Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

43850 risultati

VulnerabilitàAlta
CVE-2026-96532 - Testimonials Widget <= 4.0.4 - Unauthenticated Arbitrary Post Update

CVE ID :CVE-2026-96532 Published : Sept. 26, 2026, 7:17 a.m. | 3 hours, 12 minutes ago Description :The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-96526 - MCP Server for WordPress < 1.8.2 - Contributor+ Arbitrary Post Title Disclosure via workflows/run REST Route

CVE ID :CVE-2026-96526 Published : Sept. 26, 2026, 7:17 a.m. | 3 hours, 12 minutes ago Description :The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of its workflow REST routes, allowing users with the Contributor role to disclose the title and publication status of any post, page or custom post type, including other users' private, draft, pending and scheduled content. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-92411 - WP Delicious < 1.10.8 - Contributor+ Stored XSS via Recipe Block Tag Name

CVE ID :CVE-2026-92411 Published : Sept. 26, 2026, 7:17 a.m. | 3 hours, 12 minutes ago Description :The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied recipe block data before rendering it on the front end, allowing users with the Contributor role and above to inject arbitrary HTML tags, including script tags, which execute when the recipe page is viewed. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-96525 - MCP Server for WordPress < 1.8.2 - Contributor+ Workflow Modification and Deletion via Missing Ownership Check

CVE ID :CVE-2026-96525 Published : Sept. 26, 2026, 7:17 a.m. | 3 hours, 12 minutes ago Description :The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check on its workflow create, update and delete REST routes, allowing users with the Contributor role to modify, delete and create site-wide workflow configuration, including workflows created by administrators. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-96524 - MCP Server for WordPress < 1.8.2 - Administrator Account Creation via CSRF

CVE ID :CVE-2026-96524 Published : Sept. 26, 2026, 7:17 a.m. | 3 hours, 12 minutes ago Description :The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator account, by tricking a logged-in administrator into visiting a crafted page. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-96531 - Optimole 4.0.0 - 4.2.12 - Author+ Stored XSS via Video Player Block

CVE ID :CVE-2026-96531 Published : Sept. 26, 2026, 7:17 a.m. | 3 hours, 12 minutes ago Description :The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users with the Author role and above to store an event-handler attribute that executes scripts in the browser of any user, such as an administrator, who views the post. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàCritica
CVE-2026-18143 (CVSS 9.8)

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied filename directly as the destination for `move_uploaded_file()`. This makes it possible for unauthenticated attackers to upload executable files, such as PHP files, to a web-accessible temporary RFQ upload directory when a public quote rule with the multi-page popup flow is enabled.

NVD (NIST)1g fa
VulnerabilitàAlta
CVE-2026-18143 - Request a Quote for WooCommerce <= 2.9.2 - Unauthenticated Arbitrary File Upload via AJAX Popup Handler

CVE ID :CVE-2026-18143 Published : Sept. 26, 2026, 7:17 a.m. | 3 hours, 12 minutes ago Description :The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied filename directly as the destination for `move_uploaded_file()`. This makes it possible for unauthenticated attackers to upload executable files, such as PHP files, to a web-accessible temporary RFQ upload directory when a public quote rule with the multi-page popup flow is enabled. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-84095 - WP Review Slider Pro < 12.7.12 - Subscriber+ Stored XSS via Review Import

CVE ID :CVE-2026-84095 Published : Sept. 26, 2026, 7:17 a.m. | 3 hours, 12 minutes ago Description :The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to store arbitrary review content which is later output without escaping on public pages, leading to Stored Cross-Site Scripting. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-19708 - File Manager 7.2.2 - 8.0.4 - Unauthenticated Database Backup Disclosure

CVE ID :CVE-2026-19708 Published : Sept. 26, 2026, 7:17 a.m. | 3 hours, 12 minutes ago Description :The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a full database dump including every user's email address and password hash on servers that do not apply the directory's .htaccess file. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-89237 - Bluff Post <= 1.1.1 - Unauthenticated SQLi via 'table_name' and 'column_name' Parameters

CVE ID :CVE-2026-89237 Published : Sept. 26, 2026, 7:17 a.m. | 3 hours, 12 minutes ago Description :The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers in a SQL query, allowing unauthenticated attackers to append additional SQL and extract sensitive information from the database. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-84097 - WP Review Slider Pro < 12.7.12 - Subscriber+ SQLi via Stored Template Filter

CVE ID :CVE-2026-84097 Published : Sept. 26, 2026, 7:17 a.m. | 3 hours, 12 minutes ago Description :The wp-review-slider-pro WordPress plugin before 12.7.12 does not sanitize a value stored through one of its AJAX handlers, which lacks a capability check, before using it in a SQL statement, allowing any authenticated user, such as a subscriber, to perform SQL injection attacks whose results are then returned to unauthenticated visitors. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa

Pagina 18 di 3655

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.