Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,479
Critical934
High3,137
Medium11,193
Reset
Showing 41-60 of 15479 records
Threat Entry Updated 2026-07-17

CVE-2026-9810 - Ai Copilot Plugin

The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileged MCP tools as an administrator, including arbitrary user creation and role escalation.

PLUGIN Ai Copilot

CVE-2026-9810

CRITICAL CVSS 9.8 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-12393 - Wps Bookings For Woocommerce Plugin

The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing any authenticated user, such as a Subscriber or Customer, to cancel and void other customers' booking orders.

PLUGIN Wps Bookings For Woocommerce

CVE-2026-12393

MEDIUM CVSS 5.4 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-13402 - Royal Addons For Elementor Plugin

The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft Elementor templates linked from non-public navigation menu items.

PLUGIN Royal Addons For Elementor

CVE-2026-13402

MEDIUM CVSS 5.3 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-11961 - Before 5 Plugin

The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user role, allowing unauthenticated users to register into an arbitrary published membership tier and obtain its role — up to administrator when such a tier exists.

PLUGIN Before 5

CVE-2026-11961

HIGH CVSS 8.1 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-11575 - Phonepe Payment Solutions Plugin

The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so the expected signature reduces to an unkeyed hash of the request body that anyone can compute. This allows unauthenticated attackers to forge a payment-success notification and mark unpaid WooCommerce orders as paid without any payment being made.

PLUGIN Phonepe Payment Solutions

CVE-2026-11575

HIGH CVSS 7.5 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-10525 - Nex Forms Plugin

The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and outputting it back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users such as administrators when they view the submitted entries.

PLUGIN Nex Forms

CVE-2026-10525

MEDIUM CVSS 6.1 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-11966 - Before 5 Plugin

The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membership payment actions and acts on a caller-supplied user identifier, allowing unauthenticated attackers to delete recently-registered, payment-pending user accounts.

PLUGIN Before 5

CVE-2026-11966

MEDIUM CVSS 5.3 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-15982 - Automation Toolkit Plugin

The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is due to due to a missing capability check on the 'aiomatic_call_google_ai_function' function. This makes it possible for unauthenticated attackers to leverage the 'aimogen_wp_god_mode' tool to clear function blacklists and execute arbitrary PHP functions, such as creating administrator accounts.

PLUGIN Automation Toolkit

CVE-2026-15982

CRITICAL CVSS 9.8 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-15094 - Wp Hotel Booking Plugin

The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Wp Hotel Booking

CVE-2026-15094

MEDIUM CVSS 6.1 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-15759 - Chat Help Plugin

The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes in all versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Chat Help

CVE-2026-15759

MEDIUM CVSS 6.4 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-15161 - Ninja Forms Excel Export Plugin

The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.6. This is due to the save_filter() AJAX handler storing the raw $_POST['filter'] array into a WordPress option via update_option() without any capability check, nonce verification, or input sanitization, combined with the get_filter_row() method on the admin Excel Export screen concatenating the stored filter values (field_key, condition, value) directly into HTML attributes without esc_attr(). This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary…

PLUGIN Ninja Forms Excel Export

CVE-2026-15161

MEDIUM CVSS 6.4 2026-07-17
Threat Entry Updated 2026-07-21

CVE-2026-15457 - Kirki Plugin

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.0.13 via the 'family' parameter. This makes it possible for authenticated attackers, with editor-level access and above, to delete arbitrary directories on the server, which can result in loss of data and availability.

PLUGIN Kirki

CVE-2026-15457

MEDIUM CVSS 4.9 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-15349 - Crm Suite Built For Woocommerce Plugin

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.17.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary company locations in the ERP database.

PLUGIN Crm Suite Built For Woocommerce

CVE-2026-15349

MEDIUM CVSS 4.3 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-13765 - Wordpress Lms Plugin For Create And Sell Online Courses

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated attackers to extract the correct-answer markers, full option lists, explanations, and question content for any quiz question on the site — including questions belonging to paid courses the attacker is not enrolled in.

PLUGIN Wordpress Lms Plugin For Create And Sell Online Courses

CVE-2026-13765

HIGH CVSS 7.5 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-14503 - Pcloud Wp Backup Plugin

The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3 via the wp2pcl_ajax_process_request_inner. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract force generation of a full-site backup archive written to a publicly accessible directory, exposing wp-config.php database credentials, WordPress secret salts, and the complete PHP source tree. The resulting archive is deposited in the plugin's unprotected tmp/ directory at a predictable URL, making the extracted data accessible to unauthenticated visitors once the backup…

PLUGIN Pcloud Wp Backup

CVE-2026-14503

MEDIUM CVSS 6.5 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-13352 - Wp User Avatar Plugin

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due to the unconditional registration of an upload_mimes filter that adds executable file extensions (.exe, .apk, .msi) to the global WordPress MIME allowlist, without scoping the expansion to digital-product upload contexts. This makes it possible for authenticated attackers, with author-level access and above, to upload files that may be executable,…

PLUGIN Wp User Avatar

CVE-2026-13352

HIGH CVSS 8.8 2026-07-17
Threat Entry Updated 2026-07-21

CVE-2026-8616 - Fense Block Vpn Proxy Plugin

The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including, 3.0.1. The callback is registered to both wp_ajax_* and wp_ajax_nopriv_* hooks and unconditionally calls delete_option() on four plugin options and delete_transient() on three transients tied to the plugin's API key cache and settings. This makes it possible for unauthenticated attackers to delete plugin options and transients, effectively resetting the plugin's API key/data cache and…

PLUGIN Fense Block Vpn Proxy

CVE-2026-8616

MEDIUM CVSS 5.3 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-15395 - Kali Forms Plugin

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The required form-submission nonce is publicly available on any page containing the form shortcode, making this exploitable by fully unauthenticated attackers without any precondition beyond the form being…

PLUGIN Kali Forms

CVE-2026-15395

HIGH CVSS 7.2 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-15160 - Ninja Forms Excel Export Plugin

The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_tmp_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to write .xls/.xlsx files to arbitrary locations on the server, which can be used to stage further attacks.

PLUGIN Ninja Forms Excel Export

CVE-2026-15160

MEDIUM CVSS 4.3 2026-07-17
Threat Entry Updated 2026-07-17

CVE-2026-15159 - Ninja Forms Excel Export Plugin

The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_form_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to enumerate any Ninja Forms form ID and download all stored submission data — including names, email addresses, phone numbers, physical addresses, and any other PII collected by site forms — as a downloadable XLSX file.

PLUGIN Ninja Forms Excel Export

CVE-2026-15159

MEDIUM CVSS 4.3 2026-07-17
Scroll to top