Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total14,712
Critical880
High2,932
Medium10,703
Reset
Showing 201-220 of 14712 records
Threat Entry Updated 2026-05-18

CVE-2026-1631 - Before 2 Plugin

The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is vulnerable to unauthorized modification of the Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4's license key due to a missing capability check on the 'actions' function. This makes it possible for subscribers and above delete the license key.

PLUGIN Before 2

CVE-2026-1631

MEDIUM CVSS 5.4 2026-05-18
Threat Entry Updated 2026-05-18

CVE-2026-8719 - AI Engine – The Chatbot, AI Framework & MCP for WordPress Plugin

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be granted without verifying administrator privileges. This makes it possible for authenticated (Subscriber+) attackers to invoke admin-level MCP tools and escalate privileges to Administrator.

PLUGIN AI Engine – The Chatbot, AI Framework & MCP for WordPress

CVE-2026-8719

HIGH CVSS 8.8 2026-05-17
Threat Entry Updated 2026-05-18

CVE-2026-8681 - Essential Chat Support Plugin

The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to reset all plugin configuration settings — including general settings, display rules, custom CSS, and WooCommerce tab settings — to their defaults by sending a POST request with ecs_reset_settings=1.

PLUGIN Essential Chat Support

CVE-2026-8681

MEDIUM CVSS 5.3 2026-05-16
Threat Entry Updated 2026-05-15

CVE-2026-6415 - Advanced Custom Fields Font Awesome Plugin

The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.0.2. This is due to insufficient input validation of JSON field values and unsafe client-side HTML construction in the update_preview() JavaScript function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Advanced Custom Fields Font Awesome

CVE-2026-6415

MEDIUM CVSS 6.4 2026-05-15
Threat Entry Updated 2026-05-15

CVE-2026-7046 - Nex Forms Express Wp Form Builder Plugin

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'table' parameter in all versions up to, and including, 9.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Nex Forms Express Wp Form Builder

CVE-2026-7046

MEDIUM CVSS 4.9 2026-05-15
Threat Entry Updated 2026-05-15

CVE-2026-8425 - Notify Odoo Plugin

The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the _updateSettings function. This makes it possible for unauthenticated attackers to change the Notify Odoo URL to an attacker-controlled URL and modify notification, tracking image, and allowed IP address settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Notify Odoo

CVE-2026-8425

MEDIUM CVSS 4.3 2026-05-15
Threat Entry Updated 2026-05-15

CVE-2026-7563 - Business Directory Plugin

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.3.10. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to add arbitrary notes to any order and trigger unsolicited notification and moderation emails to listing owners without administrative authorization.

PLUGIN Business Directory

CVE-2026-7563

MEDIUM CVSS 4.3 2026-05-15
Threat Entry Updated 2026-05-15

CVE-2026-5229 - Form Notify Plugin

The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting user-controlled cookie data to determine which WordPress account to authenticate after a LINE OAuth login. When LINE doesn't provide an email address (which is common), the plugin falls back to reading the 'form_notify_line_email' cookie value without verifying that the LINE account is associated with that email address. This makes it possible for unauthenticated attackers to gain access to any user account on the site, including…

PLUGIN Form Notify

CVE-2026-5229

CRITICAL CVSS 9.8 2026-05-15
Threat Entry Updated 2026-05-15

CVE-2026-6228 - Acf Frontend Form Element Plugin

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to insufficient authorization checks in the role field update mechanism combined with overly permissive capabilities for the admin_form post type. The admin_form custom post type uses 'capability_type' => 'page', which grants editors the ability to create and edit forms. When an editor creates an edit_user form, they can manipulate the form configuration to include 'administrator' in the role_options array by directly submitting POST data to wp-admin/post.php, bypassing…

PLUGIN Acf Frontend Form Element

CVE-2026-6228

HIGH CVSS 8.8 2026-05-15
Threat Entry Updated 2026-05-15

CVE-2026-6403 - Quick Playground Plugin

The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is due to insufficient path validation in the qckply_zip_theme() function, which appends a user-controlled 'stylesheet' parameter directly to the theme root directory path without sanitizing directory traversal sequences. This makes it possible for unauthenticated attackers to trigger the creation of a ZIP archive containing arbitrary files from the server's filesystem — including wp-config.

