Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45464 risultati

VulnerabilitàAlta
CVE-2026-90985 - WPC Smart Compare for WooCommerce < 6.6.1 - Unauthenticated Password-Protected Product Description Disclosure via woosc_load

CVE ID :CVE-2026-90985 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection when returning product content through its comparison handler, allowing unauthenticated users to read the description of password-protected products. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-91073 - Subscribe Forms 1.4.1 - 1.6.2 - Author+ Stored XSS via Attention Effect Form Setting

CVE ID :CVE-2026-91073 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who views a page embedding the form, including logged-out visitors and administrators. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-89331 - FluentBoards 1.95 - 2.0.15 - Unauthenticated Board Member Email Address Disclosure via Public Board Endpoints

CVE ID :CVE-2026-89331 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose the email addresses of a shared board's members, typically including administrators. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-91077 - Event Booking Manager for WooCommerce 5.3.6 - 5.7.2 - Contributor+ Unpublished Event Disclosure via mpwem_load_event_list

CVE ID :CVE-2026-91077 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to read, so users with contributor-level access and above can retrieve other authors' private, draft and trashed events, together with event detail the standard listing does not show them. This discloses private events and their content that WordPress withholds from users lacking the read_private_posts capability. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-90951 - Paid Member Subscriptions < 3.1.0 - Unauthenticated In-Flight Checkout State Deletion via pms_process_payment

CVE ID :CVE-2026-90951 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that member's checkout state. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-87069 - Forminator Forms < 1.57.2.1 - Subscriber+ Form Stripe Field Migration via migrate_stripe

CVE ID :CVE-2026-87069 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction of one of its admin screens, and that construction happens on every wp-admin request for any logged-in user. Any authenticated user, including a Subscriber with no permissions in the Forminator Forms WordPress plugin before 1.57.2.1, can therefore rewrite the saved field configuration of any form on the site, including a live payment form. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-86842 - Real3D Flipbook Lite < 5.4 - Author+ Content Deletion and Stored XSS via Global Settings Overwrite

CVE ID :CVE-2026-86842 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flipbook management actions, allowing users with Author-level access and above to delete other users' flipbook content and overwrite administrator-only global settings, which can be leveraged to store JavaScript that executes in the context of any visitor or administrator viewing the site. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-87074 - Forminator Forms < 1.57.2.1 - Unauthenticated Arbitrary Recipient Email Sending with Attacker-Controlled Link

CVE ID :CVE-2026-87074 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail configuration to any address, carrying a link of their choosing inside the site's own template. The token that authorises the send is handed to the anonymous caller by the Forminator Forms WordPress plugin before 1.57.2.1 itself and can be replayed without limit. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-86608 - WP Recipe Maker 9.8.0 - 10.8.1 - Unauthenticated DoS via Unbounded User Meta Insertion

CVE ID :CVE-2026-86608 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what that route stores, allowing unauthenticated users to write unlimited data into any user's metadata and to permanently prevent that account, including an administrator's, from loading. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-86783 - PostX < 5.0.41 - Unauthenticated Custom Field Key Disclosure via REST API

CVE ID :CVE-2026-86783 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose the custom field key names of arbitrary posts, including private, draft, pending, scheduled and password-protected posts. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-86785 - Social Commerce for WooCommerce <= 2.5.4 - Unauthenticated Plugin Option and Product Sync Status Update

CVE ID :CVE-2026-86785 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its REST API endpoints, allowing unauthenticated users to update Social Commerce for WooCommerce WordPress plugin through 2.5.4 configuration and product synchronisation state. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-87979 - Paymob for WooCommerce < 4.1.14 - Unauthenticated Saved Card Token Write to Any User via Webhook

CVE ID :CVE-2026-87979 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch of its payment webhook, allowing unauthenticated attackers to write a card-token record to any user's account and to enumerate registered accounts. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026

Pagina 221 di 3789

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.