Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,559
Critical940
High3,162
Medium11,246
Reset
Showing 2381-2400 of 15559 records
Threat Entry Updated 2026-06-17

CVE-2026-24605 - X Addons for Elementor Plugin

Missing Authorization vulnerability in pencilwp X Addons for Elementor x-addons-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects X Addons for Elementor: from n/a through

PLUGIN X Addons for Elementor

CVE-2026-24605

MEDIUM CVSS 4.3 2026-01-23
Threat Entry Updated 2026-06-17

CVE-2026-24591 - Turn Yoast SEO FAQ Block to Accordion Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yasir129 Turn Yoast SEO FAQ Block to Accordion faq-schema-block-to-accordion allows Stored XSS.This issue affects Turn Yoast SEO FAQ Block to Accordion: from n/a through

PLUGIN Turn Yoast SEO FAQ Block to Accordion

CVE-2026-24591

MEDIUM CVSS 6.5 2026-01-23
Threat Entry Updated 2026-06-17

CVE-2026-24593 - AWP Classifieds Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Retrieve Embedded Sensitive Data.This issue affects AWP Classifieds: from n/a through

PLUGIN AWP Classifieds

CVE-2026-24593

MEDIUM CVSS 5.3 2026-01-23
Threat Entry Updated 2026-06-17

CVE-2026-24596 - Related Posts Thumbnails Plugin for WordPress

Cross-Site Request Forgery (CSRF) vulnerability in marynixie Related Posts Thumbnails Plugin for WordPress related-posts-thumbnails allows Cross Site Request Forgery.This issue affects Related Posts Thumbnails Plugin for WordPress: from n/a through

PLUGIN Related Posts Thumbnails Plugin for WordPress

CVE-2026-24596

MEDIUM CVSS 4.7 2026-01-23
Threat Entry Updated 2026-06-17

CVE-2026-24585 - WooCommerce Plugin

Missing Authorization vulnerability in Hyyan Abo Fakher Hyyan WooCommerce Polylang Integration woo-poly-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hyyan WooCommerce Polylang Integration: from n/a through

PLUGIN WooCommerce

CVE-2026-24585

MEDIUM CVSS 6.5 2026-01-23
Threat Entry Updated 2026-06-17

CVE-2026-24581 - WooCommerce Plugin

Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce points-and-rewards-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Points and Rewards for WooCommerce: from n/a through

PLUGIN WooCommerce

CVE-2026-24581

MEDIUM CVSS 5.4 2026-01-23
Threat Entry Updated 2026-06-17

CVE-2026-24583 - WooCommerce Plugin

Missing Authorization vulnerability in sumup SumUp Payment Gateway For WooCommerce sumup-payment-gateway-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SumUp Payment Gateway For WooCommerce: from n/a through

PLUGIN WooCommerce

CVE-2026-24583

MEDIUM CVSS 5.3 2026-01-23
Threat Entry Updated 2026-06-17

CVE-2026-24559 - Integration for Contact Form 7 HubSpot Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in CRM Perks Integration for Contact Form 7 HubSpot cf7-hubspot allows Retrieve Embedded Sensitive Data.This issue affects Integration for Contact Form 7 HubSpot: from n/a through

PLUGIN Integration for Contact Form 7 HubSpot

CVE-2026-24559

MEDIUM CVSS 5.4 2026-01-23
Threat Entry Updated 2026-06-17

CVE-2026-24562 - WooCommerce Plugin

Missing Authorization vulnerability in Ryviu Ryviu – Product Reviews for WooCommerce ryviu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ryviu – Product Reviews for WooCommerce: from n/a through

PLUGIN WooCommerce

CVE-2026-24562

MEDIUM CVSS 5.3 2026-01-23
Threat Entry Updated 2026-06-17

CVE-2026-24557 - Contact Form 7 GetResponse Extension Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in WEN Solutions Contact Form 7 GetResponse Extension contact-form-7-getresponse-extension allows Retrieve Embedded Sensitive Data.This issue affects Contact Form 7 GetResponse Extension: from n/a through

PLUGIN Contact Form 7 GetResponse Extension

CVE-2026-24557

MEDIUM CVSS 5.3 2026-01-23
Threat Entry Updated 2026-06-17

CVE-2026-24553 - WooCommerce Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers allows Retrieve Embedded Sensitive Data.This issue affects Fraud Prevention For Woocommerce: from n/a through

PLUGIN WooCommerce

CVE-2026-24553

MEDIUM CVSS 4.3 2026-01-23
Threat Entry Updated 2026-06-17

CVE-2026-24526 - WooCommerce Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steve Truman Email Inquiry & Cart Options for WooCommerce woocommerce-email-inquiry-cart-options allows DOM-Based XSS.This issue affects Email Inquiry & Cart Options for WooCommerce: from n/a through

PLUGIN WooCommerce

CVE-2026-24526

MEDIUM CVSS 6.5 2026-01-23
Threat Entry Updated 2026-01-26

CVE-2025-13921 - Wedocs Plugin

The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to unauthorized modification or loss of data due to a missing capability check on the 'wedocs_user_documentation_handling_capabilities' function in all versions up to, and including, 2.1.16. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit any documentation post. The vulnerability was partially patched in version 2.1.16.

PLUGIN Wedocs

CVE-2025-13921

MEDIUM CVSS 4.3 2026-01-23
Threat Entry Updated 2026-06-17

CVE-2026-0914 - Shapepress Dsgvo Plugin

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lw_content_block' shortcode in all versions up to, and including, 3.1.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Shapepress Dsgvo

CVE-2026-0914

MEDIUM CVSS 6.4 2026-01-23
Threat Entry Updated 2026-01-26

CVE-2025-14866 - Melapress Role Editor Plugin

The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.1. This is due to a misconfigured capability check on the 'save_secondary_roles_field' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to assign themselves additional roles including Administrator.

PLUGIN Melapress Role Editor

CVE-2025-14866

HIGH CVSS 8.8 2026-01-23
Threat Entry Updated 2026-01-26

CVE-2024-11976 - The Buddypress Plugin

The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 14.3.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN The Buddypress

CVE-2024-11976

HIGH CVSS 7.3 2026-01-23
Threat Entry Updated 2026-01-26

CVE-2025-14745 - Wp Rss Aggregator Plugin

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-rss-aggregator' shortcode in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Rss Aggregator

CVE-2025-14745

MEDIUM CVSS 6.4 2026-01-23
Threat Entry Updated 2026-06-17

CVE-2026-0927 - Kivicare Clinic Management System Plugin

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization checks in the uploadMedicalReport() function in all versions up to, and including, 3.6.15. This makes it possible for unauthenticated attackers to upload text files and PDF documents to the affected site's server which may be leveraged for further attacks such as hosting malicious content or phishing pages via PDF files.

PLUGIN Kivicare Clinic Management System

CVE-2026-0927

MEDIUM CVSS 5.3 2026-01-23
Threat Entry Updated 2026-01-26

CVE-2025-14069 - Schema And Structured Data For Wp Plugin

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saswp_custom_schema_field' profile field in all versions up to, and including, 1.54 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Schema And Structured Data For Wp

CVE-2025-14069

MEDIUM CVSS 6.4 2026-01-23
Threat Entry Updated 2026-01-26

CVE-2025-15522 - Uncanny Automator Plugin

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automator_discord_user_mapping shortcode in all versions up to, and including, 6.10.0.2 due to insufficient input sanitization and output escaping on the verified_message parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user with a verified Discord account accesses the injected page.

PLUGIN Uncanny Automator

CVE-2025-15522

MEDIUM CVSS 6.4 2026-01-23
Scroll to top