Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,479
Critical934
High3,137
Medium11,193
Reset
Showing 521-540 of 15479 records
Threat Entry Updated 2026-06-25

CVE-2026-10753 - Site Kit By Google Plugin

The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have been granted dashboard sharing access (such as Editors) to modify a site-wide Site Kit by Google WordPress plugin before 1.176.0 setting that should only be modifiable by administrators.

PLUGIN Site Kit By Google

CVE-2026-10753

LOW CVSS 2.7 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-10735 - Multiple Shapedsmart Post Show Pro Plugin

Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.

PLUGIN Multiple Shapedsmart Post Show Pro

CVE-2026-10735

HIGH CVSS 7.5 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-10749 - Post Duplicator Plugin

The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication, storing attacker-supplied serialized values without the WordPress meta API's double-serialization protection, allowing users with Contributor-level access and above to inject a PHP Object.

PLUGIN Post Duplicator

CVE-2026-10749

HIGH CVSS 7.2 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-10092 - Cincopa Video And Media Plug In Plugin

The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortcode in Post Comments in all versions up to, and including, 1.163 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation is possible because the plugin processes the [cincopa] shortcode via a comment_text filter hook, allowing unauthenticated visitors who can post comments to supply a malicious shortcode argument that…

PLUGIN Cincopa Video And Media Plug In

CVE-2026-10092

HIGH CVSS 7.2 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-10091 - Email Javascript Cloak Plugin

The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' shortcode in all versions up to, and including, 1.03 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Email Javascript Cloak

CVE-2026-10091

HIGH CVSS 7.2 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-10531 - Before 2 Plugin

The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes before outputting them in a page, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2026-10531

MEDIUM CVSS 5.4 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-10552 - Blue Captcha Plugin

The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1. This is due to missing or incorrect nonce validation on the main admin panel (blcap_main_page) and on the Hall of Shame and Log subpages, which accept a 'blcap_action' / 'action' parameter from $_REQUEST and perform destructive operations (plugin uninstall via blcap_uninstall(), log deletion via blcap_delete_logs(), Hall of Shame deletion via blcap_delete_ip_db(), and adding IPs to the banned list via update_option('blcap_settings')) with no wp_verify_nonce(), check_admin_referer(), or check_ajax_referer() calls anywhere in the codebase.…

PLUGIN Blue Captcha

CVE-2026-10552

MEDIUM CVSS 4.3 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-3652 - Arforms Plugin

The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save_incomplete_form_data` AJAX action in all versions up to, and including, 7.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute whenever an administrator views the "Partial Filled Form Entries" page in the ARForms dashboard.

PLUGIN Arforms

CVE-2026-3652

HIGH CVSS 7.2 2026-06-24
Threat Entry Updated 2026-06-25

CVE-2026-11614 - Xpro Addons — 140+ Widgets for Elementor Plugin

The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attributes' parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Xpro Addons — 140+ Widgets for Elementor

CVE-2026-11614

MEDIUM CVSS 6.4 2026-06-24
Threat Entry Updated 2026-06-29

CVE-2026-4610 - ProfileGrid – User Profiles, Groups and Communities Plugin

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pm_author_message' parameter in the pm_send_message_to_author function in all versions up to, and including, 5.9.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 5.9.8.5.

PLUGIN ProfileGrid – User Profiles, Groups and Communities

CVE-2026-4610

MEDIUM CVSS 6.4 2026-06-23
Threat Entry Updated 2026-06-23

CVE-2026-8379 - Frontend File Manager Plugin

The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file download handler, allowing unauthenticated attackers to download files uploaded by any user through the Frontend File Manager Plugin WordPress plugin through 23.6 by iterating identifiers.

PLUGIN Frontend File Manager Plugin

CVE-2026-8379

HIGH CVSS 7.5 2026-06-23
Threat Entry Updated 2026-06-23

CVE-2026-8172 - Simple Basic Contact Form Plugin

The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it into the contact form output on validation errors, leading to a Reflected Cross-Site Scripting vulnerability that unauthenticated attackers can exploit against site visitors via a crafted link or cross-site form submission.

PLUGIN Simple Basic Contact Form

CVE-2026-8172

HIGH CVSS 7.1 2026-06-23
Threat Entry Updated 2026-06-23

CVE-2026-8378 - Frontend File Manager Plugin

The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitted to the frontend file-rename endpoint before storing it as post meta and rendering it back on the admin File Manager listing, leading to a Stored Cross-Site Scripting vulnerability exploitable by users with Subscriber-level access and above against an administrator viewing the file management interface.

PLUGIN Frontend File Manager Plugin

CVE-2026-8378

MEDIUM CVSS 5.4 2026-06-23
Threat Entry Updated 2026-06-23

CVE-2026-8163 - Infility Global Plugin

The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vulnerability exploitable by authenticated users with Subscriber-level access and above.

PLUGIN Infility Global

CVE-2026-8163

HIGH CVSS 8.8 2026-06-23
Threat Entry Updated 2026-06-23

CVE-2026-7842 - Infility Global Infility Global Plugin

The Infility Global Infility Global WordPress plugin before 2.15.20 for WordPress does not sanitize or validate the orderby and order parameters in the import_list(), url_detail(), and file_detail() admin page callbacks before using them in SQL queries, allowing authenticated attackers with Editor-level access or higher to perform time-based blind SQL injection and extract sensitive data from the database. The ImportData module must be enabled via the Infility Global WordPress plugin before 2.15.20's module toggle page.

PLUGIN Infility Global Infility Global

CVE-2026-7842

MEDIUM CVSS 6.8 2026-06-23
Threat Entry Updated 2026-06-22

CVE-2026-8157 - Allowing Authenticated Users With A Custom Vitepos Plugin

The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a custom Vitepos WordPress plugin before 3.4.2 role to escalate privileges to administrator.

PLUGIN Allowing Authenticated Users With A Custom Vitepos

CVE-2026-8157

HIGH CVSS 8.8 2026-06-22
Threat Entry Updated 2026-06-22

CVE-2026-7859 - Before 1 Plugin

The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices.

PLUGIN Before 1

CVE-2026-7859

MEDIUM CVSS 5.3 2026-06-22
Threat Entry Updated 2026-06-22

CVE-2026-6858 - Transbank Webpay Plugin

The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator

PLUGIN Transbank Webpay

CVE-2026-6858

HIGH CVSS 7.1 2026-06-22
Threat Entry Updated 2026-06-22

CVE-2026-4259 - Ultimate Woocommerce Auction Pro Plugin

The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Ultimate Woocommerce Auction Pro

CVE-2026-4259

HIGH CVSS 7.1 2026-06-22
Threat Entry Updated 2026-06-22

CVE-2026-4110 - Ultimate Woocommerce Auction Pro Plugin

The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Ultimate Woocommerce Auction Pro

CVE-2026-4110

MEDIUM CVSS 6.1 2026-06-22
Scroll to top