WAFPlanet

CVE Database - Low WAF Effectiveness

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

22304
Matching CVEs
15562
Critical
25943
High
66770
High WAF Coverage

CVE-2026-32543

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in CyberChimps Responsive Blocks responsive-block-editor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Blocks: from n/a through <= 2.2.0.

Missing Authorization
WAF: Low

CVE-2026-32487

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in raratheme Lawyer Landing Page lawyer-landing-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lawyer Landing Page: from n/a through <= 1.2.7.

Missing Authorization
WAF: Low

CVE-2026-32486

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in wptravelengine Travel Booking travel-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel Booking: from n/a through <= 1.3.9.

Missing Authorization
WAF: Low

CVE-2026-32461

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Really Simple Plugins Really Simple SSL really-simple-ssl allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Really Simple SSL: from n/a through <= 9.5.7.

Missing Authorization
WAF: Low

CVE-2026-32457

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Wombat Plugins Advanced Product Fields (Product Addons) for WooCommerce advanced-product-fields-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Product Fields (Product Addons) for WooCommerce: from n/a through <= 1.6.18.

Missing Authorization
WAF: Low

CVE-2026-32456

UNKNOWN
0.00 CVSS none

Cross-Site Request Forgery (CSRF) vulnerability in Janis Elsts Admin Menu Editor admin-menu-editor allows Cross Site Request Forgery.This issue affects Admin Menu Editor: from n/a through <= 1.14.1.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2026-32453

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in ThemeFusion Avada Core fusion-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Avada Core: from n/a through < 5.15.0.

Missing Authorization
WAF: Low

CVE-2026-32452

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in ThemeFusion Fusion Builder fusion-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fusion Builder: from n/a through < 3.15.0.

Missing Authorization
WAF: Low

CVE-2026-32451

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in ThemeFusion Fusion Builder fusion-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fusion Builder: from n/a through < 3.15.0.

Missing Authorization
WAF: Low

CVE-2026-32447

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Atarim: from n/a through <= 4.3.2.

Missing Authorization
WAF: Low

CVE-2026-32446

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n/a through <= 1.9.9.3.

Missing Authorization
WAF: Low

CVE-2026-32445

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n/a through <= 3.35.5.

Missing Authorization
WAF: Low

CVE-2026-32443

UNKNOWN
0.00 CVSS none

Cross-Site Request Forgery (CSRF) vulnerability in Josh Kohlbach Product Feed PRO for WooCommerce woo-product-feed-pro allows Cross Site Request Forgery.This issue affects Product Feed PRO for WooCommerce: from n/a through <= 13.5.2.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2026-32442

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in E2Pdf e2pdf e2pdf allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects e2pdf: from n/a through <= 1.28.15.

Missing Authorization
WAF: Low

CVE-2026-32440

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Ex-Themes WP Food wp-food allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Food: from n/a through < 2.7.1.

Missing Authorization
WAF: Low

CVE-2026-32439

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in WebGeniusLab BigHearts bighearts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BigHearts: from n/a through <= 3.1.14.

Missing Authorization
WAF: Low

CVE-2026-32438

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in vowelweb VW School Education vw-school-education allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW School Education: from n/a through <= 1.4.6.

Missing Authorization
WAF: Low

CVE-2026-32437

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in vowelweb VW Portfolio vw-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Portfolio: from n/a through <= 1.3.3.

Missing Authorization
WAF: Low

CVE-2026-32436

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in vowelweb VW Photography vw-photography allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Photography: from n/a through <= 1.3.8.

Missing Authorization
WAF: Low

CVE-2026-32435

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in vowelweb VW Pet Shop vw-pet-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Pet Shop: from n/a through <= 1.4.7.

Missing Authorization
WAF: Low

CVE-2026-32434

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in vowelweb VW Fitness vw-fitness allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Fitness: from n/a through <= 4.3.4.

Missing Authorization
WAF: Low

CVE-2026-32432

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through <= 1.2.42.

Missing Authorization
WAF: Low

CVE-2026-32428

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Ays Pro Popup Like box ays-facebook-popup-likebox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Like box: from n/a through <= 3.7.7.

Missing Authorization
WAF: Low

CVE-2026-32427

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in vowelweb VW Education Lite vw-education-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Education Lite: from n/a through <= 2.2.0.

Missing Authorization
WAF: Low

CVE-2026-32425

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in linknacional Payment Gateway Pix For GiveWP payment-gateway-pix-for-givewp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Gateway Pix For GiveWP: from n/a through <= 2.2.3.

