Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total291
Critical15
High59
Medium208
Reset
Showing 1-20 of 291 records
Threat Entry Updated 2026-07-20

CVE-2026-8825 - Before 4 Plugin

The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators).

PLUGIN Before 4

CVE-2026-8825

MEDIUM CVSS 4.9 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12970 - Before 4 Plugin

The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a crafted link.

PLUGIN Before 4

CVE-2026-12970

HIGH CVSS 7.1 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-10755 - Before 4 Plugin

The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.

PLUGIN Before 4

CVE-2026-10755

LOW CVSS 2.7 2026-07-20
Threat Entry Updated 2026-07-16

CVE-2026-12525 - Before 4 Plugin

The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile, on sites where the Redux Framework WordPress plugin before 4.5.13's user-profile (Users extension) feature is enabled.

PLUGIN Before 4

CVE-2026-12525

HIGH CVSS 8.8 2026-07-16
Threat Entry Updated 2026-07-16

CVE-2026-11371 - Before 4 Plugin

The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the feature that generates it is exposed to unauthenticated users, allowing them to store a malicious payload via prompt injection that executes in the browser of any visitor who views the affected page, including administrators.

PLUGIN Before 4

CVE-2026-11371

MEDIUM CVSS 6.1 2026-07-16
Threat Entry Updated 2026-07-14

CVE-2026-12583 - Before 4 Plugin

The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress plugin before 4.15, write arbitrary files and execute code on the server.

PLUGIN Before 4

CVE-2026-12583

HIGH CVSS 8.1 2026-07-14
Threat Entry Updated 2026-07-06

CVE-2026-11855 - Before 4 Plugin

The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no signing secret is configured, nor escape a value taken from them before outputting it in an administrator notice, allowing unauthenticated attackers to inject arbitrary web scripts that execute in the context of a logged-in administrator.

PLUGIN Before 4

CVE-2026-11855

HIGH CVSS 8.8 2026-07-06
Threat Entry Updated 2026-07-02

CVE-2026-11781 - Before 4 Plugin

The Adminify WordPress plugin before 4.2.10 does not perform per-user read-capability checks on the results returned by one of its administration search features, allowing users with a low-privilege role (Contributor) to disclose non-public content that WordPress would not otherwise expose to them, such as other authors' unpublished post titles, pending comment content, the site's Adminify WordPress plugin before 4.2.10 inventory, and user account names.

PLUGIN Before 4

CVE-2026-11781

LOW CVSS 2.7 2026-07-02
Threat Entry Updated 2026-06-29

CVE-2026-10083 - Before 4 Plugin

The APCu Manager WordPress plugin before 4.5.0 does not escape APCu object-cache keys before rendering them in an admin-area page, leading to a Stored Cross-Site Scripting vulnerability. When a persistent object cache is enabled, cache keys derived from unsanitised user input (e.g. a transient name created by another APCu Manager WordPress plugin before 4.5.0 from an unauthenticated request) are output without escaping and execute arbitrary JavaScript in the session of an administrator viewing the page.

PLUGIN Before 4

CVE-2026-10083

HIGH CVSS 7.5 2026-06-29
Threat Entry Updated 2026-06-29

CVE-2026-10820 - Before 4 Plugin

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not verify that the user performing a subscription action owns the targeted subscription, allowing any authenticated user (Subscriber+) to cancel other users' active subscriptions via an Insecure Direct Object Reference.

PLUGIN Before 4

CVE-2026-10820

HIGH CVSS 8.1 2026-06-27
Threat Entry Updated 2026-06-25

CVE-2026-10735 - Before 4 Plugin

Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.

PLUGIN Before 4

CVE-2026-10735

HIGH CVSS 7.5 2026-06-24
Threat Entry Updated 2026-06-17

CVE-2026-8383 - Before 4 Plugin

The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allowing unauthenticated visitors to retrieve each returned user's roles, full capabilities map, extra capabilities, locale, and registration date via a crafted request

PLUGIN Before 4

CVE-2026-8383

MEDIUM CVSS 5.3 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-8981 - Before 4 Plugin

The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrators on multisite installations (or single-site installs with DISALLOW_UNFILTERED_HTML defined) to inject arbitrary JavaScript that executes for any visitor of pages embedding the affected block.

PLUGIN Before 4

CVE-2026-8981

LOW CVSS 3.5 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-7862 - Before 4 Plugin

The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not properly restrict access to its refund request handler, allowing unauthenticated attackers to initiate refunds against any WooCommerce order using the merchant's payment gateway credentials, and for applicable payment methods, to redirect refunded funds to an attacker-controlled bank account.

PLUGIN Before 4

CVE-2026-7862

HIGH CVSS 8.6 2026-05-28
Threat Entry Updated 2026-06-17

CVE-2026-6381 - Before 4 Plugin

The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks.

PLUGIN Before 4

CVE-2026-6381

HIGH CVSS 7.5 2026-05-18
Threat Entry Updated 2026-06-17

CVE-2026-4432 - Before 4 Plugin

The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist ownership in the save_title() AJAX handler before allowing wishlist renaming operations. The function only checks for a valid nonce, which is publicly exposed in the page source of the /wishlist/ page, making it possible for unauthenticated attackers to rename any wishlist belonging to any user on the site.

PLUGIN Before 4

CVE-2026-4432

MEDIUM CVSS 6.5 2026-04-10
Threat Entry Updated 2026-06-17

CVE-2026-1368 - Before 4 Plugin

The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve the site's Zoom SDK key.

PLUGIN Before 4

CVE-2026-1368

HIGH CVSS 7.5 2026-02-18
Threat Entry Updated 2026-01-08

CVE-2025-14719 - Before 4 Plugin

The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks

PLUGIN Before 4

CVE-2025-14719

MEDIUM CVSS 4.9 2026-01-07
Threat Entry Updated 2026-01-02

CVE-2025-13153 - Before 4 Plugin

The Logo Slider WordPress plugin before 4.9.0 does not validate and escape some of its slider options before outputting them back in the dashboard, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 4

CVE-2025-13153

MEDIUM CVSS 6.1 2026-01-02
Threat Entry Updated 2026-01-02

CVE-2025-14434 - Before 4 Plugin

The Ultimate Post Kit Addons for Elementor WordPress plugin before 4.0.16 exposes multiple AJAX “load more” endpoints such as upk_alex_grid_loadmore_posts without ensuring that posts to be displayed are published authentication. This allows an unauthenticated attacker to query arbitrary posts and retrieve rendered HTML content of private and unpublished ones.

PLUGIN Before 4

CVE-2025-14434

MEDIUM CVSS 5.3 2025-12-31
Scroll to top