripe with Subscriptions for WooCommerce","defaultStatus":"unknown","versions":[{"version":"0","lessThanOrEqual":"3.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/01cc2578-8bf8-4889-9e21-7b78cae074d7/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-17016","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:48.710","lastModified":"2026-08-10T07:16:48.710","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal Data Transfer feature is enabled."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Accept PayPal & Stripe with Subscriptions for WooCommerce","defaultStatus":"unknown","versions":[{"version":"0","lessThanOrEqual":"3.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/fb73461f-521a-401b-98d0-5f32272368b8/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-17018","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:48.813","lastModified":"2026-08-10T07:16:48.813","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of its REST API endpoints, allowing users with the Contributor role and above to read arbitrary post metadata (including that of other users' draft, pending, private, and password-protected posts) and arbitrary user metadata of any user, including administrators."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"CubeWP Framework","defaultStatus":"unknown","versions":[{"version":"0","lessThanOrEqual":"1.1.30","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/df87c8d0-b3f3-4995-ac95-d63544e71a32/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-17019","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:48.927","lastModified":"2026-08-10T07:16:48.927","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict who can upload them, allowing unauthenticated attackers to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting)."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"JetEngine","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.8.13.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/355ea90d-9fb3-4dc6-9676-48e5255fbc77/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-17020","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:49.040","lastModified":"2026-08-10T07:16:49.040","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Salon Booking System  WordPress plugin through 10.30.33 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Salon Booking System","defaultStatus":"unknown","versions":[{"version":"0","lessThanOrEqual":"10.30.33","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/6e7852e9-0acd-4a79-9240-b864b14459a3/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-17021","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:49.140","lastModified":"2026-08-10T07:16:49.140","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Salon Booking System  WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Salon Booking System","defaultStatus":"unknown","versions":[{"version":"0","lessThanOrEqual":"10.30.33","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/fbbfa907-3efd-4050-9651-d3836af062a9/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-17022","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:49.243","lastModified":"2026-08-10T07:16:49.243","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Salon Booking System  WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Salon Booking System","defaultStatus":"unknown","versions":[{"version":"0","lessThanOrEqual":"10.30.33","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/ddc84492-408b-477c-ac6c-b9ec96ccf223/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-17023","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:49.353","lastModified":"2026-08-10T07:16:49.353","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Salon Booking System  WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Salon Booking System","defaultStatus":"unknown","versions":[{"version":"0","lessThanOrEqual":"10.30.33","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/a116db0a-38ea-43e3-a9cd-991768ce3e07/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-17540","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:49.460","lastModified":"2026-08-10T07:16:49.460","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"File Manager","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"6.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/096cb7df-26a5-4f5f-bbec-725e063a2b75/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-17541","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:49.580","lastModified":"2026-08-10T07:16:49.580","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"File Manager","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"6.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/972bf72f-08c4-41ec-b6e9-2d6083d21734/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-17542","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:49.707","lastModified":"2026-08-10T07:16:49.707","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"File Manager","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"6.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/d17f3de9-b0f9-4bbd-8a57-18cda9d43d79/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-18030","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:49.830","lastModified":"2026-08-10T07:16:49.830","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one of its form actions, allowing unauthenticated attackers to set an arbitrary password for any user, including administrators, and take over their account.\n\nExploitation requires the site to have a form using the BricksForge WordPress plugin before 3.1.8.8's password reset action in its update mode. The server-side current-password verification option for that action is disabled by default, so the vulnerable state is the default one once the action is used."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"BricksForge","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.1.8.8","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/15463bda-fb39-4629-b96b-34b83191bab7/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-18200","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:49.937","lastModified":"2026-08-10T07:16:49.937","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including administrators."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"FoodBoxBooker","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.0.8","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/a5864653-4df6-4d8d-9f8a-ace7b0220342/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-18468","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:50.047","lastModified":"2026-08-10T07:16:50.047","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Login & Register Forms  WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently completed a reset verification, including an administrator."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Login & Register Forms","defaultStatus":"unaffected","versions":[{"version":"3.2.5","lessThan":"4.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/0b567954-4bcc-4e2a-a2b5-024175012a19/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-18469","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:50.160","lastModified":"2026-08-10T07:16:50.160","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Login & Register Forms  WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-derived value, keying both the verification code and the per-source attempt counter on client-controlled data, allowing unauthenticated attackers to reset the limit at will and brute-force the code to take over any account, including administrators, when the verification-code reset mode is enabled."