Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total472
Critical34
High97
Medium322
Reset
Showing 1-20 of 472 records
Threat Entry Updated 2026-07-21

CVE-2026-8082 - Before 3 Plugin

The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowing unauthenticated attackers to perform time-based blind SQL injection on stores running this bpost-shipping-platform WordPress plugin before 3.2.3.

PLUGIN Before 3

CVE-2026-8082

HIGH CVSS 7.5 2026-07-21
Threat Entry Updated 2026-07-21

CVE-2026-14184 - Before 3 Plugin

The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated users with subscriber-level access to read and modify other users' lesson notes and mark other users' lesson content as completed.

PLUGIN Before 3

CVE-2026-14184

UNKNOWN CVSS 0.0 2026-07-21
Threat Entry Updated 2026-07-21

CVE-2026-13694 - Before 3 Plugin

The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's configured workflow actions such as notification emails and integrations.

PLUGIN Before 3

CVE-2026-13694

UNKNOWN CVSS 0.0 2026-07-21
Threat Entry Updated 2026-07-21

CVE-2026-13693 - Before 3 Plugin

The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a notification email, allowing unauthenticated attackers to read arbitrary server files such as the WordPress configuration file.

PLUGIN Before 3

CVE-2026-13693

UNKNOWN CVSS 0.0 2026-07-21
Threat Entry Updated 2026-07-17

CVE-2026-12393 - Before 3 Plugin

The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing any authenticated user, such as a Subscriber or Customer, to cancel and void other customers' booking orders.

PLUGIN Before 3

CVE-2026-12393

MEDIUM CVSS 5.4 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-11575 - Before 3 Plugin

The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so the expected signature reduces to an unkeyed hash of the request body that anyone can compute. This allows unauthenticated attackers to forge a payment-success notification and mark unpaid WooCommerce orders as paid without any payment being made.

PLUGIN Before 3

CVE-2026-11575

HIGH CVSS 7.5 2026-07-17
Threat Entry Updated 2026-07-16

CVE-2026-12978 - Before 3 Plugin

The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX actions, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against logged-in users who open a crafted page. The affected action is only registered when the Divi /builder is active.

PLUGIN Before 3

CVE-2026-12978

HIGH CVSS 7.1 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-12979 - Before 3 Plugin

The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator privileges to delete arbitrary .json files outside the intended directory through path traversal, which can disable other FunnelKit WordPress plugin before 3.15.0.6 or (denial of service).

PLUGIN Before 3

CVE-2026-12979

MEDIUM CVSS 5.5 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-12510 - Before 3 Plugin

The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their conversation records when the discussions feature is enabled.

PLUGIN Before 3

CVE-2026-12510

MEDIUM CVSS 5.9 2026-07-16
Threat Entry Updated 2026-07-15

CVE-2026-12512 - Before 3 Plugin

The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform UNION-based SQL injection and read arbitrary data from the database, including password hashes.

PLUGIN Before 3

CVE-2026-12512

HIGH CVSS 8.6 2026-07-15
Threat Entry Updated 2026-07-14

CVE-2026-12988 - Before 3 Plugin

The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the user, allowing an attacker who has obtained a user's credentials to redirect the setup verification code to an attacker-controlled email address and take over the account.

PLUGIN Before 3

CVE-2026-12988

MEDIUM CVSS 6.4 2026-07-14
Threat Entry Updated 2026-07-14

CVE-2026-12511 - Before 3 Plugin

The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server via path traversal.

PLUGIN Before 3

CVE-2026-12511

HIGH CVSS 8.1 2026-07-14
Threat Entry Updated 2026-07-13

CVE-2026-12582 - Before 3 Plugin

The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection and extract arbitrary data from the database, including user password hashes.

PLUGIN Before 3

CVE-2026-12582

HIGH CVSS 8.6 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-12275 - Before 3 Plugin

The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it enforces in its core course handler, allowing authenticated users with subscriber-level access to enroll in paid or private courses without authorization, read private course content, and mark arbitrary courses as completed, on sites where the Droip or Kirki integration is active.

PLUGIN Before 3

CVE-2026-12275

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-12274 - Before 3 Plugin

The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post before overwriting it in one of its content-builder save handlers, authorizing the request only against an unrelated identifier, allowing authenticated users with instructor-level access to overwrite and take over any post or page on the site, including those owned by administrators.

PLUGIN Before 3

CVE-2026-12274

MEDIUM CVSS 6.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-12271 - Before 3 Plugin

The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to it, allowing authenticated users with subscriber-level access and above to modify and force-complete other students' quiz attempts, overwriting their recorded marks and pass/fail result.

PLUGIN Before 3

CVE-2026-12271

MEDIUM CVSS 5.4 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-12273 - Before 3 Plugin

The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creating a comment in one of its handlers, and stores the comment pre-approved, allowing authenticated users with subscriber-level access and above to post auto-approved comments containing arbitrary HTML and links on any content across the site, bypassing the comment moderation queue.

PLUGIN Before 3

CVE-2026-12273

MEDIUM CVSS 4.3 2026-07-13
Threat Entry Updated 2026-07-09

CVE-2026-12270 - Before 3 Plugin

The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belonging to its onboarding assistant: the capability check is only applied when an attacker-controllable request header holds a specific value, so it can be bypassed by omitting or changing that header. This makes it possible for unauthenticated attackers to read onboarding status information, modify the related Everest Forms WordPress plugin before 3.5.0 options, and trigger an email from the site to an arbitrary address.

PLUGIN Before 3

CVE-2026-12270

MEDIUM CVSS 6.5 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-11571 - Before 3 Plugin

The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission records via predictable, enumerable filenames.

PLUGIN Before 3

CVE-2026-11571

HIGH CVSS 7.5 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-11869 - Before 3 Plugin

The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject access request feature, allowing unauthenticated attackers to generate and download the full personal-data export (including name, postal address, phone number, email, and comment content) of any user, customer, or commenter by supplying their email address.

PLUGIN Before 3

CVE-2026-11869

MEDIUM CVSS 5.3 2026-07-09
Scroll to top