Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 21-40 of 837 records
Threat Entry Updated 2026-06-22

CVE-2026-6858 - Before 1 Plugin

The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator

PLUGIN Before 1

CVE-2026-6858

HIGH CVSS 7.1 2026-06-22
Threat Entry Updated 2026-06-17

CVE-2026-9278 - Before 1 Plugin

The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing it and using it as part of a client-side script execution, allowing authenticated users with Editor-level access and above to perform Stored Cross-Site Scripting attacks against any visitor of a page rendering the affected form, even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network).

PLUGIN Before 1

CVE-2026-9278

MEDIUM CVSS 5.4 2026-06-15
Threat Entry Updated 2026-06-17

CVE-2026-9061 - Before 1 Plugin

The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator WordPress plugin before 1.6.9 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network).

PLUGIN Before 1

CVE-2026-9061

LOW CVSS 3.5 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-9062 - Before 1 Plugin

The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from the server, including configuration files that contain database credentials and authentication keys.

PLUGIN Before 1

CVE-2026-9062

LOW CVSS 3.4 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-9067 - Before 1 Plugin

The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the endpoint's intended media type, allowing unauthenticated users to upload any file type accepted by WordPress's media library through endpoints that should only accept images or videos.

PLUGIN Before 1

CVE-2026-9067

CRITICAL CVSS 9.1 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-9060 - Before 1 Plugin

The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin before 1.6.6 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network where the super admin visits the page).

PLUGIN Before 1

CVE-2026-9060

LOW CVSS 3.5 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-4986 - Before 1 Plugin

The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.

PLUGIN Before 1

CVE-2026-4986

MEDIUM CVSS 5.3 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-4935 - Before 1 Plugin

The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before using it in a SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks.

PLUGIN Before 1

CVE-2026-4935

HIGH CVSS 8.6 2026-05-08
Threat Entry Updated 2026-06-17

CVE-2026-5335 - Before 1 Plugin

The Magic Export & Import WordPress plugin before 1.2.0 stores exported CSV files at a publicly accessible location, making it possible for any visitors to leak sensitive user information.

PLUGIN Before 1

CVE-2026-5335

MEDIUM CVSS 5.3 2026-05-04
Threat Entry Updated 2026-06-17

CVE-2026-1540 - Before 1 Plugin

The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file, which could allow an attacker with editor access to achieve Remote Code Execution by using a crafted header

PLUGIN Before 1

CVE-2026-1540

HIGH CVSS 7.2 2026-04-02
Threat Entry Updated 2026-06-17

CVE-2026-2687 - Before 1 Plugin

The Reading progressbar WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 1

CVE-2026-2687

MEDIUM CVSS 4.3 2026-03-12
Threat Entry Updated 2026-06-17

CVE-2026-1753 - Before 1 Plugin

The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).

PLUGIN Before 1

CVE-2026-1753

MEDIUM CVSS 6.8 2026-03-11
Threat Entry Updated 2026-06-17

CVE-2026-1508 - Before 1 Plugin

The Court Reservation WordPress plugin before 1.10.9 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete them via a CSRF attack

PLUGIN Before 1

CVE-2026-1508

MEDIUM CVSS 4.3 2026-03-10
Threat Entry Updated 2026-06-17

CVE-2026-2446 - Before 1 Plugin

The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress options (such as default_role etc) and create arbitrary admin users

PLUGIN Before 1

CVE-2026-2446

CRITICAL CVSS 9.8 2026-03-06
Threat Entry Updated 2026-06-17

CVE-2026-2025 - Before 1 Plugin

The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unauthenticated users to call it and retrieve the email addresses of users on the blog

PLUGIN Before 1

CVE-2026-2025

HIGH CVSS 7.5 2026-03-04
Threat Entry Updated 2025-12-15

CVE-2025-13355 - Before 1 Plugin

The URL Shortify WordPress plugin before 1.11.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Before 1

CVE-2025-13355

HIGH CVSS 7.1 2025-12-15
Threat Entry Updated 2025-12-15

CVE-2025-12684 - Before 1 Plugin

The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in the page, leading to a reflected cross site scripting, which could be used against high-privilege users such as admins.

PLUGIN Before 1

CVE-2025-12684

HIGH CVSS 7.1 2025-12-15
Threat Entry Updated 2025-12-15

CVE-2025-11363 - Before 1 Plugin

The Royal Addons for Elementor WordPress plugin before 1.7.1037 does not have proper authorisation, allowing unauthenticated users to upload media files via the wpr_addons_upload_file action.

PLUGIN Before 1

CVE-2025-11363

MEDIUM CVSS 5.3 2025-12-15
Threat Entry Updated 2026-01-09

CVE-2025-10684 - Before 1 Theme

The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX action, allowing any authenticated users, such as subscriber to activate arbitrary .

THEME Before 1

CVE-2025-10684

MEDIUM CVSS 4.3 2025-12-12
Threat Entry Updated 2025-12-02

CVE-2025-12630 - Before 1 Plugin

The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability check on its AJAX request handler, allowing users such as contributor to view site options.

PLUGIN Before 1

CVE-2025-12630

MEDIUM CVSS 4.9 2025-12-02
Scroll to top