Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 1-20 of 837 records
Threat Entry Updated 2026-07-21

CVE-2026-11767 - Before 1 Plugin

The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the admin dashboard, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks that execute when a logged-in administrator views the form submissions.

PLUGIN Before 1

CVE-2026-11767

UNKNOWN CVSS 0.0 2026-07-21
Threat Entry Updated 2026-07-21

CVE-2026-13142 - Before 1 Plugin

The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email address to brute-force the code and log in as that user, including an administrator, leading to full site takeover.

PLUGIN Before 1

CVE-2026-13142

HIGH CVSS 8.1 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-13156 - Before 1 Plugin

The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's SMTP configuration and deactivates the MailerSend WordPress plugin before 1.0.8, breaking the site's email delivery.

PLUGIN Before 1

CVE-2026-13156

MEDIUM CVSS 5.4 2026-07-20
Threat Entry Updated 2026-07-17

CVE-2026-9810 - Before 1 Plugin

The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileged MCP tools as an administrator, including arbitrary user creation and role escalation.

PLUGIN Before 1

CVE-2026-9810

CRITICAL CVSS 9.8 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-13402 - Before 1 Plugin

The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft Elementor templates linked from non-public navigation menu items.

PLUGIN Before 1

CVE-2026-13402

MEDIUM CVSS 5.3 2026-07-17
Threat Entry Updated 2026-07-16

CVE-2026-12869 - Before 1 Plugin

The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for its dashboard template-import action (it allows any edit_posts user), so a Contributor can import a template containing an Elementor HTML widget configured to display site-wide, injecting JavaScript that executes in the session of any visitor or administrator who loads the site.

PLUGIN Before 1

CVE-2026-12869

MEDIUM CVSS 6.1 2026-07-16
Threat Entry Updated 2026-07-13

CVE-2026-12081 - Before 1 Plugin

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classes allowed when unserializing an attacker-supplied form-field value, allowing unauthenticated users to inject arbitrary PHP objects that are instantiated when an administrator views the stored entry. This is an incomplete fix of CVE-2025-7384 and CVE-2026-2599, whose deserialization paths were hardened while the entry-editor file-field path was missed.

PLUGIN Before 1

CVE-2026-12081

MEDIUM CVSS 5.0 2026-07-13
Threat Entry Updated 2026-07-10

CVE-2026-12276 - Before 1 Plugin

The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration is enabled on the site before creating an account through one of its unauthenticated AJAX actions, allowing unauthenticated attackers to register new accounts even when registration has been disabled site-wide.

PLUGIN Before 1

CVE-2026-12276

MEDIUM CVSS 5.3 2026-07-10
Threat Entry Updated 2026-07-09

CVE-2026-12517 - Before 1 Plugin

The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-info endpoint before fetching it, allowing anonymous users (the gating nonce is exposed on public pages carrying an embed) to make the site request internal and private-network URLs and read back the parsed page metadata. This is a Server-Side Request Forgery.

PLUGIN Before 1

CVE-2026-12517

MEDIUM CVSS 5.3 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-12516 - Before 1 Plugin

The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media-proxying endpoint, allowing anonymous users to make the site fetch arbitrary URLs, including internal and private-network addresses, and read back the response body. This results in a full-read Server-Side Request Forgery and open proxy.

PLUGIN Before 1

CVE-2026-12516

MEDIUM CVSS 5.3 2026-07-09
Threat Entry Updated 2026-07-06

CVE-2026-6382 - Before 1 Plugin

The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a shell command when processing image operations, allowing authenticated users to perform OS Command Injection. This requires the server to have the ImageMagick convert CLI available without either the PHP imagick or GD extensions.

PLUGIN Before 1

CVE-2026-6382

CRITICAL CVSS 9.1 2026-07-06
Threat Entry Updated 2026-07-06

CVE-2026-11962 - Before 1 Plugin

The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-management operations, allowing authenticated users who have been granted file-manager access — which its premium add-on can extend to sub-administrator roles — to upload arbitrary PHP files and achieve remote code execution. This is an incomplete fix of CVE-2024-7985, which only added file-type validation to the upload operation.

PLUGIN Before 1

CVE-2026-11962

HIGH CVSS 8.8 2026-07-06
Threat Entry Updated 2026-07-06

CVE-2026-10830 - Before 1 Plugin

The AllCoach WordPress plugin before 1.0.2 does not verify that an email address submitted to a public account-registration endpoint is not already associated with an existing user before overwriting that user's password, allowing unauthenticated attackers to reset the password of arbitrary accounts, including administrators, and take over the site.

PLUGIN Before 1

CVE-2026-10830

HIGH CVSS 8.8 2026-07-06
Threat Entry Updated 2026-07-01

CVE-2026-11568 - Before 1 Plugin

The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or post-status check before returning WooCommerce product data through a public AJAX action, allowing unauthenticated users to retrieve the data (title, price, weight, stock status, and configurator option pricing/SKUs) of private and draft, non-public products by supplying the product ID. WordPress post-visibility controls are bypassed.

PLUGIN Before 1

CVE-2026-11568

HIGH CVSS 7.5 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-10750 - Before 1 Plugin

The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after token authentication, allowing authenticated users with a low-privileged role such as Subscriber to read private content, enumerate all users and their roles, and create, modify, or delete content owned by other users.

PLUGIN Before 1

CVE-2026-10750

HIGH CVSS 8.1 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11562 - Before 1 Plugin

The WS Form LITE WordPress plugin before 1.11.8 does not have a capability check on one of its settings-update actions, allowing authenticated users with subscriber-level access and above to modify the WS Form LITE WordPress plugin before 1.11.8's settings.

PLUGIN Before 1

CVE-2026-11562

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-06-25

CVE-2026-5305 - Before 1 Plugin

The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks

PLUGIN Before 1

CVE-2026-5305

HIGH CVSS 8.8 2026-06-25
Threat Entry Updated 2026-06-25

CVE-2026-9702 - Before 1 Plugin

The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination to be updated, allowing unauthenticated attackers to silently redirect the shipping destination of any pending or processing order on the site.

PLUGIN Before 1

CVE-2026-9702

HIGH CVSS 7.5 2026-06-25
Threat Entry Updated 2026-06-25

CVE-2026-10753 - Before 1 Plugin

The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have been granted dashboard sharing access (such as Editors) to modify a site-wide Site Kit by Google WordPress plugin before 1.176.0 setting that should only be modifiable by administrators.

PLUGIN Before 1

CVE-2026-10753

LOW CVSS 2.7 2026-06-24
Threat Entry Updated 2026-06-22

CVE-2026-7859 - Before 1 Plugin

The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices.

PLUGIN Before 1

CVE-2026-7859

MEDIUM CVSS 5.3 2026-06-22
Scroll to top