Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High0
Medium3
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2026-06-17

CVE-2026-5247 - Post Expirator Plugin

The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper' attribute of the [futureaction] shortcode in all versions up to, and including, 4.10.0. This is due to insufficient input sanitization on the wrapper attribute. The plugin uses esc_html() to escape the value, but esc_html() only encodes HTML entities and does not prevent attribute injection when the value is used as an HTML tag name in a sprintf() call. An attacker can inject event handler attributes via spaces in the wrapper value.…

PLUGIN Post Expirator

CVE-2026-5247

MEDIUM CVSS 5.5 2026-05-05
Threat Entry Updated 2025-12-16

CVE-2025-13741 - Post Expirator Plugin

The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getAuthors function in all versions up to, and including, 4.9.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to retrieve emails for all users with edit_posts capability.

PLUGIN Post Expirator

CVE-2025-13741

MEDIUM CVSS 4.3 2025-12-16
Threat Entry Updated 2024-11-21

CVE-2021-24783 - Post Expirator Plugin

The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow users with a role as low as Contributor to schedule deletion of arbitrary posts.

PLUGIN Post Expirator

CVE-2021-24783

MEDIUM CVSS 6.5 2021-11-08
Scroll to top