sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total17,710
Critical1,270
High4,022
Medium12,142
Reset
Showing 1-20 of 17710 records
Threat Entry Updated 2026-09-04

LearnDash LMS - Security Vulnerability (CVE-2026-12483)

The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. This is due to insufficient input validation in the 'learndash_fileupload_process' function, which iterates through an entire array and validates only the first file. This makes it possible for authenticated attackers, with subscriber-level access and above who are enrolled in a course with assignment uploads enabled, to upload arbitrary disallowed files, including PHP files, to the server's wp-content/uploads/learndash/assignments/ directory. The uploaded files can only be used for Remote Code Execution if…

PLUGIN LearnDash LMS

CVE-2026-12483

HIGH CVSS 7.5 2026-09-04
Threat Entry Updated 2026-09-04

E-cab Taxi Booking Manager for Woocommerce - Security Vulnerability (CVE-2026-84045)

The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before pricing a booking, allowing unauthenticated attackers to manipulate the order total down to zero and place real taxi-booking orders at an arbitrary price.

PLUGIN E-cab Taxi Booking Manager for Woocommerce

CVE-2026-84045

MEDIUM CVSS 5.3 2026-09-04
Threat Entry Updated 2026-09-04

Restaurant Menu and Food Ordering - Security Vulnerability (CVE-2026-84044)

The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification genuinely originates from PayPal, allowing unauthenticated attackers to forge a payment notification and mark their own order as paid and completed without making any payment.

PLUGIN Restaurant Menu and Food Ordering

CVE-2026-84044

MEDIUM CVSS 5.3 2026-09-04
Threat Entry Updated 2026-09-04

Xpro Addons - Security Vulnerability (CVE-2026-84146)

The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summary from a supplied product identifier, allowing unauthenticated visitors to retrieve the title, price, SKU, description and stock details of products that are not publicly published (draft, pending, private or scheduled status).

PLUGIN Xpro Addons

CVE-2026-84146

MEDIUM CVSS 5.3 2026-09-04
Threat Entry Updated 2026-09-04

Frontend Admin by DynamiApps - Security Vulnerability (CVE-2026-81347)

The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outside the intended directory, including the WordPress root, which can render the site inoperable. Successful exploitation requires a non-default form configuration.

PLUGIN Frontend Admin by DynamiApps

CVE-2026-81347

MEDIUM CVSS 5.9 2026-09-04
Threat Entry Updated 2026-09-04

3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms - Security Vulnerability (CVE-2026-80438)

The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user granted that capability to read Ninja Forms WordPress plugin before 3.15.2 settings and stored form submissions, overwrite the Ninja Forms WordPress plugin before 3.15.2's configuration, and create or modify arbitrary posts and pages. The capability belongs to no default WordPress role and the Ninja Forms WordPress plugin before 3.15.2 never grants it, so an administrator must…

PLUGIN 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms

CVE-2026-80438

MEDIUM CVSS 5.9 2026-09-04
Threat Entry Updated 2026-09-04

WPvivid - Security Vulnerability (CVE-2026-82194)

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root.

PLUGIN WPvivid

CVE-2026-82194

MEDIUM CVSS 5.5 2026-09-04
Threat Entry Updated 2026-09-04

WPvivid - Security Vulnerability (CVE-2026-82193)

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing administrators to write files of permitted types to arbitrary locations on the server and to overwrite existing files.

PLUGIN WPvivid

CVE-2026-82193

MEDIUM CVSS 5.5 2026-09-04
Threat Entry Updated 2026-09-04

WPFunnels - Security Vulnerability (CVE-2026-79632)

The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing unauthenticated users to make the site send emails to arbitrary recipients with an arbitrary subject.

PLUGIN WPFunnels

CVE-2026-79632

MEDIUM CVSS 5.3 2026-09-04
Threat Entry Updated 2026-09-04

Directorist - Security Vulnerability (CVE-2026-84066)

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above to overwrite image metadata on posts belonging to other users.

PLUGIN Directorist

CVE-2026-84066

LOW CVSS 3.1 2026-09-04
Threat Entry Updated 2026-09-04

Pods - Security Vulnerability (CVE-2026-74853)

The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, including files outside the web root. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.

PLUGIN Pods

CVE-2026-74853

MEDIUM CVSS 6.8 2026-09-04
Threat Entry Updated 2026-09-04

WPFunnels - Security Vulnerability (CVE-2026-79631)

The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, allowing unauthenticated users to download customer order details and opt-in form submissions when logging is enabled.

PLUGIN WPFunnels

CVE-2026-79631

MEDIUM CVSS 5.3 2026-09-04
Threat Entry Updated 2026-09-04

WPFunnels - Security Vulnerability (CVE-2026-79630)

The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was configured for, allowing unauthenticated users to obtain any purchasable product at a discount intended for a different one, with the reduced price carried through to the total of the order they place.

PLUGIN WPFunnels

CVE-2026-79630

MEDIUM CVSS 5.3 2026-09-04
Threat Entry Updated 2026-09-04

ACPT - Security Vulnerability (CVE-2026-15354)

The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling `wp_update_user()`. This makes it possible for unauthenticated attackers to overwrite any WordPress user's email address and password, including an administrator's, and take over the account. Successful exploitation requires a public ACPT user form that permits anonymous submissions.

PLUGIN ACPT

CVE-2026-15354

CRITICAL CVSS 9.8 2026-09-04
Threat Entry Updated 2026-09-04

Classified Listing - Security Vulnerability (CVE-2026-16281)

The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing owned by another user.

PLUGIN Classified Listing

CVE-2026-16281

HIGH CVSS 7.1 2026-09-04
Threat Entry Updated 2026-09-04

Content Views - Security Vulnerability (CVE-2026-17517)

The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read the posts it returns, allowing unauthenticated attackers to obtain the title and content of non-public posts, such as draft, pending, private and scheduled posts, when a view has been configured to include them.

PLUGIN Content Views

CVE-2026-17517

MEDIUM CVSS 5.3 2026-09-04
Threat Entry Updated 2026-09-04

Divi Ajax Filter - Security Vulnerability (CVE-2026-11613)

The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. This vulnerability is only exploitable when the loop_templates parameter is set…

PLUGIN Divi Ajax Filter

CVE-2026-11613

CRITICAL CVSS 9.8 2026-09-04