Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,479
Critical934
High3,137
Medium11,193
Reset
Showing 421-440 of 15479 records
Threat Entry Updated 2026-07-01

CVE-2026-12902 - Kadence Blocks — Page Builder Toolkit for Gutenberg Editor Plugin

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to create arbitrary Media Library attachments by downloading remote images to the site's uploads directory via wp_upload_bits() and wp_insert_attachment(), bypassing the upload_files capability boundary.

PLUGIN Kadence Blocks — Page Builder Toolkit for Gutenberg Editor

CVE-2026-12902

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12133 - JoomSport – for Sports: Team & League, Football, Hockey & more Plugin

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Group Deletion in versions up to, and including, 5.7.8. This is due to a missing capability check in the joomsport_season_groupdel() AJAX handler, which only verifies a nonce before executing a DELETE query on attacker-supplied group IDs. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary JoomSport group records.

PLUGIN JoomSport – for Sports: Team & League, Football, Hockey & more

CVE-2026-12133

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12113 - Appointment Booking Calendar Plugin

The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, with contributor-level access and above, to extract customer names, email addresses, phone numbers, appointment comments, and other booking personally identifiable information.

PLUGIN Appointment Booking Calendar

CVE-2026-12113

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-12090 - Taskbuilder – Project Management & Task Management Tool With Kanban Board Plugin

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'wppm_proj_filter' parameter in all versions up to, and including, 5.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. No nonce verification is performed on…

PLUGIN Taskbuilder – Project Management & Task Management Tool With Kanban Board

CVE-2026-12090

MEDIUM CVSS 6.5 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11988 - LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.9.1 via the 'userId' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to view the course enrollment progress and completion data belonging to any instructor or administrator account on the site. This IDOR does not apply when the target user is a regular subscriber, as the guard…

PLUGIN LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

CVE-2026-11988

MEDIUM CVSS 6.5 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11380 - Jetwidgets For Elementor Plugin

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.21. This is due to insufficient output escaping and missing server-side validation of the Animated Box widget's animation_effect setting before it is rendered inside an HTML class attribute. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Jetwidgets For Elementor

CVE-2026-11380

MEDIUM CVSS 6.4 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-11981 - GiveWP – Donation Plugin and Fundraising Platform

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.3 This is due to missing nonce validation on the give_set_notification_status_handler() function. This makes it possible for unauthenticated attackers to disable donation email notifications via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN GiveWP – Donation Plugin and Fundraising Platform

CVE-2026-11981

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-07-01

CVE-2026-10513 - Webmention Plugin

The Webmention plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.8.0 via parser-derived 'avatar' and 'url' author metadata. This is due to insufficient input sanitization and output escaping on user-supplied MF2 author properties processed by the unauthenticated webmention REST endpoint and rendered directly into HTML 'value' attributes by the edit-comment-form template without esc_attr() or esc_url(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a privileged user (moderator or administrator) opens the affected comment…

PLUGIN Webmention

CVE-2026-10513

HIGH CVSS 7.2 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-9711 - Eventon Wordpress Virtual Event Calendar Plugin

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and including, 5.0.11 due to insufficient escaping on the user supplied parameter and lack of preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database, granted the "Enable additional search queries" setting is enabled and at least one published event exists.

PLUGIN Eventon Wordpress Virtual Event Calendar

CVE-2026-9711

CRITICAL CVSS 9.8 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-8141 - Ajax Load More Filters Plugin

The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include_children' parameter in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Ajax Load More Filters

CVE-2026-8141

HIGH CVSS 7.2 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-9576 - Fluent Booking Plugin

The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users with at least the Calendar Manager role to retrieve attendees' PII (name, email, phone, address, payment information) from calendar groups they do not own.

PLUGIN Fluent Booking

CVE-2026-9576

MEDIUM CVSS 4.9 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-11589 - Wp Support Plus Responsive Ticket System Plugin

The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploaded files, allowing unauthenticated users to upload files containing malicious JavaScript (such as HTML or SVG) to a publicly accessible location, leading to Stored Cross-Site Scripting attacks against site users and administrators.

PLUGIN Wp Support Plus Responsive Ticket System

CVE-2026-11589

HIGH CVSS 8.8 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-12240 - Export User Data Plugin

The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize function in all versions up to, and including, 2.2.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Successful exploitation requires an administrator to trigger a user data export while a subscriber-level (or higher) user has stored a crafted serialized XLSXWriter…

PLUGIN Export User Data

CVE-2026-12240

HIGH CVSS 8.0 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-11581 - Drag And Drop Builder Plugin

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's caption before outputting it as a column header on the administrator form-entries screen, allowing users with Contributor-level access or above to store JavaScript that executes in an administrator's session. A missing capability check in the Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13's post-duplication action additionally lets the Contributor publish the malicious form so an administrator renders it.

PLUGIN Drag And Drop Builder

CVE-2026-11581

MEDIUM CVSS 5.9 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-8944 - Io Engagement Analytics Plugin

The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the Google Analytics settings page (ga.php). This makes it possible for unauthenticated attackers to update the plugin's stored Google Analytics tracking ID option (io-ga-id) via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Io Engagement Analytics

CVE-2026-8944

MEDIUM CVSS 4.3 2026-06-30
Threat Entry Updated 2026-07-01

CVE-2026-12560 - Editorial Rating – Product Review & Rating System Plugin

The Editorial Rating – Product Review & Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Link URL' Field in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The WordPress unfiltered_html capability exemption does not apply here because the payload is stored in post meta (_wpas_er_options via update_post_meta) rather than in…

PLUGIN Editorial Rating – Product Review & Rating System

CVE-2026-12560

MEDIUM CVSS 4.4 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-12073 - Groups And Communities Plugin

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on registration forms that don't contain this parameter, and not properly handling the error messages. This makes it possible for unauthenticated attackers to change email address of user account with ID=1 (usually an administrator), and leverage that to reset the user's password and gain access to their account.

PLUGIN Groups And Communities

CVE-2026-12073

CRITICAL CVSS 9.8 2026-06-30
Threat Entry Updated 2026-07-01

CVE-2026-12349 - Premium Addons For Kingcomposer Plugin

The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including, 1.1.1. This is due to missing authorization and capability checks on the add_custom_sidebar() and remove_custom_sidebar() AJAX handlers, both of which are exposed through wp_ajax_nopriv_* hooks and write directly to the octagon_custom_sidebar option via update_option(). This makes it possible for unauthenticated attackers to create arbitrary custom widget areas or delete existing custom sidebars, which can cause widgets assigned to those areas to silently lose their registration and stop…

PLUGIN Premium Addons For Kingcomposer

CVE-2026-12349

MEDIUM CVSS 5.3 2026-06-30
Threat Entry Updated 2026-06-30

CVE-2026-11367 - Wordpress Image Editor Plugin

The PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.2 via the move_image_on_server function. This makes it possible for authenticated attackers, with author-level access and above, to write files with attacker-controlled content to arbitrary locations on the server. The unsanitized 'layers[].id' parameter is concatenated into a filesystem path and passed to PHP's copy() function, allowing traversal sequences (e.g. '../../') to escape the intended upload directory and write attacker-supplied file contents to arbitrary paths accessible by the web server…

PLUGIN Wordpress Image Editor

CVE-2026-11367

MEDIUM CVSS 6.5 2026-06-30
Scroll to top