Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total44
Critical4
High8
Medium32
Reset
Showing 1-20 of 44 records
Threat Entry Updated 2026-07-15

CVE-2026-9017 - For Wordpress Plugin

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the saved_admin_email, saved_user_email, and saved_user_email_address fields of arbitrary form entries belonging to other users, and cause the site to dispatch attacker-controlled email content to attacker-chosen recipient addresses.

PLUGIN For Wordpress

CVE-2026-9017

MEDIUM CVSS 5.3 2026-07-11
Threat Entry Updated 2026-07-07

CVE-2026-13040 - For Wordpress Plugin

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The submission endpoint is registered via wp_ajax_nopriv_submit_nex_form with no nonce verification, making it fully accessible to unauthenticated attackers without any CSRF token.

PLUGIN For Wordpress

CVE-2026-13040

HIGH CVSS 7.2 2026-07-03
Threat Entry Updated 2026-07-02

CVE-2026-11592 - For Wordpress Plugin

The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to overwrite plugin mail settings (from name and from email address), create audience lists, insert arbitrary contacts into those lists, create and overwrite newsletter broadcasts and post notifications, add…

PLUGIN For Wordpress

CVE-2026-11592

MEDIUM CVSS 4.3 2026-07-02
Threat Entry Updated 2026-07-01

CVE-2026-12142 - For Wordpress Plugin

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '_name[]' Array Parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The wp_kses() output filtering pass provides no mitigation because NEXForms_allowed_tags() explicitly permits <script>, <iframe src/srcdoc>, and JS event handlers such as onClick, onBlur, and onChange in its allow-list.

PLUGIN For Wordpress

CVE-2026-12142

HIGH CVSS 7.2 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12408 - For Wordpress Plugin

The Slim SEO – A Fast & Automated SEO Plugin For WordPress plugin for WordPress is vulnerable to Unauthorized Private Content Disclosure in all versions up to, and including, 4.9.8 via the `/wp-json/slim-seo/meta-tags/ai` REST API endpoint. This is due to the endpoint's `permission_callback` performing only a top-level `edit_posts` capability check without verifying that the requesting user has read access to the specific post supplied via the `object.ID` parameter, allowing the `generate` function to pass the attacker-controlled post ID to `Data::get_post_content()`, which calls `get_post()` regardless of post status or ownership. This…

PLUGIN For Wordpress

CVE-2026-12408

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-06-29

CVE-2026-12404 - For Wordpress Plugin

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enumerate sequential report IDs and download complete form submission data — including names, email addresses, phone numbers, postal addresses, payment details, and uploaded file paths — for any saved report on the site.

PLUGIN For Wordpress

CVE-2026-12404

MEDIUM CVSS 5.3 2026-06-27
Threat Entry Updated 2026-06-17

CVE-2026-7046 - For Wordpress Plugin

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'table' parameter in all versions up to, and including, 9.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN For Wordpress

CVE-2026-7046

MEDIUM CVSS 4.9 2026-05-15
Threat Entry Updated 2026-06-17

CVE-2026-5063 - For Wordpress Plugin

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via POST parameter key names in the submit_nex_form() function in versions up to, and including, 9.1.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN For Wordpress

CVE-2026-5063

HIGH CVSS 7.2 2026-05-03
Threat Entry Updated 2026-06-17

CVE-2026-1947 - For Wordpress Plugin

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 9.1.9 via the submit_nex_form() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to to overwrite arbitrary form entries via the 'nf_set_entry_update_id' parameter.

PLUGIN For Wordpress

CVE-2026-1947

HIGH CVSS 7.5 2026-03-16
Threat Entry Updated 2026-06-17

CVE-2026-1948 - For Wordpress Plugin

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_license() function in all versions up to, and including, 9.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to to deactivate the plugin license.

PLUGIN For Wordpress

CVE-2026-1948

MEDIUM CVSS 4.3 2026-03-16
Threat Entry Updated 2026-06-17

CVE-2026-1189 - For Wordpress Plugin

The LeadBI Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_id' parameter of the 'leadbi_form' shortcode in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN For Wordpress

CVE-2026-1189

MEDIUM CVSS 6.4 2026-01-24
Threat Entry Updated 2026-06-17

CVE-2026-0820 - For Wordpress Plugin

The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference due to missing capability checks on the wc_upload_and_save_signature_handler function in all versions up to, and including, 4.1116. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary signatures to any order in the system, potentially modifying order metadata and triggering unauthorized status changes.

PLUGIN For Wordpress

CVE-2026-0820

MEDIUM CVSS 5.3 2026-01-17
Threat Entry Updated 2026-01-08

CVE-2025-14128 - For Wordpress Plugin

The Stumble! for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN For Wordpress

CVE-2025-14128

MEDIUM CVSS 6.1 2026-01-07
Threat Entry Updated 2025-12-15

CVE-2025-13728 - For Wordpress Plugin

The FluentAuth – The Ultimate Authorization & Security Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `fluent_auth_reset_password` shortcode in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN For Wordpress

CVE-2025-13728

MEDIUM CVSS 6.4 2025-12-15
Threat Entry Updated 2025-12-15

CVE-2025-10738 - For Wordpress Plugin

The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘analytic_id’ parameter in all versions up to, and including, 3.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN For Wordpress

CVE-2025-10738

CRITICAL CVSS 9.8 2025-12-13
Threat Entry Updated 2025-12-08

CVE-2025-13006 - For Wordpress Plugin

The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.5 via several unprotected /wp-json/surveyfunnel/v2/ REST API endpoints. This makes it possible for unauthenticated attackers to extract sensitive data from survey responses.

PLUGIN For Wordpress

CVE-2025-13006

MEDIUM CVSS 5.3 2025-12-05
Threat Entry Updated 2025-12-08

CVE-2025-12417 - For Wordpress Plugin

The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'surveyfunnel_lite_survey' shortcode in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN For Wordpress

CVE-2025-12417

MEDIUM CVSS 6.4 2025-12-05
Threat Entry Updated 2025-10-27

CVE-2025-10740 - For Wordpress Plugin

The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provided by the API due to a missing capability check on the verifyRequest function in all versions up to, and including, 3.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify links.

PLUGIN For Wordpress

CVE-2025-10740

MEDIUM CVSS 6.3 2025-10-24
Threat Entry Updated 2025-10-14

CVE-2025-10185 - For Wordpress Plugin

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the action nf_load_form_entries in all versions up to, and including, 9.1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This may be exploitable by lower-level users…

PLUGIN For Wordpress

CVE-2025-10185

MEDIUM CVSS 4.9 2025-10-11
Threat Entry Updated 2025-09-08

CVE-2025-10003 - For Wordpress Plugin

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘upload_file_remove’ function and 'htmlvar' parameter in all versions up to, and including, 1.2.44 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN For Wordpress

CVE-2025-10003

MEDIUM CVSS 6.5 2025-09-06
Scroll to top