Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total14,712
Critical880
High2,932
Medium10,703
Reset
Showing 381-400 of 14712 records
Threat Entry Updated 2026-05-05

CVE-2026-6447 - Woocommerce Call For Price Plugin

The Call for Price for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Woocommerce Call For Price

CVE-2026-6447

MEDIUM CVSS 4.4 2026-05-02
Threat Entry Updated 2026-05-05

CVE-2026-5112 - Gravity Forms Plugin

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping of Calculation Product field product names when rendered inside Repeater fields. The validate() method in the GF_Field_Calculation class only validates the quantity field (.3) and completely ignores the product name field (.1), allowing malicious HTML to pass through validation. When the value is saved, the sanitize_entry_value() method returns the raw value without sanitization for fields where HTML is not expected.…

PLUGIN Gravity Forms

CVE-2026-5112

HIGH CVSS 7.2 2026-05-02
Threat Entry Updated 2026-05-05

CVE-2026-5111 - Gravity Forms Plugin

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping on Hidden Product field values when used inside Repeater fields, where repeater subfields bypass state validation checks and the Hidden Product validate() method only validates the quantity field while ignoring the product name field that is later output without proper escaping in the get_value_entry_detail() method. This makes it possible for unauthenticated attackers to inject arbitrary web scripts through form submissions that…

PLUGIN Gravity Forms

CVE-2026-5111

HIGH CVSS 7.2 2026-05-02
Threat Entry Updated 2026-05-05

CVE-2026-5110 - Gravity Forms Plugin

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping in the SingleProduct field when used inside a Repeater field. When SingleProduct fields are nested within Repeater fields, the validation flow bypasses the state validation mechanism (failed_state_validation()) that would normally prevent tampering with field values. The validate_subfield() method only calls the field's validate() method, which for SingleProduct fields only validates the quantity field and does not check the product name…

PLUGIN Gravity Forms

CVE-2026-5110

HIGH CVSS 7.2 2026-05-02
Threat Entry Updated 2026-05-05

CVE-2026-5109 - Gravity Forms Plugin

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and output escaping of Product Option field values. The vulnerability exists because the state validation function accepts submitted values where the wp_kses()-sanitized version matches a legitimate option value, but then stores the raw unsanitized value in the database. When administrators view entry details via the Order Summary section, the option_label is output directly without escaping (view-order-summary.php line 32), executing the injected JavaScript. This makes it…

PLUGIN Gravity Forms

CVE-2026-5109

HIGH CVSS 7.2 2026-05-02
Threat Entry Updated 2026-05-05

CVE-2026-7458 - User Verification Plugin

The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP codes in the "user_verification_form_wrap_process_otpLogin" function. This makes it possible for unauthenticated attackers to log in as any user with a verified email address, such as an administrator, by submitting a "true" OTP value.

PLUGIN User Verification

CVE-2026-7458

CRITICAL CVSS 9.8 2026-05-02
Threat Entry Updated 2026-05-05

CVE-2026-7641 - Import And Export Users And Customers Plugin

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an incomplete blocklist that correctly restricts capability meta keys for the primary site (e.g., `wp_capabilities`, `wp_user_level`) but fails to block the equivalent meta keys for any other subsite in a WordPress Multisite network (e.g., `wp_2_capabilities`, `wp_2_user_level`), allowing these keys to pass the `in_array()` check and be written directly to user meta via `update_user_meta()`. This makes it possible for authenticated…

PLUGIN Import And Export Users And Customers

CVE-2026-7641

HIGH CVSS 8.8 2026-05-02
Threat Entry Updated 2026-05-05

CVE-2026-6963 - Wp Mail Gateway Plugin

The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wmg_save_provider_config AJAX action in all versions up to, and including, 1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update SMTP settings and redirect mail which can be used for privilege escalation by triggering a password reset email and using that to access and administrator's account.

PLUGIN Wp Mail Gateway

CVE-2026-6963

HIGH CVSS 8.8 2026-05-02
Threat Entry Updated 2026-05-05

CVE-2026-6446 - My Social Feeds Plugin

The My Social Feeds – Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 1.0.4 via the 'ttp_get_accounts' AJAX action. This is due to the complete absence of authorization checks (no capability verification) and nonce verification in the get_accounts() function, which returns the full contents of the 'ttp_tiktok_accounts' WordPress option. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive TikTok OAuth credentials, including access_token and refresh_token values, that belong to administrator-connected TikTok accounts, enabling…

PLUGIN My Social Feeds

CVE-2026-6446

MEDIUM CVSS 5.4 2026-05-02
Threat Entry Updated 2026-05-05

CVE-2026-4882 - User Registration Advanced Fields Plugin

The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'URAF_AJAX::method_upload' function in all versions up to, and including, 1.6.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vulnerability can only be exploited if a "Profile Picture" field is added to the form.

