Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 21-40 of 664 records
Threat Entry Updated 2026-06-29

CVE-2026-9676 - Before 2 Plugin

The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users with Subscriber-level access and above to modify the parent and menu order of arbitrary posts.

PLUGIN Before 2

CVE-2026-9676

MEDIUM CVSS 4.3 2026-06-29
Threat Entry Updated 2026-06-25

CVE-2026-10824 - Before 2 Plugin

The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress records.

PLUGIN Before 2

CVE-2026-10824

MEDIUM CVSS 6.5 2026-06-25
Threat Entry Updated 2026-06-25

CVE-2026-10531 - Before 2 Plugin

The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes before outputting them in a page, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2026-10531

MEDIUM CVSS 5.4 2026-06-24
Threat Entry Updated 2026-06-23

CVE-2026-8163 - Before 2 Plugin

The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vulnerability exploitable by authenticated users with Subscriber-level access and above.

PLUGIN Before 2

CVE-2026-8163

HIGH CVSS 8.8 2026-06-23
Threat Entry Updated 2026-06-23

CVE-2026-7842 - Before 2 Plugin

The Infility Global Infility Global WordPress plugin before 2.15.20 for WordPress does not sanitize or validate the orderby and order parameters in the import_list(), url_detail(), and file_detail() admin page callbacks before using them in SQL queries, allowing authenticated attackers with Editor-level access or higher to perform time-based blind SQL injection and extract sensitive data from the database. The ImportData module must be enabled via the Infility Global WordPress plugin before 2.15.20's module toggle page.

PLUGIN Before 2

CVE-2026-7842

MEDIUM CVSS 6.8 2026-06-23
Threat Entry Updated 2026-06-22

CVE-2026-9822 - Before 2 Plugin

The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, allowing authenticated users with Subscriber-level access to read other users' booking line items, enumerate active coupons, and read pricing data.

PLUGIN Before 2

CVE-2026-9822

MEDIUM CVSS 6.5 2026-06-19
Threat Entry Updated 2026-06-17

CVE-2026-8089 - Before 2 Plugin

The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing unauthenticated attackers to deliver Reflected Cross-Site Scripting against any authenticated user (including administrators) via a crafted URL.

PLUGIN Before 2

CVE-2026-8089

HIGH CVSS 7.1 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-5776 - Before 2 Plugin

The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user input, allowing unauthenticated attackers to perform Stored XSS attacks

PLUGIN Before 2

CVE-2026-5776

MEDIUM CVSS 6.1 2026-05-20
Threat Entry Updated 2026-06-17

CVE-2026-3220 - Before 2 Plugin

The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.

PLUGIN Before 2

CVE-2026-3220

HIGH CVSS 8.8 2026-05-18
Threat Entry Updated 2026-06-17

CVE-2026-1631 - Before 2 Plugin

The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is vulnerable to unauthorized modification of the Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4's license key due to a missing capability check on the 'actions' function. This makes it possible for subscribers and above delete the license key.

PLUGIN Before 2

CVE-2026-1631

MEDIUM CVSS 5.4 2026-05-18
Threat Entry Updated 2026-06-17

CVE-2026-5306 - Before 2 Plugin

The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks when the email encoder setting is enabled

PLUGIN Before 2

CVE-2026-5306

MEDIUM CVSS 5.4 2026-04-28
Threat Entry Updated 2026-06-17

CVE-2026-4512 - Before 2 Plugin

The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key setting before outputting it in a JavaScript string context via the grecaptcha_js() function. This allows administrators on multisite installations (who do not have the unfiltered_html capability) to inject arbitrary JavaScript that executes for all visitors to the WordPress login page.

PLUGIN Before 2

CVE-2026-4512

LOW CVSS 3.5 2026-04-23
Threat Entry Updated 2026-06-17

CVE-2026-4079 - Before 2 Plugin

The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queries, making it possible for attackers to conduct SQL Injection attacks against the dynamic filter functionality.

PLUGIN Before 2

CVE-2026-4079

MEDIUM CVSS 6.5 2026-04-07
Threat Entry Updated 2026-06-17

CVE-2026-1969 - Before 2 Plugin

The trx_addons WordPress plugin before 2.38.5 does not correctly validate file types in one of its AJAX action, allowing unauthenticated users to upload arbitrary file. This is due to an incorrect fix of CVE-2024-13448

PLUGIN Before 2

CVE-2026-1969

MEDIUM CVSS 5.3 2026-03-23
Threat Entry Updated 2026-06-17

CVE-2026-2631 - Before 2 Plugin

The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_token` without verification. This token is subsequently used for authentication in a protected endpoint that allows users to perform arbitrary WordPress `update_option()` operations. Attackers can use this to enable registartion and to set the default role as Administrator.

PLUGIN Before 2

CVE-2026-2631

CRITICAL CVSS 9.8 2026-03-11
Threat Entry Updated 2026-02-24

CVE-2025-15386 - Before 2 Plugin

The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved.

PLUGIN Before 2

CVE-2025-15386

HIGH CVSS 8.8 2026-02-24
Threat Entry Updated 2026-06-17

CVE-2026-0658 - Before 2 Plugin

The Five Star Restaurant Reservations WordPress plugin before 2.7.9 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting bookings via CSRF attacks.

PLUGIN Before 2

CVE-2026-0658

MEDIUM CVSS 4.3 2026-02-02
Threat Entry Updated 2026-01-29

CVE-2025-14975 - Before 2 Plugin

The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

PLUGIN Before 2

CVE-2025-14975

HIGH CVSS 8.1 2026-01-29
Threat Entry Updated 2026-01-08

CVE-2025-14719 - Before 2 Plugin

The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks

PLUGIN Before 2

CVE-2025-14719

MEDIUM CVSS 4.9 2026-01-07
Threat Entry Updated 2025-12-29

CVE-2025-13407 - Before 2 Plugin

The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.

PLUGIN Before 2

CVE-2025-13407

MEDIUM CVSS 6.8 2025-12-24
Scroll to top