Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,305
Critical188
High692
Medium2,401
Reset
Showing 21-40 of 3305 records
Threat Entry Updated 2026-05-22

CVE-2026-7636 - Changeset Plugin

The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 via the map_meta_cap. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract draft slider metadata including unpublished media URLs, captions, and slider configuration authored by administrators or editors.

PLUGIN Changeset

CVE-2026-7636

MEDIUM CVSS 4.3 2026-05-22
Threat Entry Updated 2026-05-20

CVE-2026-5200 - Changeset Plugin

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 10.8.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify privileged AcyMailing configuration, export subscriber secret keys, and chain these actions into administrator account takeover when a target administrator email address is known.

PLUGIN Changeset

CVE-2026-5200

HIGH CVSS 8.8 2026-05-20
Threat Entry Updated 2026-05-20

CVE-2026-6566 - Changeset Plugin

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 4.2.0. This is due to insufficient object-level authorization in the image deletion REST flow where the permission callback for DELETE /imagely/v1/images/{id} only checks 'NextGEN Manage gallery' permissions and does not enforce gallery ownership or 'NextGEN Manage others gallery' permissions. This makes it possible for authenticated attackers, with Subscriber-level privileges and 'NextGEN Manage gallery' capability, to delete gallery images belonging to other users as well…

PLUGIN Changeset

CVE-2026-6566

MEDIUM CVSS 4.3 2026-05-20
Threat Entry Updated 2026-05-20

CVE-2026-2955 - Changeset Plugin

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header in versions up to, and including, 1.4.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: Practical exploitation is constrained due to a 20-character storage limit.

PLUGIN Changeset

CVE-2026-2955

MEDIUM CVSS 6.4 2026-05-20
Threat Entry Updated 2026-05-20

CVE-2026-5075 - Changeset Plugin

The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized script data in versions up to, and including, 4.9.7 due to sensitive internal option data being passed to wp_localize_script() in post editor contexts without effective masking for low-privilege users. This makes it possible for authenticated attackers, with contributor-level access and above, to view configured API/OAuth tokens and license-related values from page source.

PLUGIN Changeset

CVE-2026-5075

MEDIUM CVSS 4.3 2026-05-20
Threat Entry Updated 2026-05-20

CVE-2026-7284 - Changeset Plugin

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due to the 'easyel_handle_register' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.

PLUGIN Changeset

CVE-2026-7284

CRITICAL CVSS 9.8 2026-05-20
Threat Entry Updated 2026-05-19

CVE-2026-8073 - Changeset Plugin

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation and missing capability check in the 'downloadZIP' function in all versions up to, and including, 6.0.6. This makes it possible for unauthenticated attackers to read and delete arbitrary files limited in the WordPress uploads base directory.

PLUGIN Changeset

CVE-2026-8073

HIGH CVSS 7.5 2026-05-19
Threat Entry Updated 2026-05-19

CVE-2026-8096 - Changeset Plugin

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to view all Kirki frontend forms and read stored visitor form submission data, including contact details, messages, and any other visitor-provided information submitted through site forms.

PLUGIN Changeset

CVE-2026-8096

MEDIUM CVSS 6.5 2026-05-19
Threat Entry Updated 2026-05-19

CVE-2026-47100 - Changeset Plugin

Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and write arbitrary data to the plugin's External Scripts global setting. Attackers can inject malicious JavaScript through the External Scripts setting that executes in the browsers of all checkout page visitors.

PLUGIN Changeset

CVE-2026-47100

HIGH CVSS 8.7 2026-05-19
Threat Entry Updated 2026-05-18

CVE-2026-8719 - Changeset Plugin

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be granted without verifying administrator privileges. This makes it possible for authenticated (Subscriber+) attackers to invoke admin-level MCP tools and escalate privileges to Administrator.

