sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total17,710
Critical1,270
High4,022
Medium12,142
Reset
Showing 21-40 of 17710 records
Threat Entry Updated 2026-09-03

Learnpress - Security Vulnerability (CVE-2026-82023)

LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to persistently modify quiz content across courses they do not own.

PLUGIN Learnpress

CVE-2026-82023

MEDIUM CVSS 5.3 2026-09-03
Threat Entry Updated 2026-09-03

Learnpress - Security Vulnerability (CVE-2026-82024)

LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persistent malicious payloads by submitting unsanitized input into quiz question answer title fields. Attackers can store arbitrary JavaScript through the answer title parameter, which is rendered through an unescaped HTML sink to execute in the browsers of any user who views the affected quiz question, including students, other instructors, and administrators.

PLUGIN Learnpress

CVE-2026-82024

MEDIUM CVSS 5.1 2026-09-03
Threat Entry Updated 2026-09-03

Elementor - Security Vulnerability (CVE-2026-85302)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects WPKoi Templates for Elementor: from n/a through 3.7.2.

PLUGIN Elementor

CVE-2026-85302

MEDIUM CVSS 6.5 2026-09-03
Threat Entry Updated 2026-09-03

Elementor - Security Vulnerability (CVE-2026-85304)

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.17.

PLUGIN Elementor

CVE-2026-85304

MEDIUM CVSS 5.3 2026-09-03