Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,479
Critical934
High3,137
Medium11,193
Reset
Showing 501-520 of 15479 records
Threat Entry Updated 2026-06-30

CVE-2026-8896 - Mir Blocks And Shortcodes Plugin

The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute (and other attributes such as 'ready_animation_text') of the 'msc_stats' shortcode in versions up to, and including, 1.0.0. This is due to insufficient input sanitization and output escaping on user supplied shortcode attributes inside the msc_stats() rendering function. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Mir Blocks And Shortcodes

CVE-2026-8896

MEDIUM CVSS 6.4 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-8865 - Avalon23 Products Filter For Woocommerce Plugin

The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'avalon23_qr' shortcode in all versions up to, and including, 1.1.6. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes (notably 'title' and 'fixed_link') which are concatenated directly into single-quoted HTML attributes by the AVALON23_HELPER::draw_html_item() helper without esc_attr() or any other encoding. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an…

PLUGIN Avalon23 Products Filter For Woocommerce

CVE-2026-8865

MEDIUM CVSS 6.4 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-8905 - Osiris Signature Banner Plugin

The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Osiris Signature Banner

CVE-2026-8905

MEDIUM CVSS 6.1 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-8628 - Entredroppers Plugin

The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The payload is delivered via attacker-controlled path-info in the URL (e.g., /wp-admin/admin.php/">/?page=EntreDroppers.php), which PHP_SELF reflects directly into the form action attribute.

PLUGIN Entredroppers

CVE-2026-8628

MEDIUM CVSS 6.1 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-9172 - Devs Accounting – Simple Accounting and Invoicing Solution Plugin

The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due to a missing capability check on the delete_single_account() function in versions up to, and including, 1.2.0. The REST route 'devs-accounting/v1/delete-account/(?P\d+)' is registered without any permission_callback, which causes WordPress to expose the endpoint to public, unauthenticated access. This makes it possible for unauthenticated attackers to soft-delete arbitrary accounting account records (wp_dac_accounts) by issuing a simple GET request to the endpoint with any account ID.

PLUGIN Devs Accounting – Simple Accounting and Invoicing Solution

CVE-2026-9172

MEDIUM CVSS 5.3 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-8690 - RentMy Real-Time Rental Management Plugin

The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.4.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read, create, update, and delete event records stored in the rentmy_events WordPress option, as well as overwrite the rentmy_locationId option.

PLUGIN RentMy Real-Time Rental Management Plugin

CVE-2026-8690

MEDIUM CVSS 5.3 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-8688 - Advance Nav Menu Manager Plugin

The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to duplicate, copy, move, or publish nav_menu_item posts via wp_insert_post(), modifying the site's navigation menus without authorization.

PLUGIN Advance Nav Menu Manager

CVE-2026-8688

MEDIUM CVSS 4.3 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-4297 - Newscred Publishing Plugin

The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and including 0.0.31. This is due to a missing capability check in the nc_setOption() function, which is exposed via the nc.setOption XML-RPC method. The function authenticates the user via $wp_xmlrpc_server->login() (verifying credentials are valid) but does not perform any authorization check such as current_user_can('manage_options'). This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary WordPress options via XML-RPC requests. This can be leveraged to change the default_role…

PLUGIN Newscred Publishing

CVE-2026-4297

HIGH CVSS 8.8 2026-06-24
Threat Entry Updated 2026-06-29

CVE-2026-8622 - Image Sizes On Demand Plugin

The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Variable in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The injected payload only executes in the context of an administrator, as the settings page requires the manage_options capability to render.

PLUGIN Image Sizes On Demand

CVE-2026-8622

MEDIUM CVSS 6.1 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-8617 - Searchplus Plugin

The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, and including, 1.7.1. This is due to a missing capability check and missing nonce validation on the searchplus_save_token_action_callback() and searchplus_reset_token_action_callback() functions, both of which are exposed to unauthenticated users through the wp_ajax_nopriv_ hooks. This makes it possible for unauthenticated attackers to overwrite or delete the plugin's stored account token and account name options (dym_token, dym_name, searchplus_token, searchplus_name, sp_token, sp_name).

PLUGIN Searchplus

CVE-2026-8617

MEDIUM CVSS 5.3 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-7617 - Secufor_OAuth Plugin

The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to disconnect the WordPress site from its linked Secufor account by clearing the plugin's stored login token and user login configuration.

