Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total466
Critical34
High95
Medium321
Reset
Showing 1-20 of 466 records
Threat Entry Updated 2026-07-16

CVE-2026-12978 - Before 3 Plugin

The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX actions, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against logged-in users who open a crafted page. The affected action is only registered when the Divi /builder is active.

PLUGIN Before 3

CVE-2026-12978

HIGH CVSS 7.1 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-12979 - Before 3 Plugin

The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator privileges to delete arbitrary .json files outside the intended directory through path traversal, which can disable other FunnelKit WordPress plugin before 3.15.0.6 or (denial of service).

PLUGIN Before 3

CVE-2026-12979

MEDIUM CVSS 5.5 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-12510 - Before 3 Plugin

The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their conversation records when the discussions feature is enabled.

PLUGIN Before 3

CVE-2026-12510

MEDIUM CVSS 5.9 2026-07-16
Threat Entry Updated 2026-07-15

CVE-2026-12512 - Before 3 Plugin

The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform UNION-based SQL injection and read arbitrary data from the database, including password hashes.

PLUGIN Before 3

CVE-2026-12512

HIGH CVSS 8.6 2026-07-15
Threat Entry Updated 2026-07-14

CVE-2026-12988 - Before 3 Plugin

The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the user, allowing an attacker who has obtained a user's credentials to redirect the setup verification code to an attacker-controlled email address and take over the account.

PLUGIN Before 3

CVE-2026-12988

MEDIUM CVSS 6.4 2026-07-14
Threat Entry Updated 2026-07-14

CVE-2026-12511 - Before 3 Plugin

The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server via path traversal.

PLUGIN Before 3

CVE-2026-12511

HIGH CVSS 8.1 2026-07-14
Threat Entry Updated 2026-07-13

CVE-2026-12582 - Before 3 Plugin

The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection and extract arbitrary data from the database, including user password hashes.

PLUGIN Before 3

CVE-2026-12582

HIGH CVSS 8.6 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-12275 - Before 3 Plugin

The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it enforces in its core course handler, allowing authenticated users with subscriber-level access to enroll in paid or private courses without authorization, read private course content, and mark arbitrary courses as completed, on sites where the Droip or Kirki integration is active.

PLUGIN Before 3

CVE-2026-12275

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-12274 - Before 3 Plugin

The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post before overwriting it in one of its content-builder save handlers, authorizing the request only against an unrelated identifier, allowing authenticated users with instructor-level access to overwrite and take over any post or page on the site, including those owned by administrators.

PLUGIN Before 3

CVE-2026-12274

MEDIUM CVSS 6.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-12271 - Before 3 Plugin

The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to it, allowing authenticated users with subscriber-level access and above to modify and force-complete other students' quiz attempts, overwriting their recorded marks and pass/fail result.

PLUGIN Before 3

CVE-2026-12271

MEDIUM CVSS 5.4 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-12273 - Before 3 Plugin

The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creating a comment in one of its handlers, and stores the comment pre-approved, allowing authenticated users with subscriber-level access and above to post auto-approved comments containing arbitrary HTML and links on any content across the site, bypassing the comment moderation queue.

PLUGIN Before 3

CVE-2026-12273

MEDIUM CVSS 4.3 2026-07-13
Threat Entry Updated 2026-07-09

CVE-2026-12270 - Before 3 Plugin

The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belonging to its onboarding assistant: the capability check is only applied when an attacker-controllable request header holds a specific value, so it can be bypassed by omitting or changing that header. This makes it possible for unauthenticated attackers to read onboarding status information, modify the related Everest Forms WordPress plugin before 3.5.0 options, and trigger an email from the site to an arbitrary address.

PLUGIN Before 3

CVE-2026-12270

MEDIUM CVSS 6.5 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-11571 - Before 3 Plugin

The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission records via predictable, enumerable filenames.

PLUGIN Before 3

CVE-2026-11571

HIGH CVSS 7.5 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-11869 - Before 3 Plugin

The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject access request feature, allowing unauthenticated attackers to generate and download the full personal-data export (including name, postal address, phone number, email, and comment content) of any user, customer, or commenter by supplying their email address.

PLUGIN Before 3

CVE-2026-11869

MEDIUM CVSS 5.3 2026-07-09
Threat Entry Updated 2026-06-26

CVE-2026-10835 - Before 3 Plugin

The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one of its AJAX actions before using it in a SQL statement, and fails to enforce authorisation on that action, allowing authenticated users with minimal permissions, such as subscribers, to perform SQL injection attacks.

PLUGIN Before 3

CVE-2026-10835

HIGH CVSS 7.7 2026-06-26
Threat Entry Updated 2026-06-26

CVE-2026-10823 - Before 3 Plugin

The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and does not validate a user-supplied query parameter, allowing unauthenticated attackers to retrieve the titles and content of private, draft, and other non-public posts.

PLUGIN Before 3

CVE-2026-10823

HIGH CVSS 7.5 2026-06-26
Threat Entry Updated 2026-06-25

CVE-2026-10735 - Before 3 Plugin

Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.

PLUGIN Before 3

CVE-2026-10735

HIGH CVSS 7.5 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-10749 - Before 3 Plugin

The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication, storing attacker-supplied serialized values without the WordPress meta API's double-serialization protection, allowing users with Contributor-level access and above to inject a PHP Object.

PLUGIN Before 3

CVE-2026-10749

HIGH CVSS 7.2 2026-06-24
Threat Entry Updated 2026-06-22

CVE-2026-8157 - Before 3 Plugin

The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a custom Vitepos WordPress plugin before 3.4.2 role to escalate privileges to administrator.

PLUGIN Before 3

CVE-2026-8157

HIGH CVSS 8.8 2026-06-22
Threat Entry Updated 2026-06-22

CVE-2026-10530 - Before 3 Plugin

The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token and activate an account without access to the associated email inbox.

PLUGIN Before 3

CVE-2026-10530

MEDIUM CVSS 5.3 2026-06-22
Scroll to top