Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total65
Critical5
High14
Medium44
Reset
Showing 1-20 of 65 records
Threat Entry Updated 2026-07-20

CVE-2026-12898 - Before 7 Plugin

The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations outside its intended storage directory.

PLUGIN Before 7

CVE-2026-12898

MEDIUM CVSS 6.5 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-11349 - Before 7 Plugin

The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection vulnerability that allows attackers to extract sensitive data from the database.

PLUGIN Before 7

CVE-2026-11349

HIGH CVSS 8.6 2026-07-20
Threat Entry Updated 2026-07-07

CVE-2026-12375 - Before 7 Plugin

The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites and beacons the site's secret keys and administrator details to attacker-controlled servers.

PLUGIN Before 7

CVE-2026-12375

CRITICAL CVSS 9.8 2026-07-07
Threat Entry Updated 2026-06-25

CVE-2026-9710 - Before 7 Plugin

The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce needed to call it to every logged-in user on any wp-admin page, allowing any authenticated user to evaluate dynamic content tokens against arbitrary users and disclose their sensitive metadata including raw password hashes. This affects the premium co Cornerstone page builder distributed bundled with the X , not the unrelated free `cornerstone` Cornerstone WordPress plugin before 7.8.8 (v0.8.x) on the .org repository.

PLUGIN Before 7

CVE-2026-9710

HIGH CVSS 7.7 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-9709 - Before 7 Plugin

The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to disclose the metadata of any other user, including roles, session token previews and stored billing/shipping fields. This affects the premium co Cornerstone page builder distributed bundled with the X , not the unrelated free `cornerstone` Cornerstone WordPress plugin before 7.8.9 (v0.8.x) on the .org repository.

PLUGIN Before 7

CVE-2026-9709

HIGH CVSS 7.7 2026-06-24
Threat Entry Updated 2026-06-17

CVE-2026-3220 - Before 7 Plugin

The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.

PLUGIN Before 7

CVE-2026-3220

HIGH CVSS 8.8 2026-05-18
Threat Entry Updated 2026-06-17

CVE-2026-6495 - Before 7 Plugin

The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 7

CVE-2026-6495

HIGH CVSS 7.1 2026-05-18
Threat Entry Updated 2026-01-05

CVE-2025-13820 - Before 7 Plugin

The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.

PLUGIN Before 7

CVE-2025-13820

MEDIUM CVSS 5.3 2026-01-01
Threat Entry Updated 2025-09-22

CVE-2025-9487 - Before 7 Plugin

The Admin and Site Enhancements (ASE) WordPress plugin before 7.9.8 does not sanitise SVG files when uploaded via xmlrpc.php when such uploads are enabled, which could allow users to upload a malicious SVG containing XSS payloads

PLUGIN Before 7

CVE-2025-9487

MEDIUM CVSS 4.7 2025-09-22
Threat Entry Updated 2025-11-13

CVE-2025-9111 - Before 7 Plugin

The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 7

CVE-2025-9111

LOW CVSS 3.5 2025-09-09
Threat Entry Updated 2025-06-04

CVE-2024-7758 - Before 7 Plugin

The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could allow high privilege users of contributor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 7

CVE-2024-7758

MEDIUM CVSS 4.8 2025-05-15
Threat Entry Updated 2025-05-14

CVE-2024-13688 - Before 7 Plugin

The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protection feature, allowing attacker to bypass the protection offered via a crafted request

PLUGIN Before 7

CVE-2024-13688

MEDIUM CVSS 5.3 2025-04-28
Threat Entry Updated 2025-05-15

CVE-2024-10472 - Before 7 Plugin

The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 7

CVE-2024-10472

MEDIUM CVSS 5.9 2025-03-25
Threat Entry Updated 2025-05-09

CVE-2025-1232 - Before 7 Plugin

The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform Stored XSS attacks

PLUGIN Before 7

CVE-2025-1232

HIGH CVSS 8.8 2025-03-19
Threat Entry Updated 2025-05-14

CVE-2024-13685 - Before 7 Plugin

The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate their value to bypass the login limit feature in the Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10.

PLUGIN Before 7

CVE-2024-13685

MEDIUM CVSS 5.3 2025-03-04
Threat Entry Updated 2024-10-02

CVE-2024-3635 - Before 7 Plugin

The Post Grid WordPress plugin before 7.5.0 does not sanitise and escape some of its Grid settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 7

CVE-2024-3635

MEDIUM CVSS 4.8 2024-09-30
Threat Entry Updated 2025-06-13

CVE-2024-6766 - Before 7 Plugin

The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 7

CVE-2024-6766

MEDIUM CVSS 5.4 2024-08-06
Threat Entry Updated 2025-06-10

CVE-2024-4217 - Before 7 Plugin

The shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, making it possible for attackers with a Contributor account to conduct Stored XSS attacks.

PLUGIN Before 7

CVE-2024-4217

MEDIUM CVSS 4.7 2024-07-13
Threat Entry Updated 2025-05-21

CVE-2024-5488 - Before 7 Plugin

The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.

PLUGIN Before 7

CVE-2024-5488

CRITICAL CVSS 9.8 2024-07-09
Threat Entry Updated 2025-05-19

CVE-2024-4900 - Before 7 Plugin

The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform Open redirect attacks against any user viewing a malicious post

PLUGIN Before 7

CVE-2024-4900

MEDIUM CVSS 6.1 2024-06-24
Scroll to top