CVE-2026-78259 - WPLegalPages API Secret Disclosure and Account Disconnect via Unauthenticated REST API
Unauthenticated WPLegalPages <= 3.6.4 REST endpoints disclose API secrets and allow attackers to disconnect the connected account.
Unauthenticated WPLegalPages <= 3.6.4 REST endpoints disclose API secrets and allow attackers to disconnect the connected account.
Broken access control in Events Made Easy <= 3.0.67 lets unauthenticated attackers modify arbitrary person records through the public personal-information AJAX endpoint.
Unauthenticated SQL injection in WPDM Premium Packages <= 6.2.0 exposes the public Mini Cart coupon REST endpoint to blind time-based database extraction.
Unauthenticated webhook forgery in Peach Payments Gateway <= 4.0.2 lets attackers mark pending WooCommerce orders as paid by submitting a forged successful payment result.