CVE-2026-78259 - WPLegalPages API Secret Disclosure and Account Disconnect via Unauthenticated REST API
Unauthenticated WPLegalPages <= 3.6.4 REST endpoints disclose API secrets and allow attackers to disconnect the connected account.
Unauthenticated WPLegalPages <= 3.6.4 REST endpoints disclose API secrets and allow attackers to disconnect the connected account.
Broken access control in Events Made Easy <= 3.0.67 lets unauthenticated attackers modify arbitrary person records through the public personal-information AJAX endpoint.
Broken authentication in Colissimo Officiel <= 2.9.0 exposes shipping-rate import/export actions to unauthenticated visitors via the shared admin-ajax dispatcher.
Broken access control in Newsletters <= 4.13 lets an unauthenticated attacker take over any subscriber's management account via a predictable md5(id) token.
Broken authentication in Melhor Envio <= 2.16.3 lets a low-privilege Subscriber read and overwrite the store's Melhor Envio API tokens.
Broken authentication in Masteriyo LMS 2.1.8 allows unauthenticated attackers to forge Lemon Squeezy webhooks and mark pending orders as paid.