PLUGIN User Registration Advanced Fields

CVE-2026-4882

CRITICAL CVSS 9.8 2026-05-02
Threat Entry Updated 2026-05-05

CVE-2026-4658 - Essential Blocks Plugin

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the className, classHook, and blockId attributes in the Add to Cart block (essential-blocks/add-to-cart) in all versions up to, and including, 6.0.4. This is due to insufficient output escaping in the render_callback() function where these attributes are placed into class and data-id HTML attributes using raw sprintf() and implode() without esc_attr() escaping. While the outer wrapper div uses get_block_wrapper_attributes() which properly escapes, the inner divs do not. This makes it…

PLUGIN Essential Blocks

CVE-2026-4658

MEDIUM CVSS 6.4 2026-05-02
Threat Entry Updated 2026-05-05

CVE-2026-7209 - Simple Link Directory Plugin

The Simple Link Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `qcopd-directory` shortcode in all versions up to, and including, 8.9.2. This is due to insufficient input sanitization and output escaping on user supplied attributes such as `title_font_size`. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Simple Link Directory

CVE-2026-7209

MEDIUM CVSS 6.4 2026-05-02
Threat Entry Updated 2026-05-05

CVE-2026-7638 - App Builder Plugin

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 5.6.0. This is due to missing authorization validation in the `upload_avatar()` function, which accepts an attacker-controlled `user_id` parameter from the POST request body and uses it to update user meta without verifying that the authenticated requester owns or has permission to modify the target account. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the…

PLUGIN App Builder

CVE-2026-7638

MEDIUM CVSS 5.3 2026-05-02
Threat Entry Updated 2026-05-05

CVE-2026-6378 - Maxi Blocks Plugin

The Maxi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `/wp-json/maxi-blocks/v1.0/style-card` REST API endpoint in all versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping of the `sc_styles` parameter. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts that execute on every page where the plugin's style card styles are loaded, including across the entire WordPress admin panel.

PLUGIN Maxi Blocks

CVE-2026-6378

MEDIUM CVSS 6.4 2026-05-02
Threat Entry Updated 2026-05-01

CVE-2026-3143 - Boldgrid Backup Plugin

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_cli_cancel' function in all versions up to, and including, 1.17.1. This makes it possible for unauthenticated attackers to cancel a pending rollback, potentially preventing a WordPress installation from automatically reverting a failed update.

PLUGIN Boldgrid Backup

CVE-2026-3143

MEDIUM CVSS 5.3 2026-05-01
Threat Entry Updated 2026-05-01

CVE-2026-3772 - Wp Editor Plugin

The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9.2. This is due to missing nonce verification in the 'add_plugins_page' and 'add_themes_page' functions. This makes it possible for unauthenticated attackers to overwrite arbitrary plugin and theme PHP files with attacker-controlled code via a forged request, granted they can trick a site administrator into performing an action such as clicking a link.

PLUGIN Wp Editor

CVE-2026-3772

HIGH CVSS 8.8 2026-05-01
Threat Entry Updated 2026-05-01

CVE-2026-3140 - Ultimate Dashboard Plugin

The Ultimate Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.14. This is due to a flawed nonce validation conditional in the 'handle_module_actions' function. This makes it possible for unauthenticated attackers to toggle plugin modules on or off via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Ultimate Dashboard

CVE-2026-3140

MEDIUM CVSS 4.3 2026-05-01
Threat Entry Updated 2026-05-01

CVE-2026-7567 - Temporary Login Plugin

The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. This is due to improper input validation in the maybe_login_temporary_user() function, which fails to verify that the 'temp-login-token' GET parameter is a scalar string before processing it. When the parameter is supplied as an array, PHP's empty() check is bypassed and sanitize_key() returns an empty string, which is then passed as the meta_value to get_users(). WordPress ignores an empty meta_value and returns all users matching the meta_key '_temporary_login_token', allowing authentication without a…

PLUGIN Temporary Login

CVE-2026-7567

CRITICAL CVSS 9.8 2026-05-01
Threat Entry Updated 2026-05-01

CVE-2026-6127 - Elementor Website Builder Plugin

The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _elementor_data meta field in versions up to, and including, 4.0.4. This is due to insufficient input sanitization when processing form-encoded REST API requests. The plugin registers the _elementor_data meta field with show_in_rest but omits a sanitize_callback, relying instead on a rest_pre_insert_post filter (sanitize_post_data function) that only sanitizes JSON-encoded request bodies. When a contributor sends a form-encoded PATCH request to the WordPress REST API, the json_decode() call on the raw body returns null, causing all sanitization…

PLUGIN Elementor Website Builder

CVE-2026-6127

MEDIUM CVSS 6.4 2026-05-01
Threat Entry Updated 2026-04-30

CVE-2026-2892 - Otter Blocks Plugin

The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3.1.4. This is due to the 'get_customer_data' method relying on an unsigned 'o_stripe_data' cookie to determine Stripe product ownership for unauthenticated users. The 'check_purchase' method trusts this cookie data without performing server-side verification against the Stripe API for one-time 'payment' mode purchases. This makes it possible for unauthenticated attackers to bypass Stripe purchase-gated content visibility conditions by forging the 'o_stripe_data' cookie with a target product ID, which is publicly exposed in…

PLUGIN Otter Blocks

CVE-2026-2892

HIGH CVSS 7.5 2026-04-30
Scroll to top