sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10
Critical1
High4
Medium5
Reset
Showing 1-10 of 10 records
Threat Entry Updated 2026-09-28

from 1 - Security Vulnerability (CVE-2026-88828)

The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded.

PLUGIN from 1

CVE-2026-88828

MEDIUM CVSS 5.4 2026-09-28
Threat Entry Updated 2026-09-28

from 1 - Security Vulnerability (CVE-2026-84744)

The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts.

PLUGIN from 1

CVE-2026-84744

MEDIUM CVSS 6.5 2026-09-28
Threat Entry Updated 2026-09-25

from 1 - Security Vulnerability (CVE-2026-88848)

The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is covered by their membership plan, nor that the plan identifier submitted with the request is one they actually hold, allowing any member to enrol themselves into restricted paid courses outside their plan and beyond the number of courses it entitles them to.

PLUGIN from 1

CVE-2026-88848

MEDIUM CVSS 4.2 2026-09-25
Threat Entry Updated 2026-09-18

from 1 - Security Vulnerability (CVE-2026-86801)

The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no authentication, capability or nonce check of any kind, and validates only the name of an uploaded file rather than its content, allowing unauthenticated users to store active content served from the site's own origin, and to list and delete the files already staged there.

PLUGIN from 1

CVE-2026-86801

HIGH CVSS 8.8 2026-09-17
Threat Entry Updated 2026-09-20

from 1 - Security Vulnerability (CVE-2026-87963)

The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attackers to perform SQL injection and read arbitrary database contents including administrator password hashes.

PLUGIN from 1

CVE-2026-87963

HIGH CVSS 8.6 2026-09-17
Threat Entry Updated 2026-09-14

from 1 - Security Vulnerability (CVE-2026-81648)

The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext.

PLUGIN from 1

CVE-2026-81648

CRITICAL CVSS 10.0 2026-09-13
Threat Entry Updated 2026-09-14

from 1 - Security Vulnerability (CVE-2026-74933)

The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page.

PLUGIN from 1

CVE-2026-74933

HIGH CVSS 8.8 2026-09-13
Threat Entry Updated 2026-09-11

from 1 - Security Vulnerability (CVE-2026-85116)

The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.

PLUGIN from 1

CVE-2026-85116

MEDIUM CVSS 6.5 2026-09-11
Threat Entry Updated 2026-08-26

from 1 - Broken Access Control (CVE-2026-13342)

The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-based login restriction feature, allowing the restriction to be bypassed so that unauthenticated requests from non-allowlisted IP addresses can reach and use the login form, defeating the access control the administrator configured.

PLUGIN from 1

CVE-2026-13342

MEDIUM CVSS 5.3 2026-08-06
Threat Entry Updated 2026-08-26

from 1 - SQL Injection (CVE-2026-3430)

The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.

PLUGIN from 1

CVE-2026-3430

HIGH CVSS 8.6 2026-08-06