PLUGIN Quick Playground

CVE-2026-6403

HIGH CVSS 7.5 2026-05-15
Threat Entry Updated 2026-05-15

CVE-2026-4683 - Smartcat Translator For Wpml Plugin

The Smartcat Translator for WPML plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'routeData' REST endpoint in all versions up to, and including, 3.1.77. This makes it possible for unauthenticated attackers to overwrite the plugin's Smartcat API credentials (account ID, API secret key, hub key, API host, and hub host), effectively hijacking the translation service or causing a denial of service.

PLUGIN Smartcat Translator For Wpml

CVE-2026-4683

MEDIUM CVSS 6.5 2026-05-15
Threat Entry Updated 2026-05-15

CVE-2026-4094 - Currency Switcher Professional For Woocommerce Plugin

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete the entire multi-currency configuration by visiting any wp-admin page with the `woocs_reset` parameter appended. Additionally, because no nonce is verified, this is also exploitable via Cross-Site Request Forgery against any administrator. The vulnerability may also be exploited by Subscriber-level users if…

PLUGIN Currency Switcher Professional For Woocommerce

CVE-2026-4094

HIGH CVSS 8.1 2026-05-15
Threat Entry Updated 2026-05-15

CVE-2026-6646 - Dt The7 Plugin

The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all versions up to, and including, 14.3.2. This is due to insufficient input sanitization and output escaping on the 'title' component of the 'link' shortcode parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Dt The7

CVE-2026-6646

MEDIUM CVSS 6.4 2026-05-15
Threat Entry Updated 2026-05-14

CVE-2026-4030 - Database Backup For Wordpress Plugin

The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check combined with a user-controlled backup directory parameter. This makes it possible for unauthenticated attackers to read and delete arbitrary files on the server, leading to Sensitive Information Exposure and potential site takeover. Note: This vulnerability is only exploitable in WordPress Multisite environments where the deprecated is_site_admin() function exists.

PLUGIN Database Backup For Wordpress

CVE-2026-4030

HIGH CVSS 8.1 2026-05-14
Threat Entry Updated 2026-05-14

CVE-2026-4031 - Database Backup For Wordpress Plugin

The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due to the plugin not restricting access to the wp_db_temp_dir parameter, which controls where database backups are written. This makes it possible for unauthenticated attackers to send a request to wp-cron.php with a poisoned wp_db_temp_dir value pointing to a publicly accessible directory (e.g., wp-content/uploads/), and if a scheduled backup is due, intercept the backup file before it is cleaned up. The backup file has a predictable name…

PLUGIN Database Backup For Wordpress

CVE-2026-4031

HIGH CVSS 7.5 2026-05-14
Threat Entry Updated 2026-05-14

CVE-2026-4029 - Database Backup For Wordpress Plugin

The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check. This makes it possible for unauthenticated attackers to export database tables, leading to Sensitive Information Exposure. Note: This vulnerability is only exploitable in WordPress Multisite environments where the deprecated is_site_admin() function exists.

PLUGIN Database Backup For Wordpress

CVE-2026-4029

HIGH CVSS 7.5 2026-05-14
Threat Entry Updated 2026-05-14

CVE-2026-6514 - Infusedwoo Pro Plugin

The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Infusedwoo Pro

CVE-2026-6514

HIGH CVSS 7.5 2026-05-14
Threat Entry Updated 2026-05-14

CVE-2026-6512 - Infusedwoo Pro Plugin

The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages, products, or orders, mass-delete all comments on any post, and change any post's status.

PLUGIN Infusedwoo Pro

CVE-2026-6512

CRITICAL CVSS 9.1 2026-05-14
Threat Entry Updated 2026-05-14

CVE-2026-6504 - Royal Addons for Elementor – Addons and Templates Kit for Elementor Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Royal Addons for Elementor – Addons and Templates Kit for Elementor

CVE-2026-6504

MEDIUM CVSS 6.4 2026-05-14
Threat Entry Updated 2026-05-14

CVE-2026-6174 - Cc Child Pages Plugin

The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'more' parameter in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Cc Child Pages

CVE-2026-6174

MEDIUM CVSS 6.4 2026-05-14
Scroll to top