CVE-2026-97317
Description détaillée
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured.
Références et Patchs
Dernières Vulnérabilités
CVE-2026-97219
The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying.
CVE-2026-93698
Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
CVE-2026-93697
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
