Known Vulnerabilities for Wordpress Rest Api Authentication by Miniorange
Listed below are 1 of the newest known vulnerabilities associated with "Wordpress Rest Api Authentication" by "Miniorange".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-15335 json | The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form |
Not Provided | 2026-07-11 | 2026-07-14 |
| CVE-2026-15291 json | The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all ver... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-14262 json | The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass... | Not Provided | 2026-07-11 | 2026-07-13 |
| CVE-2026-10580 json | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Ac... | Not Provided | 2026-06-05 | 2026-06-05 |
| CVE-2026-9180 json | The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in a... | Not Provided | 2026-07-03 | 2026-07-06 |
| CVE-2026-9178 json | The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. ... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-9175 json | The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorization ... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-8293 json | The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-f... | Not Provided | 2026-06-02 | 2026-06-02 |
| CVE-2026-8198 json | The Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity plugin for WordPress is vulnerable to Authen... | Not Provided | 2026-05-09 | 2026-05-09 |
| CVE-2026-6937 json | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missin... | Not Provided | 2026-05-28 | 2026-05-28 |