NVD CVEs — 本日公開 (9 件)
CVE-2026-56821 7.4 HIGH
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, letting an on-path at
CVE-2026-56822 7.4 HIGH
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. This allows the client's downstream handlers to send
CVE-2026-12144 8.8 HIGH
The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User:
CVE-2026-12938 6.4 MEDIUM
The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode in versions up to and including 4.15. This is due to insufficient input sanitization and output escaping in the posts_single() function which propagat
CVE-2026-12939 6.4 MEDIUM
The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletters_post_thumbnail) shortcodes in versions up to and including 4.15. This is due to insufficient input sanitization and output escaping in the post_thumb
CVE-2026-15735 6.4 MEDIUM
The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contribu
CVE-2026-17161 6.4 MEDIUM
The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'filterMobileText' Block Attribute in all versions up to, and including, 4.4.24 due to insufficient input sanitization and output escaping. This makes it possible for a
CVE-2026-17162 6.4 MEDIUM
The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'currentPostId' Block Attribute in all versions up to, and including, 4.4.24 due to insufficient input sanitization and output escaping. This makes it possible for auth
CVE-2026-17166 4.3 MEDIUM
The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action.
GitHub Security Advisories — 本日公開 (7 件)
GHSA-6p3r-44rr-gcj5
MEDIUM
The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event...
GHSA-wp8x-j7cp-hqvg
MEDIUM
The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable...
GHSA-x3c9-qfw8-8r9c
MEDIUM
The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
GHSA-5j37-75mq-f752
MEDIUM
The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
GHSA-fgx3-jj2q-3c9j
HIGH
The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all...
GHSA-prqm-g69w-ff97
MEDIUM
The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable...
GHSA-qmcf-q538-935f
MEDIUM
The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...