Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total14,193
Critical852
High2,805
Medium10,341
Reset
Showing 461-480 of 14193 records
Threat Entry Updated 2026-03-09

CVE-2026-1086 - Font Pairing Preview For Landing Pages Plugin

The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to modify the plugin's font pairing settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Font Pairing Preview For Landing Pages

CVE-2026-1086

MEDIUM CVSS 4.3 2026-03-07
Threat Entry Updated 2026-03-09

CVE-2026-1085 - Seo Local Rank Plugin

The True Ranker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.9. This is due to missing nonce validation on the seolocalrank-signout action. This makes it possible for unauthenticated attackers to disconnect the administrator's True Ranker account via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Seo Local Rank

CVE-2026-1085

MEDIUM CVSS 4.3 2026-03-07
Threat Entry Updated 2026-03-09

CVE-2026-1071 - Carta Online Plugin

The Carta Online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Carta Online

CVE-2026-1071

MEDIUM CVSS 4.4 2026-03-07
Threat Entry Updated 2026-03-09

CVE-2026-1073 - Purchase Button Plugin

The Purchase Button For Affiliate Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing nonce validation on the settings page form handler in `inc/purchase-btn-options-page.php`. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Purchase Button

CVE-2026-1073

MEDIUM CVSS 4.3 2026-03-07
Threat Entry Updated 2026-03-09

CVE-2026-3352 - Easy Php Settings Plugin

The Easy PHP Settings plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0.4 via the `update_wp_memory_constants()` method. This is due to insufficient input validation on the `wp_memory_limit` and `wp_max_memory_limit` settings before writing them to `wp-config.php`. The `sanitize_text_field()` function used for sanitization does not filter single quotes, allowing an attacker to break out of the string context in a PHP `define()` statement. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject and execute arbitrary PHP code on the…

PLUGIN Easy Php Settings

CVE-2026-3352

HIGH CVSS 7.2 2026-03-07
Threat Entry Updated 2026-03-09

CVE-2026-2722 - Stock Ticker Plugin

The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.26.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Stock Ticker

CVE-2026-2722

MEDIUM CVSS 4.8 2026-03-07
Threat Entry Updated 2026-03-09

CVE-2026-2020 - Jquery Archive List Widget Plugin

The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1.7 via the 'included' shortcode attribute. This is due to the deserialization of untrusted input supplied via the 'included' parameter of the plugin's shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could…

PLUGIN Jquery Archive List Widget

CVE-2026-2020

HIGH CVSS 7.5 2026-03-07
Threat Entry Updated 2026-03-09

CVE-2026-2431 - Cm Custom Reports Plugin

The CM Custom Reports plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_from' and 'date_to' parameters in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Cm Custom Reports

CVE-2026-2431

MEDIUM CVSS 6.1 2026-03-07
Threat Entry Updated 2026-03-09

CVE-2026-2429 - Community Events Plugin

The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'ce_venue_name' CSV field in the `on_save_changes_venues` function in all versions up to, and including, 1.5.8. This is due to insufficient escaping on the user-supplied CSV data and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database via a crafted CSV file upload.

PLUGIN Community Events

CVE-2026-2429

MEDIUM CVSS 4.9 2026-03-07
Threat Entry Updated 2026-03-09

CVE-2026-2721 - Mailarchiver Plugin

The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Mailarchiver

CVE-2026-2721

MEDIUM CVSS 4.8 2026-03-07
Threat Entry Updated 2026-03-09

CVE-2026-2494 - ProfileGrid – User Profiles, Groups and Communities Plugin

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.8.2. This is due to missing nonce validation on the membership request management page (approve and decline actions). This makes it possible for unauthenticated attackers to approve or deny group membership requests via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN ProfileGrid – User Profiles, Groups and Communities

CVE-2026-2494

MEDIUM CVSS 4.3 2026-03-07
Threat Entry Updated 2026-03-09

CVE-2026-2488 - ProfileGrid – User Profiles, Groups and Communities Plugin

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message deletion due to a missing capability check on the pg_delete_msg() function in all versions up to, and including, 5.9.8.1. This is due to the function not verifying that the requesting user has permission to delete the targeted message. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary messages belonging to any user by sending a direct request with a valid message ID (mid parameter).

PLUGIN ProfileGrid – User Profiles, Groups and Communities

CVE-2026-2488

MEDIUM CVSS 4.3 2026-03-07
Threat Entry Updated 2026-03-09

CVE-2026-1902 - Hammas Calendar Plugin

The Hammas Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'apix' parameter in the 'hp-calendar-manage-redirect' shortcode in all versions up to, and including, 1.5.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Hammas Calendar

CVE-2026-1902

MEDIUM CVSS 6.4 2026-03-07
Threat Entry Updated 2026-03-09

CVE-2026-1650 - Mdjm Event Management Plugin

The MDJM Event Management plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'custom_fields_controller' function in all versions up to, and including, 1.7.8.1. This makes it possible for unauthenticated attackers to delete arbitrary custom event fields via the 'delete_custom_field' and 'id' parameters.

PLUGIN Mdjm Event Management

CVE-2026-1650

MEDIUM CVSS 5.3 2026-03-07
Threat Entry Updated 2026-03-09

CVE-2026-2371 - Greenshift – animation and page builder blocks Plugin

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 12.8.3. This is due to missing authorization and post status validation in the `gspb_el_reusable_load()` AJAX handler. The handler accepts an arbitrary `post_id` parameter and renders the content of any `wp_block` post without checking `current_user_can('read_post', $post_id)` or verifying the post status. Combined with the nonce being exposed to unauthenticated users on any public page using the `[wp_reusable_render]` shortcode with `ajax="1"`, this makes it possible for unauthenticated…

PLUGIN Greenshift – animation and page builder blocks

CVE-2026-2371

MEDIUM CVSS 5.3 2026-03-07
Threat Entry Updated 2026-03-09

CVE-2026-1981 - Winston Ai Wp Plugin

The HUMN-1 AI Website Scanner & Human Certification by Winston AI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the winston_disconnect() function in all versions up to, and including, 0.0.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the plugin's API connection settings via the 'winston_disconnect' AJAX action.

PLUGIN Winston Ai Wp

CVE-2026-1981

MEDIUM CVSS 4.3 2026-03-07
Threat Entry Updated 2026-03-09

CVE-2026-1644 - Wp Front End Profile Plugin

The WP Frontend Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.8. This is due to missing nonce validation on the 'update_action' function. This makes it possible for unauthenticated attackers to approve or reject user account registrations via a forged request granted they can trick an administrator into performing an action such as clicking on a link.

PLUGIN Wp Front End Profile

CVE-2026-1644

MEDIUM CVSS 4.3 2026-03-07
Threat Entry Updated 2026-04-15

CVE-2026-3589 - From Versions 5 Plugin

The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allow unauthenticated users to make a logged in admin call non store/WC REST endpoints, and create arbitrary admin users via a CSRF attack for example.

PLUGIN From Versions 5

CVE-2026-3589

HIGH CVSS 7.5 2026-03-06
Threat Entry Updated 2026-03-09

CVE-2026-2830 - Google Sheets Plugin

The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filepath’ parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Google Sheets

CVE-2026-2830

MEDIUM CVSS 6.1 2026-03-06
Threat Entry Updated 2026-04-15

CVE-2026-2446 - Powerpack For Learndash Plugin

The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress options (such as default_role etc) and create arbitrary admin users

PLUGIN Powerpack For Learndash

CVE-2026-2446

CRITICAL CVSS 9.8 2026-03-06
Scroll to top