Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total50
Critical2
High8
Medium39
Reset
Showing 1-20 of 50 records
Threat Entry Updated 2026-07-21

CVE-2026-14185 - Before 8 Plugin

The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-generation settings handlers, allowing authenticated users with subscriber-level access to modify the WPBot WordPress plugin before 8.2.0's configuration.

PLUGIN Before 8

CVE-2026-14185

MEDIUM CVSS 4.3 2026-07-21
Threat Entry Updated 2026-07-20

CVE-2026-12973 - Before 8 Plugin

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some configurations, to modify order statuses.

PLUGIN Before 8

CVE-2026-12973

MEDIUM CVSS 6.5 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12972 - Before 8 Plugin

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.

PLUGIN Before 8

CVE-2026-12972

MEDIUM CVSS 5.3 2026-07-20
Threat Entry Updated 2026-07-06

CVE-2026-6382 - Before 8 Plugin

The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a shell command when processing image operations, allowing authenticated users to perform OS Command Injection. This requires the server to have the ImageMagick convert CLI available without either the PHP imagick or GD extensions.

PLUGIN Before 8

CVE-2026-6382

CRITICAL CVSS 9.1 2026-07-06
Threat Entry Updated 2026-07-06

CVE-2026-12083 - Before 8 Plugin

The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before 8.8.4 does not perform authentication, authorization, or nonce checks on a role-restoration request handler, allowing unauthenticated attackers to restore a previously demoted administrator account back to the administrator role. This is an incomplete fix of CVE-2024-43333 / CVE-2025-24648, which closed the issue for only one of the demotion paths the WordPress role API exposes.

PLUGIN Before 8

CVE-2026-12083

HIGH CVSS 8.1 2026-07-06
Threat Entry Updated 2026-06-17

CVE-2026-4338 - Before 8 Plugin

The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts

PLUGIN Before 8

CVE-2026-4338

HIGH CVSS 7.5 2026-04-08
Threat Entry Updated 2025-06-12

CVE-2025-3582 - Before 8 Plugin

The Newsletter WordPress plugin before 8.85 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 8

CVE-2025-3582

MEDIUM CVSS 4.8 2025-06-09
Threat Entry Updated 2025-06-12

CVE-2025-3581 - Before 8 Plugin

The Newsletter WordPress plugin before 8.8.5 does not validate and escape some of its Widget options before outputting them back in a page/post where the block is embed, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 8

CVE-2025-3581

MEDIUM CVSS 4.8 2025-06-09
Threat Entry Updated 2025-06-05

CVE-2025-3584 - Before 8 Plugin

The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 8

CVE-2025-3584

MEDIUM CVSS 4.8 2025-06-03
Threat Entry Updated 2025-06-09

CVE-2025-4133 - Before 8 Plugin

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 8.4.0 does not escape the title of posts when outputting them in a dashboard, which could allow users with the contributor role to perform Cross-Site Scripting attacks.

PLUGIN Before 8

CVE-2025-4133

MEDIUM CVSS 5.4 2025-05-22
Threat Entry Updated 2025-06-09

CVE-2025-4094 - Before 8 Plugin

The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.

PLUGIN Before 8

CVE-2025-4094

CRITICAL CVSS 9.8 2025-05-21
Threat Entry Updated 2025-06-10

CVE-2024-13619 - Before 8 Plugin

The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Before 8

CVE-2024-13619

MEDIUM CVSS 6.1 2025-05-15
Threat Entry Updated 2025-06-04

CVE-2023-5529 - Before 8 Plugin

The Advanced Page Visit Counter WordPress plugin before 8.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 8

CVE-2023-5529

MEDIUM CVSS 4.8 2025-05-15
Threat Entry Updated 2025-05-07

CVE-2025-3583 - Before 8 Plugin

The Newsletter WordPress plugin before 8.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Before 8

CVE-2025-3583

MEDIUM CVSS 4.8 2025-05-05
Threat Entry Updated 2025-05-08

CVE-2024-6133 - Before 8 Plugin

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 8

CVE-2024-6133

MEDIUM CVSS 6.5 2024-08-12
Threat Entry Updated 2025-05-08

CVE-2024-6136 - Before 8 Plugin

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

PLUGIN Before 8

CVE-2024-6136

MEDIUM CVSS 5.4 2024-08-12
Threat Entry Updated 2025-05-08

CVE-2024-6134 - Before 8 Plugin

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 8

CVE-2024-6134

MEDIUM CVSS 5.4 2024-08-12
Threat Entry Updated 2024-11-21

CVE-2024-6075 - Before 8 Plugin

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

PLUGIN Before 8

CVE-2024-6075

HIGH CVSS 8.8 2024-07-15
Threat Entry Updated 2024-11-21

CVE-2024-6076 - Before 8 Plugin

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 8

CVE-2024-6076

MEDIUM CVSS 6.1 2024-07-15
Threat Entry Updated 2024-11-21

CVE-2024-6074 - Before 8 Plugin

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Before 8

CVE-2024-6074

MEDIUM CVSS 6.1 2024-07-15
Scroll to top