PLUGIN Changeset

CVE-2026-8719

HIGH CVSS 8.8 2026-05-17
Threat Entry Updated 2026-05-15

CVE-2026-6415 - Changeset Plugin

The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.0.2. This is due to insufficient input validation of JSON field values and unsafe client-side HTML construction in the update_preview() JavaScript function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2026-6415

MEDIUM CVSS 6.4 2026-05-15
Threat Entry Updated 2026-05-15

CVE-2026-7563 - Changeset Plugin

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.3.10. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to add arbitrary notes to any order and trigger unsolicited notification and moderation emails to listing owners without administrative authorization.

PLUGIN Changeset

CVE-2026-7563

MEDIUM CVSS 4.3 2026-05-15
Threat Entry Updated 2026-05-15

CVE-2026-6228 - Changeset Plugin

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to insufficient authorization checks in the role field update mechanism combined with overly permissive capabilities for the admin_form post type. The admin_form custom post type uses 'capability_type' => 'page', which grants editors the ability to create and edit forms. When an editor creates an edit_user form, they can manipulate the form configuration to include 'administrator' in the role_options array by directly submitting POST data to wp-admin/post.php, bypassing…

PLUGIN Changeset

CVE-2026-6228

HIGH CVSS 8.8 2026-05-15
Threat Entry Updated 2026-05-15

CVE-2026-4683 - Changeset Plugin

The Smartcat Translator for WPML plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'routeData' REST endpoint in all versions up to, and including, 3.1.77. This makes it possible for unauthenticated attackers to overwrite the plugin's Smartcat API credentials (account ID, API secret key, hub key, API host, and hub host), effectively hijacking the translation service or causing a denial of service.

PLUGIN Changeset

CVE-2026-4683

MEDIUM CVSS 6.5 2026-05-15
Threat Entry Updated 2026-05-15

CVE-2026-4094 - Changeset Plugin

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete the entire multi-currency configuration by visiting any wp-admin page with the `woocs_reset` parameter appended. Additionally, because no nonce is verified, this is also exploitable via Cross-Site Request Forgery against any administrator. The vulnerability may also be exploited by Subscriber-level users if…

PLUGIN Changeset

CVE-2026-4094

HIGH CVSS 8.1 2026-05-15
Threat Entry Updated 2026-05-14

CVE-2026-4030 - Changeset Plugin

The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check combined with a user-controlled backup directory parameter. This makes it possible for unauthenticated attackers to read and delete arbitrary files on the server, leading to Sensitive Information Exposure and potential site takeover. Note: This vulnerability is only exploitable in WordPress Multisite environments where the deprecated is_site_admin() function exists.

PLUGIN Changeset

CVE-2026-4030

HIGH CVSS 8.1 2026-05-14
Threat Entry Updated 2026-05-14

CVE-2026-4031 - Changeset Plugin

The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due to the plugin not restricting access to the wp_db_temp_dir parameter, which controls where database backups are written. This makes it possible for unauthenticated attackers to send a request to wp-cron.php with a poisoned wp_db_temp_dir value pointing to a publicly accessible directory (e.g., wp-content/uploads/), and if a scheduled backup is due, intercept the backup file before it is cleaned up. The backup file has a predictable name…

PLUGIN Changeset

CVE-2026-4031

HIGH CVSS 7.5 2026-05-14
Threat Entry Updated 2026-05-14

CVE-2026-4029 - Changeset Plugin

The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check. This makes it possible for unauthenticated attackers to export database tables, leading to Sensitive Information Exposure. Note: This vulnerability is only exploitable in WordPress Multisite environments where the deprecated is_site_admin() function exists.

PLUGIN Changeset

CVE-2026-4029

HIGH CVSS 7.5 2026-05-14
Threat Entry Updated 2026-05-14

CVE-2026-6504 - Changeset Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2026-6504

MEDIUM CVSS 6.4 2026-05-14
Threat Entry Updated 2026-05-14

CVE-2026-6174 - Changeset Plugin

The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'more' parameter in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Changeset

CVE-2026-6174

MEDIUM CVSS 6.4 2026-05-14
Scroll to top