Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total135
Critical12
High24
Medium97
Reset
Showing 1-20 of 135 records
Threat Entry Updated 2026-07-20

CVE-2026-13147 - Before 6 Plugin

The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).

PLUGIN Before 6

CVE-2026-13147

CRITICAL CVSS 9.1 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-13432 - Before 6 Plugin

The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher to deactivate the ThumbPress WordPress plugin before 6.2.2, disrupting the site's image-handling functionality.

PLUGIN Before 6

CVE-2026-13432

MEDIUM CVSS 5.4 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12723 - Before 6 Plugin

The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment moderation.

PLUGIN Before 6

CVE-2026-12723

MEDIUM CVSS 5.3 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12724 - Before 6 Plugin

The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivered to a registered user, which can be used for phishing.

PLUGIN Before 6

CVE-2026-12724

MEDIUM CVSS 4.3 2026-07-20
Threat Entry Updated 2026-07-16

CVE-2026-12585 - Before 6 Plugin

The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the automatic-login option is enabled.

PLUGIN Before 6

CVE-2026-12585

HIGH CVSS 8.1 2026-07-16
Threat Entry Updated 2026-07-09

CVE-2026-10834 - Before 6 Plugin

The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile image path before moving the file, allowing authenticated users with subscriber-level access and above to relocate arbitrary files within the WordPress uploads directory into their own profile-image path. This removes the targeted media from its original location and can break content across the site.

PLUGIN Before 6

CVE-2026-10834

MEDIUM CVSS 4.6 2026-07-07
Threat Entry Updated 2026-07-02

CVE-2026-11578 - Before 6 Plugin

The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to the forms a restricted Manager is authorized to manage, allowing a Manager limited to specific forms to permanently delete submission entries belonging to other forms. This requires a non-default configuration in which an administrator has created at least one Manager restricted to specific forms.

PLUGIN Before 6

CVE-2026-11578

LOW CVSS 2.7 2026-07-02
Threat Entry Updated 2026-07-01

CVE-2026-11880 - Before 6 Plugin

The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users.

PLUGIN Before 6

CVE-2026-11880

LOW CVSS 3.1 2026-07-01
Threat Entry Updated 2026-06-17

CVE-2026-8935 - Before 6 Plugin

The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a magic-login URL granting interactive admin access.

PLUGIN Before 6

CVE-2026-8935

CRITICAL CVSS 9.8 2026-06-15
Threat Entry Updated 2026-06-17

CVE-2026-8071 - Before 6 Plugin

The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (including administrators) views the post.

PLUGIN Before 6

CVE-2026-8071

HIGH CVSS 8.8 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-0929 - Before 6 Plugin

The RegistrationMagic WordPress plugin before 6.0.7.2 does not have proper capability checks, allowing subscribers and above to create forms on the site.

PLUGIN Before 6

CVE-2026-0929

MEDIUM CVSS 4.3 2026-02-16
Threat Entry Updated 2026-02-13

CVE-2025-15520 - Before 6 Plugin

The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing for the disclosure of some sensitive data to subscribers and above.

PLUGIN Before 6

CVE-2025-15520

MEDIUM CVSS 4.3 2026-02-13
Threat Entry Updated 2026-01-13

CVE-2025-14579 - Before 6 Plugin

The Quiz Maker WordPress plugin before 6.7.0.89 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 6

CVE-2025-14579

MEDIUM CVSS 4.8 2026-01-12
Threat Entry Updated 2025-10-14

CVE-2025-9698 - Before 6 Plugin

The Plus Addons for Elementor WordPress plugin before 6.3.16 does not sanitize SVG file contents, which could allow users with minimum role access as Author to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 6

CVE-2025-9698

MEDIUM CVSS 6.8 2025-10-13
Threat Entry Updated 2025-07-02

CVE-2025-5034 - Before 6 Plugin

The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 6

CVE-2025-5034

HIGH CVSS 7.1 2025-06-21
Threat Entry Updated 2025-06-12

CVE-2024-9838 - Before 6 Plugin

The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

PLUGIN Before 6

CVE-2024-9838

MEDIUM CVSS 5.4 2025-05-15
Threat Entry Updated 2025-06-12

CVE-2025-0329 - Before 6 Plugin

The AI ChatBot for WordPress WordPress plugin before 6.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 6

CVE-2025-0329

MEDIUM CVSS 4.8 2025-05-15
Threat Entry Updated 2025-06-04

CVE-2024-9390 - Before 6 Plugin

The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 6

CVE-2024-9390

MEDIUM CVSS 4.8 2025-05-15
Threat Entry Updated 2025-06-04

CVE-2024-8617 - Before 6 Plugin

The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 6

CVE-2024-8617

MEDIUM CVSS 4.8 2025-05-15
Threat Entry Updated 2025-06-04

CVE-2024-8493 - Before 6 Plugin

The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 6

CVE-2024-8493

MEDIUM CVSS 4.8 2025-05-15
Scroll to top