Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,479
Critical934
High3,137
Medium11,193
Reset
Showing 461-480 of 15479 records
Threat Entry Updated 2026-06-29

CVE-2026-13335 - Codepeople Post Map Plugin

The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point' Post Meta in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Codepeople Post Map

CVE-2026-13335

MEDIUM CVSS 6.4 2026-06-27
Threat Entry Updated 2026-06-29

CVE-2026-13422 - Hd Quiz Plugin

The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to missing or incorrect nonce validation on the hdq_validate_nonce function. This makes it possible for unauthenticated attackers to delete or modify quizzes and questions, create new quizzes, and change plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Hd Quiz

CVE-2026-13422

MEDIUM CVSS 4.3 2026-06-27
Threat Entry Updated 2026-06-29

CVE-2026-13333 - And Marketing Automation Plugin

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via 'query[select]' Parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Sales Representative-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The sanitized Contact_Query code path can be bypassed by supplying…

PLUGIN And Marketing Automation

CVE-2026-13333

MEDIUM CVSS 6.5 2026-06-27
Threat Entry Updated 2026-06-29

CVE-2026-13331 - And Marketing Automation Plugin

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'search' parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with marketer-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN And Marketing Automation

CVE-2026-13331

MEDIUM CVSS 6.5 2026-06-27
Threat Entry Updated 2026-06-29

CVE-2026-11356 - Add Search To Menu Plugin

The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings in all versions up to, and including, 5.5.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Add Search To Menu

CVE-2026-11356

MEDIUM CVSS 4.4 2026-06-27
Threat Entry Updated 2026-06-26

CVE-2026-57620 - Elementor Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.8.

PLUGIN Elementor

CVE-2026-57620

MEDIUM CVSS 6.5 2026-06-26
Threat Entry Updated 2026-06-26

CVE-2026-1869 - Login Builder Plugin

The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the confirm_payment() function in all versions up to, and including, 5.2.0. This makes it possible for unauthenticated attackers to bypass payment processing and activate paid memberships.

PLUGIN Login Builder

CVE-2026-1869

MEDIUM CVSS 6.5 2026-06-26
Threat Entry Updated 2026-06-26

CVE-2026-10835 - Before 3 Plugin

The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one of its AJAX actions before using it in a SQL statement, and fails to enforce authorisation on that action, allowing authenticated users with minimal permissions, such as subscribers, to perform SQL injection attacks.

PLUGIN Before 3

CVE-2026-10835

HIGH CVSS 7.7 2026-06-26
Threat Entry Updated 2026-06-26

CVE-2026-10823 - Ymc Filter Plugin

The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and does not validate a user-supplied query parameter, allowing unauthenticated attackers to retrieve the titles and content of private, draft, and other non-public posts.

PLUGIN Ymc Filter

CVE-2026-10823

HIGH CVSS 7.5 2026-06-26
Threat Entry Updated 2026-06-26

CVE-2026-8380 - Frontend File Manager Plugin

The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to permanently delete arbitrary posts and pages. When the Frontend File Manager Plugin WordPress plugin through 23.6's "Allow guest uploads" setting is enabled by an administrator, the same deletion primitive becomes reachable by unauthenticated users.

PLUGIN Frontend File Manager Plugin

CVE-2026-8380

MEDIUM CVSS 6.5 2026-06-26
Threat Entry Updated 2026-06-26

CVE-2026-13226 - And Marketing Automation Plugin

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'after' parameter in all versions up to, and including, 4.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Sales Manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The AJAX handler wp_ajax_groundhogg_get_contacts_table has its capability check commented…

PLUGIN And Marketing Automation

CVE-2026-13226

MEDIUM CVSS 6.5 2026-06-26
Threat Entry Updated 2026-06-25

CVE-2026-12937 - Car Rental Plugin

The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'post_id' parameter in all versions up to, and including, 2.22.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The AJAX handler is registered for unauthenticated users via…

PLUGIN Car Rental

CVE-2026-12937

HIGH CVSS 7.5 2026-06-25
Threat Entry Updated 2026-06-25

CVE-2026-5305 - Email Address Encoder Plugin

The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks

PLUGIN Email Address Encoder

CVE-2026-5305

HIGH CVSS 8.8 2026-06-25
Threat Entry Updated 2026-06-25

CVE-2026-9702 - Inpost Pl Plugin

The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination to be updated, allowing unauthenticated attackers to silently redirect the shipping destination of any pending or processing order on the site.

PLUGIN Inpost Pl

CVE-2026-9702

HIGH CVSS 7.5 2026-06-25
Threat Entry Updated 2026-06-25

CVE-2026-10824 - Masteriyo Lms Plugin

The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress records.

PLUGIN Masteriyo Lms

CVE-2026-10824

MEDIUM CVSS 6.5 2026-06-25
Threat Entry Updated 2026-06-25

CVE-2026-2508 - Gravity Bookings Plugin

The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and including, 2.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Gravity Bookings

CVE-2026-2508

MEDIUM CVSS 6.5 2026-06-25
Threat Entry Updated 2026-06-29

CVE-2026-12077 - Dokan Pro Plugin

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameters in all versions up to, and including, 5.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Dokan Pro

CVE-2026-12077

HIGH CVSS 7.5 2026-06-25
Scroll to top