Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,479
Critical934
High3,137
Medium11,193
Reset
Showing 201-220 of 15479 records
Threat Entry Updated 2026-07-10

CVE-2026-9838 - Ics Calendar Plugin

The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter in all versions up to, and including, 12.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability is reachable via the unauthenticated wp_ajax_nopriv_r34ics_ajax AJAX action, which accepts attacker-controlled js_args values merged over stored shortcode configuration without nonce verification, allowing the…

PLUGIN Ics Calendar

CVE-2026-9838

MEDIUM CVSS 6.1 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-15104 - Faq With Chatbot Plugin

The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to generic SQL Injection via the 'lang' parameter in all versions up to, and including, 4.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a supported multilingual plugin…

PLUGIN Faq With Chatbot

CVE-2026-15104

MEDIUM CVSS 6.5 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-3907 - Hostel Plugin

The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all versions up to and including 1.1.7. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, the second shortcode attribute (used as button text) is passed to the `$text` variable without sanitization at line 79 and then output directly into an HTML `value` attribute at line 91 without `esc_attr()` or any other escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary…

PLUGIN Hostel

CVE-2026-3907

MEDIUM CVSS 6.4 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-6802 - Easy Upload Files During Checkout Plugin

The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.0.1. This is due to missing authorization checks in the ufdc_custom_init() function, which processes the 'eufdc-delete' parameter without any nonce verification, capability check, or attachment ownership validation. This makes it possible for unauthenticated attackers to permanently delete arbitrary media library attachments from the WordPress site.

PLUGIN Easy Upload Files During Checkout

CVE-2026-6802

MEDIUM CVSS 5.3 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-14475 - Gdpr Cookie Consent Plugin

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via the 'scan_id' parameter in all versions up to, and including, 4.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Gdpr Cookie Consent

CVE-2026-14475

MEDIUM CVSS 4.9 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-15026 - Import And Export Users And Customers Plugin

The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the post_title and raw post_content of arbitrary posts regardless of status (draft, private, future, trash, password-protected) or post type (including non-public CPTs such as WooCommerce orders and internal CRM records) by enumerating post IDs. The required codection-security nonce is exposed as inline JavaScript on any wp-admin page when ?post_type=acui_email_template…

PLUGIN Import And Export Users And Customers

CVE-2026-15026

MEDIUM CVSS 4.3 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-6440 - Video Conference Plugin

The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1.8. This is due to a missing nonce verification in the reset_credential() function, which handles the wp_ajax_goodmeet_reset_google_meet_credential AJAX action. While the function does verify the user's capability (manage_options), it does not validate a nonce, making it susceptible to CSRF attacks. This makes it possible for unauthenticated attackers to trick a site administrator into clicking a malicious link that will reset (delete) the plugin's…

PLUGIN Video Conference

CVE-2026-6440

MEDIUM CVSS 4.3 2026-07-10
Threat Entry Updated 2026-07-14

CVE-2026-1946 - Gw Ai Website Builder Plugin

The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gwaiwebu_gravitywrite_disconnect_handler() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disconnect the plugin from GravityWrite via the 'gwaiwebu_gravitywrite_disconnect' AJAX action.

PLUGIN Gw Ai Website Builder

CVE-2026-1946

MEDIUM CVSS 4.3 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-12924 - Wp Event Solution Plugin

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Event Solution

CVE-2026-12924

MEDIUM CVSS 6.4 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-12108 - Highlighting Code Block Plugin

The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Highlighting Code Block

CVE-2026-12108

MEDIUM CVSS 4.4 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-12955 - Gdpr Cookie Consent Plugin

The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the gdpr_cookie_consent_ajax_save_schedule_scan() function (the wp_ajax_gcc_save_schedule_scan AJAX action) in versions up to, and including, 4.3.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the plugin's cookie scan schedule configuration stored in the gdpr_scan_schedule_data option, which is an administrative function intended to be limited to users with the manage_options capability.

