Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total715
Critical47
High125
Medium518
Reset
Showing 1-20 of 715 records
Threat Entry Updated 2026-08-09

CVE-2026-18037 - Before 2 Plugin

The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.

PLUGIN Before 2

CVE-2026-18037

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-16992 - Before 2 Plugin

The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.

PLUGIN Before 2

CVE-2026-16992

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-09

CVE-2026-16988 - Before 2 Plugin

The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users to disclose the title and exact geographic coordinates of non-public (pending or draft) listings.

PLUGIN Before 2

CVE-2026-16988

UNKNOWN CVSS 0.0 2026-08-09
Threat Entry Updated 2026-08-07

CVE-2026-15211 - Before 2 Plugin

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed on the WooCommerce order-received flow: it captures a client-supplied token and marks the order paid whenever the capture status is COMPLETED, without comparing the captured amount to the order total. This allows an attacker (unauthenticated where guest checkout is enabled) to substitute an approved, uncaptured PayPal order token and have an expensive order marked paid without paying its price.

PLUGIN Before 2

CVE-2026-15211

MEDIUM CVSS 5.9 2026-08-07
Threat Entry Updated 2026-08-07

CVE-2026-15148 - Before 2 Plugin

The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the merchant, including other users' bookings.

PLUGIN Before 2

CVE-2026-15148

MEDIUM CVSS 5.3 2026-08-07
Threat Entry Updated 2026-08-07

CVE-2026-15215 - Before 2 Plugin

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin before 2.0.1, resulting in remote code execution.

PLUGIN Before 2

CVE-2026-15215

HIGH CVSS 8.8 2026-08-07
Threat Entry Updated 2026-08-07

CVE-2026-15245 - Before 2 Plugin

The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript context before echoing it into an inline script, allowing users with the contributor role and above to inject arbitrary JavaScript that executes in the browser of anyone viewing the affected content.

PLUGIN Before 2

CVE-2026-15245

MEDIUM CVSS 5.4 2026-08-07
Threat Entry Updated 2026-08-07

CVE-2026-15214 - Before 2 Plugin

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that subscription's ID.

PLUGIN Before 2

CVE-2026-15214

MEDIUM CVSS 4.3 2026-08-07
Threat Entry Updated 2026-08-07

CVE-2026-14205 - Before 2 Plugin

The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.

PLUGIN Before 2

CVE-2026-14205

CRITICAL CVSS 9.8 2026-08-07
Threat Entry Updated 2026-08-07

CVE-2026-14943 - Before 2 Plugin

The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors to bypass the sitewide password gate and read otherwise-protected content and account identifiers via the REST API. This re-introduces a previously-fixed issue (CVE-2024-0437), which was patched in 2.6.7 and regressed in 2.6.8.

PLUGIN Before 2

CVE-2026-14943

HIGH CVSS 7.5 2026-08-07
Threat Entry Updated 2026-08-07

CVE-2026-5336 - Before 2 Plugin

The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template rendering feature and exposes the viewing user's data to it, allowing users with a role as low as Contributor to disclose sensitive information, such as the session cookies of higher privileged users who view the affected content.

PLUGIN Before 2

CVE-2026-5336

MEDIUM CVSS 6.8 2026-08-06
Threat Entry Updated 2026-08-07

CVE-2026-16620 - Before 2 Plugin

The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in "Select" price mode, allowing an unauthenticated visitor to add such a product to the cart at an arbitrary value below the merchant-defined allowed prices and commit a real order at that price (revenue loss / underpriced orders). This is a distinct, unfixed vector from CVE-2025-12115, whose 2.2.0 fix only addressed applying a custom price to products where Name Your Price is disabled and left the Select-mode allowlist unenforced…

PLUGIN Before 2

CVE-2026-16620

HIGH CVSS 7.5 2026-08-06
Threat Entry Updated 2026-08-07

CVE-2026-15152 - Before 2 Plugin

The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to have their bookings marked as fully paid without any payment reaching the site owner.

PLUGIN Before 2

CVE-2026-15152

MEDIUM CVSS 5.3 2026-08-06
Threat Entry Updated 2026-08-07

CVE-2026-15149 - Before 2 Plugin

The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a booking, and relies on client-controlled cart data, allowing unauthenticated users to create confirmed reservations for free or at an arbitrarily reduced price.

PLUGIN Before 2

CVE-2026-15149

MEDIUM CVSS 5.3 2026-08-06
Threat Entry Updated 2026-08-07

CVE-2026-15147 - Before 2 Plugin

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated attackers to mark arbitrary pending reservations as paid and confirmed.

PLUGIN Before 2

CVE-2026-15147

MEDIUM CVSS 5.3 2026-08-06
Threat Entry Updated 2026-08-07

CVE-2026-13399 - Before 2 Plugin

The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments

PLUGIN Before 2

CVE-2026-13399

HIGH CVSS 7.5 2026-08-06
Threat Entry Updated 2026-08-07

CVE-2026-12901 - Before 2 Plugin

The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made.

PLUGIN Before 2

CVE-2026-12901

MEDIUM CVSS 5.9 2026-08-06
Threat Entry Updated 2026-08-06

CVE-2026-16065 - Before 2 Plugin

The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks.

PLUGIN Before 2

CVE-2026-16065

MEDIUM CVSS 6.5 2026-08-06
Threat Entry Updated 2026-08-05

CVE-2026-16968 - Before 2 Plugin

The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.

PLUGIN Before 2

CVE-2026-16968

MEDIUM CVSS 6.5 2026-08-05
Threat Entry Updated 2026-08-04

CVE-2026-16623 - Before 2 Plugin

The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, allowing a multisite subsite administrator (who holds the capability gating this action but is denied the capability that normally gates PHP file editing) to inject and execute arbitrary PHP code on the server.

PLUGIN Before 2

CVE-2026-16623

HIGH CVSS 8.0 2026-08-04
Scroll to top