Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 1-20 of 664 records
Threat Entry Updated 2026-07-20

CVE-2026-9833 - Before 2 Plugin

The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters before reflecting it in the response body served with an HTML content type, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of a logged-in user with `edit_pages` capability (Editor or higher) who is tricked into following a crafted link.

PLUGIN Before 2

CVE-2026-9833

HIGH CVSS 7.1 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-10724 - Before 2 Plugin

The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the connected source.

PLUGIN Before 2

CVE-2026-10724

MEDIUM CVSS 4.8 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-10081 - Before 2 Plugin

The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malicious review on the targeted business's Google listing to deliver Stored XSS to any visitor (including administrators) of any WP page displaying that Place ID's reviews.

PLUGIN Before 2

CVE-2026-10081

HIGH CVSS 8.8 2026-07-20
Threat Entry Updated 2026-07-16

CVE-2026-12907 - Before 2 Plugin

The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions, allowing users with at least the Author role to create and activate a site-wide template that overrides the header, footer or other global areas displayed to all visitors, which is normally restricted to administrators.

PLUGIN Before 2

CVE-2026-12907

LOW CVSS 2.7 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-12906 - Before 2 Plugin

The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a request-supplied post identifier directly, allowing users with at least the Contributor role to read the titles of other users' private, draft, pending, scheduled and trashed posts.

PLUGIN Before 2

CVE-2026-12906

LOW CVSS 2.7 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-12492 - Before 2 Plugin

The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new accounts.

PLUGIN Before 2

CVE-2026-12492

CRITICAL CVSS 9.8 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-12395 - Before 2 Plugin

The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with a subscriber-level (self-registerable) account to perform SQL injection attacks.

PLUGIN Before 2

CVE-2026-12395

MEDIUM CVSS 6.5 2026-07-16
Threat Entry Updated 2026-07-15

CVE-2026-12281 - Before 2 Plugin

The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. On a deployment where untrusted client headers reach the application, an unauthenticated attacker can log in with forged identity headers and, when automatic account creation and the default administrator role mapping are enabled, create and sign in as a new administrator. Exploitation requires the non-default HTTP header attribute mode, an empty or absent spoof…

PLUGIN Before 2

CVE-2026-12281

HIGH CVSS 8.1 2026-07-15
Threat Entry Updated 2026-07-15

CVE-2026-11580 - Before 2 Plugin

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or above to duplicate any post (regardless of owner, post type, or status) into a published post they own and read its private post metadata, including secrets stored by other Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17.

PLUGIN Before 2

CVE-2026-11580

MEDIUM CVSS 5.5 2026-07-15
Threat Entry Updated 2026-07-15

CVE-2026-11579 - Before 2 Plugin

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a file-upload field, accepting uploads regardless of whether any such form exists, which allows unauthenticated users to upload files to the WordPress Media Library; the uploads are limited to WordPress's default-allowed MIME types, so this does not lead to code execution.

PLUGIN Before 2

CVE-2026-11579

MEDIUM CVSS 5.3 2026-07-15
Threat Entry Updated 2026-07-14

CVE-2026-11567 - Before 2 Plugin

The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms that use a dynamically-sourced (variable/hidden) payment amount, allowing unauthenticated users to underpay for the configured product or subscription. Forms using a fixed configured price are not affected.

PLUGIN Before 2

CVE-2026-11567

MEDIUM CVSS 5.9 2026-07-14
Threat Entry Updated 2026-07-13

CVE-2026-12396 - Before 2 Plugin

The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job moderation actions, allowing authenticated users with a subscriber-level (self-registerable) account to approve, feature, or reject arbitrary jobs, including those owned by other users.

PLUGIN Before 2

CVE-2026-12396

MEDIUM CVSS 5.4 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-12397 - Before 2 Plugin

The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email for a given job, allowing authenticated users with a subscriber-level (self-registerable) account to read other employers' private account email addresses by enumerating job identifiers.

PLUGIN Before 2

CVE-2026-12397

MEDIUM CVSS 4.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-10551 - Before 2 Plugin

The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.

PLUGIN Before 2

CVE-2026-10551

MEDIUM CVSS 6.1 2026-07-13
Threat Entry Updated 2026-07-06

CVE-2026-6382 - Before 2 Plugin

The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a shell command when processing image operations, allowing authenticated users to perform OS Command Injection. This requires the server to have the ImageMagick convert CLI available without either the PHP imagick or GD extensions.

PLUGIN Before 2

CVE-2026-6382

CRITICAL CVSS 9.1 2026-07-06
Threat Entry Updated 2026-07-06

CVE-2026-11766 - Before 2 Plugin

The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea profile fields before outputting it on user profiles, allowing authenticated users with Subscriber-level access and above to store JavaScript that executes when any user, including an administrator, views the affected profile.

PLUGIN Before 2

CVE-2026-11766

HIGH CVSS 8.0 2026-07-06
Threat Entry Updated 2026-07-01

CVE-2026-11794 - Before 2 Plugin

The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress role assigned when it creates a user from a public form submission, allowing unauthenticated visitors to create an administrator account when an active integration maps the user role to a public form field. This requires a specific, non-default multi-Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 configuration.

PLUGIN Before 2

CVE-2026-11794

HIGH CVSS 8.1 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11883 - Before 2 Plugin

The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authentication response, allowing an attacker who already knows a user's password to bypass the two-factor authentication requirement by submitting a malformed request.

PLUGIN Before 2

CVE-2026-11883

HIGH CVSS 7.2 2026-07-01
Threat Entry Updated 2026-06-30

CVE-2026-9576 - Before 2 Plugin

The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users with at least the Calendar Manager role to retrieve attendees' PII (name, email, phone, address, payment information) from calendar groups they do not own.

PLUGIN Before 2

CVE-2026-9576

MEDIUM CVSS 4.9 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-11581 - Before 2 Plugin

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's caption before outputting it as a column header on the administrator form-entries screen, allowing users with Contributor-level access or above to store JavaScript that executes in an administrator's session. A missing capability check in the Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13's post-duplication action additionally lets the Contributor publish the malicious form so an administrator renders it.

PLUGIN Before 2

CVE-2026-11581

MEDIUM CVSS 5.9 2026-06-30
Scroll to top