Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,479
Critical934
High3,137
Medium11,193
Reset
Showing 21-40 of 15479 records
Threat Entry Updated 2026-07-20

CVE-2026-8825 - Elementor Website Builder Plugin

The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authenticated users with Contributor-level access and above to retrieve the title, body and metadata of private posts, private pages and drafts authored by other users (including administrators).

PLUGIN Elementor Website Builder

CVE-2026-8825

MEDIUM CVSS 4.9 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-13147 - Before 6 Plugin

The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).

PLUGIN Before 6

CVE-2026-13147

CRITICAL CVSS 9.1 2026-07-20
Threat Entry Updated 2026-07-21

CVE-2026-13142 - Email Otp Plugin

The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email address to brute-force the code and log in as that user, including an administrator, leading to full site takeover.

PLUGIN Email Otp

CVE-2026-13142

HIGH CVSS 8.1 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12970 - Before 4 Plugin

The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a crafted link.

PLUGIN Before 4

CVE-2026-12970

HIGH CVSS 7.1 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12973 - Payplus Payment Gateway Plugin

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some configurations, to modify order statuses.

PLUGIN Payplus Payment Gateway

CVE-2026-12973

MEDIUM CVSS 6.5 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12898 - All In One Wp Migration And Backup Plugin

The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations outside its intended storage directory.

PLUGIN All In One Wp Migration And Backup

CVE-2026-12898

MEDIUM CVSS 6.5 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-13432 - Ticated Users With Subscriber Level Access Or Higher To Deactivate The Thumbpress Plugin

The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher to deactivate the ThumbPress WordPress plugin before 6.2.2, disrupting the site's image-handling functionality.

PLUGIN Ticated Users With Subscriber Level Access Or Higher To Deactivate The Thumbpress

CVE-2026-13432

MEDIUM CVSS 5.4 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-13156 - A Logged In Administrator Into Visiting A Crafted Page That Wipes The Mailersend Plugin

The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's SMTP configuration and deactivates the MailerSend WordPress plugin before 1.0.8, breaking the site's email delivery.

PLUGIN A Logged In Administrator Into Visiting A Crafted Page That Wipes The Mailersend

CVE-2026-13156

MEDIUM CVSS 5.4 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12972 - Payplus Payment Gateway Plugin

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.

PLUGIN Payplus Payment Gateway

CVE-2026-12972

MEDIUM CVSS 5.3 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-11349 - Modern Event Calendar Pro Plugin

The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection vulnerability that allows attackers to extract sensitive data from the database.

PLUGIN Modern Event Calendar Pro

CVE-2026-11349

HIGH CVSS 8.6 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12592 - Slimstat Analytics Plugin

The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browser of an administrator who views the reports. Exploitation requires the SlimStat Analytics WordPress plugin before 5.5.0 to be configured to use the Cloudflare geolocation provider.

PLUGIN Slimstat Analytics

CVE-2026-12592

HIGH CVSS 7.5 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12723 - Before 6 Plugin

The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment moderation.

PLUGIN Before 6

CVE-2026-12723

MEDIUM CVSS 5.3 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-11868 - Wp Travel Plugin

The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.

PLUGIN Wp Travel

CVE-2026-11868

MEDIUM CVSS 5.3 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-10724 - Reviews Feed Plugin

The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the connected source.

PLUGIN Reviews Feed

CVE-2026-10724

MEDIUM CVSS 4.8 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12724 - Before 6 Plugin

The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivered to a registered user, which can be used for phishing.

PLUGIN Before 6

CVE-2026-12724

MEDIUM CVSS 4.3 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-10755 - All In One Seo Plugin

The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.

PLUGIN All In One Seo

CVE-2026-10755

LOW CVSS 2.7 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-10081 - Unlimited Elements For Elementor Plugin

The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malicious review on the targeted business's Google listing to deliver Stored XSS to any visitor (including administrators) of any WP page displaying that Place ID's reviews.

PLUGIN Unlimited Elements For Elementor

CVE-2026-10081

HIGH CVSS 8.8 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-57857 - Flow Payment Plugin

The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the WooCommerce checkout page. When the plugin handles an order cancellation, the error_message GET parameter is passed directly to wc_add_notice() in flowpayment-fl.php (lines 57-58) without input sanitization (for example sanitize_text_field()) or output escaping (for example esc_html()) before being rendered in the checkout notice HTML. An unauthenticated attacker can craft a URL containing a JavaScript payload in the error_message parameter (for example /checkout/?add-to-cart={product-id}&cancel_order=true&error_message={payload}); when a victim with an active WooCommerce checkout session follows the link,…

PLUGIN Flow Payment

CVE-2026-57857

MEDIUM CVSS 5.1 2026-07-18
Threat Entry Updated 2026-07-20

CVE-2026-9734 - W3sc Elementor To Zoho Plugin

The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the storeInfo function. This makes it possible for unauthenticated attackers to modify the plugin's Zoho CRM integration settings, replacing the configured data center, client ID, client secret, and user email credentials with attacker-controlled values via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN W3sc Elementor To Zoho

CVE-2026-9734

MEDIUM CVSS 4.3 2026-07-18
Threat Entry Updated 2026-07-17

CVE-2026-9656 - Leadin Plugin

The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.62 via the wp_localize_script() / window.leadinConfig JavaScript object. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the site's plaintext HubSpot OAuth refresh token exposed via the window.leadinConfig JavaScript object, which can then be used to access or modify data in the connected HubSpot tenant. Although the refresh token is stored at rest with AES-256-CTR encryption, decryption occurs server-side before…

PLUGIN Leadin

CVE-2026-9656

MEDIUM CVSS 4.3 2026-07-17
Scroll to top