PLUGIN Secufor_OAuth

CVE-2026-7617

MEDIUM CVSS 5.3 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-8614 - Assistio Plugin

The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the assistio_plugin_delete_assistio_settings() function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's options including the critical 'assistiobot_oauth_settings' option, which disrupts the plugin's integration with the Assistio bot service.

PLUGIN Assistio

CVE-2026-8614

MEDIUM CVSS 4.3 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-6292 - Mp Customize Login Page Plugin

The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to and including 1.0. This is due to a completely broken nonce validation in the enter_mpclp_login_options() function, which contains an inverted check (if wp_verify_nonce(...) { return false; }) and is missing the required action parameter for wp_verify_nonce(). As a result, the nonce check is effectively dead code: it never blocks malicious requests because a CSRF-supplied empty/invalid nonce always returns false, satisfying the inverted condition to continue execution. Furthermore, the settings-update handler…

PLUGIN Mp Customize Login Page

CVE-2026-6292

MEDIUM CVSS 4.3 2026-06-24
Threat Entry Updated 2026-06-29

CVE-2026-12417 - SignUp & SignIn Plugin

The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX handler — registered via `wp_ajax_nopriv_pravel_change_password` and therefore accessible to unauthenticated users — performing no nonce verification, no capability check, and only a loose equality check between an attacker-supplied `reset_activation_code` POST parameter and the target user's `forgot_email` user meta value; when a user has never initiated a password reset, `get_user_meta()` returns an empty string that trivially…

PLUGIN SignUp & SignIn

CVE-2026-12417

CRITICAL CVSS 9.8 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-12416 - Invoice Generator Plugin

The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_change_password()` function being registered as a nopriv AJAX handler with no nonce verification and no authorization check, and performing a loose equality comparison between the supplied `reset_activation_code` POST parameter and the target user's stored `forgot_email` user meta — a check that trivially evaluates to true (`'' == ''`) for any user who has never initiated a forgot-password request, which applies to administrators under…

PLUGIN Invoice Generator

CVE-2026-12416

CRITICAL CVSS 9.8 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-12100 - Url Preview Plugin

The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0 via the 'url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PLUGIN Url Preview

CVE-2026-12100

HIGH CVSS 7.2 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-12095 - Kargo Takip Plugin

The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2 via the 'api_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. The script echoes internal API response data (specifically the value of any 'auth' key in a JSON response body) verbatim back to the attacker's browser, enabling direct exfiltration of responses from internal services such as…

PLUGIN Kargo Takip

CVE-2026-12095

HIGH CVSS 7.2 2026-06-24
Threat Entry Updated 2026-06-29

CVE-2026-11370 - Wp Meta Seo Plugin

The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.5.18 via the 'new_link' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. The HTTP response status from outbound requests is reflected back in the AJAX JSON response as status_code, providing an enumeration oracle usable for probing internal hosts and cloud metadata…

PLUGIN Wp Meta Seo

CVE-2026-11370

MEDIUM CVSS 6.4 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-12094 - Advanced Contact Form 7 – Compact DB Plugin

The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the cf7cdb_ajax_delete_user() function in versions up to, and including, 1.0.0. The handler is registered against both `wp_ajax_cf7cdb_delete` and `wp_ajax_nopriv_cf7cdb_delete`, and it performs no nonce verification, no capability check, and no ownership check before invoking `$wpdb->delete()` against the `wp_cf7cdb_data` table with an attacker-supplied integer ID. This makes it possible for unauthenticated attackers to delete arbitrary contact form submission entries stored by the plugin by iterating sequential…

PLUGIN Advanced Contact Form 7 – Compact DB

CVE-2026-12094

MEDIUM CVSS 5.3 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-11997 - Bulk Seo Image Plugin

The Bulk SEO Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1. This is due to missing or incorrect nonce validation on the plugin's settings page handler BulkSeoImage(), which dispatches to launchbulk() / BulkSeoImageGo() whenever the request contains $_POST['bulkseoimage']. No wp_nonce_field() is emitted in the form and no check_admin_referer()/wp_verify_nonce() is performed before bulk-overwriting the _wp_attachment_image_alt post meta for every image attached to every published post and/or page. This makes it possible for unauthenticated attackers to bulk-overwrite image ALT-text metadata across the site…

PLUGIN Bulk Seo Image

CVE-2026-11997

MEDIUM CVSS 4.3 2026-06-24
Scroll to top