Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,479
Critical934
High3,137
Medium11,193
Reset
Showing 281-300 of 15479 records
Threat Entry Updated 2026-07-09

CVE-2026-12516 - Fediverse Embeds Plugin

The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media-proxying endpoint, allowing anonymous users to make the site fetch arbitrary URLs, including internal and private-network addresses, and read back the response body. This results in a full-read Server-Side Request Forgery and open proxy.

PLUGIN Fediverse Embeds

CVE-2026-12516

MEDIUM CVSS 5.3 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-11875 - Wp Support Plus Responsive Ticket System Plugin

The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticated attackers to forge it and impersonate any ticket owner (identified by email address) to read, reply to, and close that person's support tickets.

PLUGIN Wp Support Plus Responsive Ticket System

CVE-2026-11875

MEDIUM CVSS 5.3 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-11571 - Everest Forms Plugin

The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission records via predictable, enumerable filenames.

PLUGIN Everest Forms

CVE-2026-11571

HIGH CVSS 7.5 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-11869 - Before 3 Plugin

The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject access request feature, allowing unauthenticated attackers to generate and download the full personal-data export (including name, postal address, phone number, email, and comment content) of any user, customer, or commenter by supplying their email address.

PLUGIN Before 3

CVE-2026-11869

MEDIUM CVSS 5.3 2026-07-09
Threat Entry Updated 2026-07-09

CVE-2026-5523 - Divi Form Builder Plugin

The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. This is due to the update_user() function accepting a user ID parameter from form submissions without verifying that the authenticated user has permission to edit that specific user account, and the handle_register_submission() function only checking if any user is logged in rather than validating permissions for the target user. This makes it possible for authenticated attackers, with subscriber-level access and above, to change the email address and password of any user…

PLUGIN Divi Form Builder

CVE-2026-5523

HIGH CVSS 8.8 2026-07-09
Threat Entry Updated 2026-07-08

CVE-2026-58480 - Blocksy Companion Plugin

Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension filenames such as shell.woff2.php, causing the validation to pass on the substring match while the web server executes the file as PHP, achieving remote code execution.

PLUGIN Blocksy Companion

CVE-2026-58480

CRITICAL CVSS 9.2 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-6820 - VikBooking Hotel Booking Engine & PMS Plugin

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN VikBooking Hotel Booking Engine & PMS

CVE-2026-6820

HIGH CVSS 7.2 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-6740 - Ai Website Builder Plugin

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'commentIcon' parameter in all versions up to, and including, 4.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ai Website Builder

CVE-2026-6740

MEDIUM CVSS 6.4 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-6459 - Essential Addons for Elementor – Popular Elementor Templates & Widgets Plugin

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping on event titles sourced from The Events Calendar. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Essential Addons for Elementor – Popular Elementor Templates & Widgets

CVE-2026-6459

MEDIUM CVSS 6.4 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-5356 - LatePoint – Calendar Booking Plugin for Appointments and Events

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 5.4.0. This is due to the plugin's Stripe Connect payment processor accepting a client-supplied PaymentIntent ID. This makes it possible for unauthenticated attackers to pay an arbitrary amount by supplying a previously succeeded PaymentIntent token.

PLUGIN LatePoint – Calendar Booking Plugin for Appointments and Events

CVE-2026-5356

HIGH CVSS 7.5 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-5459 - User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration Plugin

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.1 via the payment_page() function due to missing validation on the 'user_id' user controlled key. This makes it possible for unauthenticated attackers to activate a free subscription pack for any user on the site, overwriting their existing paid subscription and causing loss of paid features.

PLUGIN User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration

CVE-2026-5459

MEDIUM CVSS 5.3 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-12002 - Smash Balloon Social Photo Feed – Easy Social Feeds Plugin

The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.11.1. This is due to missing or incorrect nonce validation on the maybe_connection_data function. This makes it possible for unauthenticated attackers to overwrite the site's Instagram and Facebook oEmbed access tokens via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Smash Balloon Social Photo Feed – Easy Social Feeds Plugin

CVE-2026-12002

MEDIUM CVSS 4.7 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-6854 - My Calendar – Accessible Event Manager Plugin

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'mc_auth' parameter in all versions up to, and including, 3.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN My Calendar – Accessible Event Manager

CVE-2026-6854

HIGH CVSS 7.5 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-6818 - VikBooking Hotel Booking Engine & PMS Plugin

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'special_requests' parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN VikBooking Hotel Booking Engine & PMS

CVE-2026-6818

HIGH CVSS 7.2 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-3688 - WCFM Membership – WooCommerce Memberships for Multivendor Marketplace Plugin

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. This makes it possible for authenticated attackers, with vendor level access and above, to change any user's role to 'wcfm_vendor' by changing their membership plan.

PLUGIN WCFM Membership – WooCommerce Memberships for Multivendor Marketplace

CVE-2026-3688

HIGH CVSS 8.1 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-6230 - Tainacan Plugin

The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all versions up to and including 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Tainacan

CVE-2026-6230

HIGH CVSS 7.5 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-6742 - Advanced Iframe Plugin

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Advanced Iframe

CVE-2026-6742

MEDIUM CVSS 6.4 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-14250 - Themehunk Login Registration Plugin

The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.2. This is due to the handle_frontend_register() function in the unauthenticated /thlogin/v1/register REST endpoint accepting a user-controlled 'role' parameter and validating it only against get_editable_roles() — which returns every defined editable site role, including 'editor' — before passing it to wp_insert_user(). This makes it possible for unauthenticated attackers, when public user registration is enabled, to create new accounts with the editor role.

PLUGIN Themehunk Login Registration

CVE-2026-14250

MEDIUM CVSS 6.3 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-12936 - Recurio – Ultimate Subscription for WooCommerce Plugin

The Recurio – Ultimate Subscription for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, and including, 1.1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Recurio – Ultimate Subscription for WooCommerce

CVE-2026-12936

MEDIUM CVSS 4.9 2026-07-08
Threat Entry Updated 2026-07-08

CVE-2026-12378 - Appointment Booking Calendar Plugin and Scheduling Plugin

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution.

PLUGIN Appointment Booking Calendar Plugin and Scheduling Plugin

CVE-2026-12378

HIGH CVSS 8.1 2026-07-08
Scroll to top