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Login & Register Forms","defaultStatus":"unaffected","versions":[{"version":"3.2.5","lessThan":"4.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/be74144a-b45b-469f-8631-7fdca6d19a66/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-18470","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:50.270","lastModified":"2026-08-10T07:16:50.270","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Login & Register Forms  WordPress plugin before 4.0.2 does not verify that a password reset request comes from the account's owner, and does not adequately redact the address returned in its response, allowing unauthenticated users to obtain registered users' email addresses, including administrators'."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Login & Register Forms","defaultStatus":"unaffected","versions":[{"version":"3.0.0","lessThan":"4.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/589b7661-4a0d-4041-8c29-2819d8b1e402/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-18666","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:50.373","lastModified":"2026-08-10T07:16:50.373","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing users with a role as low as Subscriber to perform SQL injection and extract arbitrary data from the database, including user password hashes."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Library Management System","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.6.7","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/7a9b3fff-f454-4764-ad60-0b273781f7b4/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-18786","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:50.487","lastModified":"2026-08-10T07:16:50.487","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The CheckView  WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView  WordPress plugin before 2.3.2-specific string, making it possible for unauthenticated attackers to bypass the REST nonce check and perform any REST action available to a logged-in administrator, such as creating a new administrator account, via a crafted link an administrator is tricked into opening."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"CheckView","defaultStatus":"unaffected","versions":[{"version":"2.0.29","lessThan":"2.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/f53e1706-e926-4a2c-a2a7-465b4ca5d102/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-18934","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:50.607","lastModified":"2026-08-10T07:16:50.607","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The RSS Aggregator by Feedzy  WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed to edit the import job named in the request, allowing users with author-level access and above to permanently delete the posts created by another user's import job, reset its deduplication and scheduling state, disable it, or clear its error log. One of the affected actions performs no object-type check either, so arbitrary posts and pages can also be unpublished regardless of who owns them."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"RSS Aggregator by Feedzy","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.2.6","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/f87c5a11-59a1-47cc-bc1c-d12108b510ab/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-18946","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:50.720","lastModified":"2026-08-10T07:16:50.720","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticated attackers to enumerate and download files submitted by other users."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Contact Form to Any API","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.0.7","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/fa13ebbb-8eea-492d-8f59-58228efb94d8/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-18960","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:50.830","lastModified":"2026-08-10T07:16:50.830","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Block User Account","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/c80abded-9f0e-4e44-8c8a-b0d1bc1b16d0/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-19049","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:50.937","lastModified":"2026-08-10T07:16:50.937","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the database and to delete the records the ProSolution WP Client WordPress plugin before 2.0.9 stores."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"ProSolution WP Client","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.0.9","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/5405c86c-1cf5-4123-9dea-864096d07520/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-19053","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:51.047","lastModified":"2026-08-10T07:16:51.047","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"ProSolution WP Client","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.0.6","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/c9bad349-d2d6-4b67-a107-818f25d9bf76/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-19074","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:51.157","lastModified":"2026-08-10T07:16:51.157","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vulnerable to unauthenticated sensitive information exposure via the AJAX action `acadp_public_custom_fields_listings`."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Advanced Classifieds & Directory Pro","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.4.3","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/657cb9f9-8be6-4841-b8a1-93d26a3d7984/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-19075","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:51.260","lastModified":"2026-08-10T07:16:51.260","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back to the requester."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"All-in-One Video Gallery","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.9.2","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/ad70162f-5514-41b8-84af-c79c2f881567/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-19077","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:51.377","lastModified":"2026-08-10T07:16:51.377","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Duplicate Post WordPress plugin before 1.5.5 access to permanently delete arbitrary posts on the site, including those belonging to other users."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Duplicate Post","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.5.5","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/dcced434-f7c0-4e19-b3cb-8196f6636aa3/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-19089","sourceIdentifier":"contact@wpscan.com","published":"2026-08-10T07:16:51.490","lastModified":"2026-08-10T07:16:51.490","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on servers that do not honour the directory's access rules."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Product Input Fields for WooCommerce","defaultStatus":"unaffected","versions":[{"version":"2.0.0","lessThan":"2.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/c5728a31-de92-40df-ab19-aec4db84ba21/","source":"contact@wpscan.com"}]}}]}