Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total70
Critical8
High22
Medium39
Reset
Showing 1-20 of 70 records
Threat Entry Updated 2026-07-24

CVE-2026-63030 - WordPress Core

WordPress Core Interpretation Conflict Vulnerability Vendor/Product: WordPress Core Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Notes: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ;…

CORE WordPress Core

CVE-2026-63030

CRITICAL CVSS 9.8 2026-07-21
Threat Entry Updated 2026-06-17

CVE-2026-9065 - WordPress Core

SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameters ('model_name', 'model_id', 'integration_id', 'provider') on the REST API endpoint '/surecart/v1/integrations/{id}'. The root cause is a flawed escaping bypass in the query builder ('wp-query-builder'). Values passed to the 'where()' method are only sanitized via '$wpdb->prepare()' when they do **not** contain a dot ('.') or the WordPress table prefix ('wp_'). By including a dot anywhere in the payload, an attacker completely bypasses the escaping logic and injects arbitrary SQL into the 'WHERE' clause, allowing full UNION-based extraction of…

CORE WordPress Core

CVE-2026-9065

CRITICAL CVSS 9.3 2026-05-20
Threat Entry Updated 2026-06-17

CVE-2026-3906 - WordPress Core

WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collaboration annotations) was introduced in WordPress 6.9 to allow editorial comments directly on posts in the block editor. However, the REST API `create_item_permissions_check()` method in the comments controller did not verify that the authenticated user has `edit_post` permission on the target post when creating a note. This makes it possible for authenticated attackers with Subscriber-level access to create notes on any post, including posts authored by other users, private posts, and posts in any…

CORE WordPress Core

CVE-2026-3906

MEDIUM CVSS 4.3 2026-03-11
Threat Entry Updated 2026-06-17

CVE-2026-25315 - WordPress Core

Improperly implemented security check vulnerability in KAGG hCaptcha for WP allows CAPTCHA Functionality Bypass.This issue affects hCaptcha for WP: from n/a through 4.21.1. The vulnerability is limited to the CAPTCHA mechanism intended to protect a publicly accessible form from automated abuse. It does not impact WordPress-level authentication or authorization controls.

CORE WordPress Core

CVE-2026-25315

MEDIUM CVSS 5.3 2026-02-19
Threat Entry Updated 2026-01-26

CVE-2025-53240 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in adamlabs WordPress Photo Gallery photo-gallery-portfolio allows Reflected XSS.This issue affects WordPress Photo Gallery: from n/a through

CORE WordPress Core

CVE-2025-53240

MEDIUM CVSS 6.1 2026-01-22
Threat Entry Updated 2026-01-26

CVE-2025-49043 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Magic Responsive Slider and Carousel WordPress magic_carousel allows Reflected XSS.This issue affects Magic Responsive Slider and Carousel WordPress: from n/a through

CORE WordPress Core

CVE-2025-49043

MEDIUM CVSS 6.1 2026-01-22
Threat Entry Updated 2026-01-14

CVE-2025-9427 - WordPress Core

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lemonsoft WordPress add on allows Cross-Site Scripting (XSS).This issue affects WordPress add on: 2025.7.1.

CORE WordPress Core

CVE-2025-9427

HIGH CVSS 8.4 2026-01-13
Threat Entry Updated 2026-01-20

CVE-2025-69331 - WordPress Core

Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a through

CORE WordPress Core

CVE-2025-69331

MEDIUM CVSS 4.3 2026-01-06
Threat Entry Updated 2026-01-20

CVE-2025-63005 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomas WordPress Tooltips allows Stored XSS.This issue affects WordPress Tooltips: from n/a through 10.7.9.

CORE WordPress Core

CVE-2025-63005

MEDIUM CVSS 6.5 2025-12-31
Threat Entry Updated 2026-01-20

CVE-2025-68974 - WordPress Core

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register miniorange-login-openid allows PHP Local File Inclusion.This issue affects WordPress Social Login and Register: from n/a through

CORE WordPress Core

CVE-2025-68974

CRITICAL CVSS 9.8 2025-12-30
Threat Entry Updated 2026-01-20

CVE-2025-68597 - WordPress Core

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlueGlass Interactive AG Jobs for WordPress job-postings allows Stored XSS.This issue affects Jobs for WordPress: from n/a through

CORE WordPress Core

CVE-2025-68597

MEDIUM CVSS 5.4 2025-12-24
Threat Entry Updated 2026-01-20

CVE-2025-64273 - WordPress Core

Missing Authorization vulnerability in GetResponse Email marketing for WordPress by GetResponse Official getresponse-official allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Email marketing for WordPress by GetResponse Official: from n/a through

CORE WordPress Core

CVE-2025-64273

HIGH CVSS 7.5 2025-12-18
Threat Entry Updated 2026-01-20

CVE-2025-64272 - WordPress Core

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in GetResponse Email marketing for WordPress by GetResponse Official getresponse-official allows Retrieve Embedded Sensitive Data.This issue affects Email marketing for WordPress by GetResponse Official: from n/a through

CORE WordPress Core

CVE-2025-64272

MEDIUM CVSS 6.5 2025-12-18
Threat Entry Updated 2026-01-20

CVE-2025-64253 - WordPress Core

Path Traversal: '.../...//' vulnerability in WordPress.org Health Check & Troubleshooting health-check allows Path Traversal.This issue affects Health Check & Troubleshooting: from n/a through

CORE WordPress Core

CVE-2025-64253

MEDIUM CVSS 4.9 2025-12-16
Threat Entry Updated 2026-01-20

CVE-2025-67516 - WordPress Core

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows Blind SQL Injection.This issue affects Store Locator WordPress: from n/a through

CORE WordPress Core

CVE-2025-67516

CRITICAL CVSS 9.8 2025-12-09
Threat Entry Updated 2026-01-20

CVE-2025-64259 - WordPress Core

Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a through

CORE WordPress Core

CVE-2025-64259

MEDIUM CVSS 6.5 2025-11-13
Scroll to top