Missing Authorization
WAF: Low

CVE-2026-32423

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin and Site Enhancements (ASE): from n/a through <= 8.4.0.

Missing Authorization
WAF: Low

CVE-2026-32421

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Agile Logix Post Timeline post-timeline allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Timeline: from n/a through <= 2.4.1.

Missing Authorization
WAF: Low

CVE-2026-32420

UNKNOWN
0.00 CVSS none

Cross-Site Request Forgery (CSRF) vulnerability in Ruben Garcia GamiPress gamipress allows Cross Site Request Forgery.This issue affects GamiPress: from n/a through <= 7.6.6.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2026-32417

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in wppochipp Pochipp pochipp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pochipp: from n/a through < 1.18.9.

Missing Authorization
WAF: Low

CVE-2026-32416

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in bPlugins PDF Poster pdf-poster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF Poster: from n/a through <= 2.4.0.

Missing Authorization
WAF: Low

CVE-2026-32413

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Maciej Bis Permalink Manager Lite permalink-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Permalink Manager Lite: from n/a through < 2.5.3.

Missing Authorization
WAF: Low

CVE-2026-32410

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in WBW Plugins WBW Currency Switcher for WooCommerce woo-currency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WBW Currency Switcher for WooCommerce: from n/a through <= 2.2.5.

Missing Authorization
WAF: Low

CVE-2026-32409

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Forminator: from n/a through <= 1.50.2.

Missing Authorization
WAF: Low

CVE-2026-32408

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in themefusecom Brizy brizy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brizy: from n/a through <= 2.7.23.

Missing Authorization
WAF: Low

CVE-2026-32407

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in WPClever WPC Smart Wishlist for WooCommerce woo-smart-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPC Smart Wishlist for WooCommerce: from n/a through <= 5.0.8.

Missing Authorization
WAF: Low

CVE-2026-32406

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in WPClever WPC Product Bundles for WooCommerce woo-product-bundle allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPC Product Bundles for WooCommerce: from n/a through <= 8.4.5.

Missing Authorization
WAF: Low

CVE-2026-32404

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Studio99 Studio99 WP Monitor studio99-wp-monitor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Studio99 WP Monitor: from n/a through <= 1.0.3.

Missing Authorization
WAF: Low

CVE-2026-32402

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Ays Pro Image Slider by Ays ays-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Slider by Ays: from n/a through <= 2.7.1.

Missing Authorization
WAF: Low

CVE-2026-32397

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in YMC Filter & Grids ymc-smart-filter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filter & Grids: from n/a through <= 3.5.1.

Missing Authorization
WAF: Low

CVE-2026-32396

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through <= 5.0.13.

Missing Authorization
WAF: Low

CVE-2026-32395

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Xpro Xpro Addons For Beaver Builder &#8211; Lite xpro-addons-beaver-builder-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Xpro Addons For Beaver Builder &#8211; Lite: from n/a through <= 1.5.6.

Missing Authorization
WAF: Low

CVE-2026-32394

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Capabilities: from n/a through <= 2.31.0.

Missing Authorization
WAF: Low

CVE-2026-32391

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in linethemes SmartFix smartfix allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SmartFix: from n/a through < 1.2.4.

Missing Authorization
WAF: Low

CVE-2026-32390

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in linethemes Nanosoft nanosoft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nanosoft: from n/a through < 1.3.2.

Missing Authorization
WAF: Low

CVE-2026-32388

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in linethemes GLB glb allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GLB: from n/a through <= 1.2.2.

Missing Authorization
WAF: Low

CVE-2026-32387

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Noor Alam Checkout for PayPal checkout-for-paypal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Checkout for PayPal: from n/a through <= 1.0.46.

Missing Authorization
WAF: Low

CVE-2026-32386

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in EnvoThemes Envo Extra envo-extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Envo Extra: from n/a through <= 1.9.13.

Missing Authorization
WAF: Low

CVE-2026-32385

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RegistrationMagic: from n/a through <= 6.0.7.6.

Missing Authorization
WAF: Low

CVE-2026-32383

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in raratheme Ridhi ridhi allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ridhi: from n/a through <= 1.1.2.

Missing Authorization
WAF: Low

CVE-2026-32382

UNKNOWN
0.00 CVSS none

Missing Authorization vulnerability in raratheme Digital Download digital-download allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Digital Download: from n/a through <= 1.1.4.

Missing Authorization
WAF: Low
Page 4 of 447 (22304 CVEs)