CVE-2026-12972
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX ac
CVSS
5.3
Medio
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Publicado: 20 jul 2026 · Última mod.: 21 jul 2026 · CWE-284
0.2%EPSS · 30 días0.3%
2026-08-102026-09-07
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-866725.3 MED—
———A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function of the file example.7z of the component Backup Handler. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.2hCVE-2026-819637.8 ALT—
———Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.1hCVE-2026-774878.8 ALT—
———Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.1hCVE-2026-730288.8 ALT—
———Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.1hCVE-2026-692828.8 ALT—
———Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.2hCVE-2026-692738.8 ALT—
———Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.1h