PLUGIN Gdpr Cookie Consent

CVE-2026-12955

MEDIUM CVSS 4.3 2026-07-10
Threat Entry Updated 2026-07-14

CVE-2026-12400 - Conversational Form Builder Plugin

The FlowForms – Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.1 via the update_form due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to modify the content, design, and settings of, as well as publish or revert, any form on the site — including forms owned by administrators — by supplying an arbitrary form ID in the REST URL.

PLUGIN Conversational Form Builder

CVE-2026-12400

MEDIUM CVSS 4.3 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-11992 - Easy Appointments Plugin

The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to cancel all upcoming appointments site-wide by marking every future appointment stored by the plugin as abandoned. The nonce required to authenticate the cancellation request is printed on the Appointments admin page, which is itself gated only by the edit_posts capability…

PLUGIN Easy Appointments

CVE-2026-11992

MEDIUM CVSS 4.3 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-13347 - Hide Wp Login Plugin

The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via the he_wrapper_js and he_wrapper_css query parameters processed by the elementor_assets_filter() function. This is due to the function concatenating user-supplied input directly onto ABSPATH and passing the result to file_get_contents() without any path traversal validation, allow-list, realpath containment, or extension check; the result is then echoed in the HTTP response. Although the output is passed through wp_kses_post(), that function only filters HTML tags and does not prevent disclosure of…

PLUGIN Hide Wp Login

CVE-2026-13347

HIGH CVSS 7.5 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-12685 - Escortwp Plugin

The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker who supplies a hard-coded, per-build key permanently delete all of the site's content, and that covertly transmits the site URL, administrator email address, and license key to a third-party server.

PLUGIN Escortwp

CVE-2026-12685

HIGH CVSS 7.5 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-12276 - La Studio Element Kit For Elementor Plugin

The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration is enabled on the site before creating an account through one of its unauthenticated AJAX actions, allowing unauthenticated attackers to register new accounts even when registration has been disabled site-wide.

PLUGIN La Studio Element Kit For Elementor

CVE-2026-12276

MEDIUM CVSS 5.3 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-12123 - All In One Video Gallery Plugin

The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.8.5 via the 'vdl' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. A Subscriber-level attacker can plant an internal or loopback URL in the `mp4` post meta of a newly created `aiovg_videos` post via XML-RPC `wp.newPost`, then trigger the unauthenticated `?vdl=`…

PLUGIN All In One Video Gallery

CVE-2026-12123

MEDIUM CVSS 6.4 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-15300 - Geo My Wp Plugin

The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, 4.5.4. The values were read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing wp_magic_quotes, which does not cover $_SERVER), then passed through bare esc_sql() before being interpolated into unquoted numeric positions in the proximity-search query (HAVING/SELECT clause distance math, BETWEEN bounding-box pre-filter) built by gmw_locations_query() in plugins/posts-locator/includes/class-gmw-wp-query.php. Because esc_sql() only escapes string delimiters and these positions are numeric, payloads such as `1 OR SLEEP(3)` survived sanitization. Fixed in…

PLUGIN Geo My Wp

CVE-2026-15300

CRITICAL CVSS 9.1 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-15298 - TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot Plugin

The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all versions up to, and including, 1.14.14. This is due to insufficient input sanitization when processing Telegram API responses containing attacker-controlled chat titles. This makes it possible for unauthenticated attackers to inject malicious scripts via Telegram chat titles that execute when an administrator opens the TelSender settings page and clicks the "Tested" button.

PLUGIN TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot

CVE-2026-15298

HIGH CVSS 7.2 2026-07-10
Threat Entry Updated 2026-07-10

CVE-2026-15301 - Buddyholis Tablesearch Plugin

The BuddyHolis TableSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Buddyholis Tablesearch

CVE-2026-15301

MEDIUM CVSS 6.4 2026-07-10
Scroll to top