CVE-2026-78259 - WPLegalPages API Secret Disclosure and Account Disconnect via Unauthenticated REST API
Unauthenticated WPLegalPages <= 3.6.4 REST endpoints disclose API secrets and allow attackers to disconnect the connected account.
Unauthenticated WPLegalPages <= 3.6.4 REST endpoints disclose API secrets and allow attackers to disconnect the connected account.
Broken access control in Events Made Easy <= 3.0.67 lets unauthenticated attackers modify arbitrary person records through the public personal-information AJAX endpoint.
Unauthenticated SQL injection in WPDM Premium Packages <= 6.2.0 exposes the public Mini Cart coupon REST endpoint to blind time-based database extraction.
Unauthenticated webhook forgery in Peach Payments Gateway <= 4.0.2 lets attackers mark pending WooCommerce orders as paid by submitting a forged successful payment result.
Stored XSS in reCAPTCHA for Asgaros Forum <= 1.1.0 lets a low-privilege Subscriber inject JavaScript through the reCAPTCHA site key rendered in the forum editor.
Broken authentication in Colissimo Officiel <= 2.9.0 exposes shipping-rate import/export actions to unauthenticated visitors via the shared admin-ajax dispatcher.
IDOR in SupportCandy <= 3.4.6 lets a low-privilege user reassign and download another user's private ticket attachments via the thread-creation endpoint.
Broken access control in Newsletters <= 4.13 lets an unauthenticated attacker take over any subscriber's management account via a predictable md5(id) token.
Broken authentication in Melhor Envio <= 2.16.3 lets a low-privilege Subscriber read and overwrite the store's Melhor Envio API tokens.
Broken authentication in Masteriyo LMS 2.1.8 allows unauthenticated attackers to forge Lemon Squeezy webhooks and mark pending orders as paid.