Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,479
Critical934
High3,137
Medium11,193
Reset
Showing 621-640 of 15479 records
Threat Entry Updated 2026-06-17

CVE-2026-8935 - Wp Maps Pro Plugin

The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a magic-login URL granting interactive admin access.

PLUGIN Wp Maps Pro

CVE-2026-8935

CRITICAL CVSS 9.8 2026-06-15
Threat Entry Updated 2026-06-17

CVE-2026-9278 - Form Builder Cp Plugin

The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing it and using it as part of a client-side script execution, allowing authenticated users with Editor-level access and above to perform Stored Cross-Site Scripting attacks against any visitor of a page rendering the affected form, even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network).

PLUGIN Form Builder Cp

CVE-2026-9278

MEDIUM CVSS 5.4 2026-06-15
Threat Entry Updated 2026-06-17

CVE-2026-8386 - Wp Go Maps Plugin

The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address and description fields and the marker's geographic coordinates.

PLUGIN Wp Go Maps

CVE-2026-8386

MEDIUM CVSS 5.3 2026-06-15
Threat Entry Updated 2026-06-17

CVE-2026-8385 - Wp Go Maps Plugin

The WP Go Maps WordPress plugin before 10.0.10 does not properly enforce the marker approval filter on the admin-ajax fallback for its datatables route, allowing unauthenticated visitors to retrieve marker records that the site owner has not approved for public display, including their title, category, address and description fields.

PLUGIN Wp Go Maps

CVE-2026-8385

MEDIUM CVSS 5.3 2026-06-15
Threat Entry Updated 2026-06-17

CVE-2026-5513 - Online Scheduling and Appointment Booking System – Bookly Plugin

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and including, 27.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires 'Remember personal information in cookies' setting to be enabled (disabled by default).

PLUGIN Online Scheduling and Appointment Booking System – Bookly

CVE-2026-5513

HIGH CVSS 7.2 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-1291 - Meow Gallery Plugin

The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the REST API endpoint /wp-json/meow-gallery/v1/save_shortcode in all versions up to, and including, 5.4.4 This makes it possible for authenticated attackers, with Author-level access and above, to arbitrarily create or overwrite existing gallery shortcode records by supplying a user-controlled id value. The endpoint performs database update operations without verifying that the requesting user is authorized to modify the referenced gallery record or create their own.

PLUGIN Meow Gallery

CVE-2026-1291

MEDIUM CVSS 4.3 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-9629 - Canvas Plugin

The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Canvas

CVE-2026-9629

MEDIUM CVSS 6.4 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-3297 - Drag And Drop Website Builder Plugin

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Anchor block in versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Drag And Drop Website Builder

CVE-2026-3297

MEDIUM CVSS 6.4 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-2470 - Drag And Drop Website Builder Plugin

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.9. This is due to the pagelayer_save_content AJAX handler allowing users with basic post-edit capability to persist pagelayer_contact_templates metadata on posts they can edit (including pending posts), while the unauthenticated pagelayer_contact_submit endpoint later consumes that metadata by user-controlled post/form identifiers without enforcing a privileged or published-context boundary. This makes it possible for authenticated attackers, with Contributor-level access and above, to configure arbitrary contact-form mail templates…

PLUGIN Drag And Drop Website Builder

CVE-2026-2470

MEDIUM CVSS 4.3 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-9134 - Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel Plugin

The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomplete JavaScript event handler blacklist in the foogallery_sanitize_javascript() function, which blocks only a subset of HTML event attributes (onmouseover, onmouseout, onpointerenter, onclick, onload, onchange, onerror) while permitting others such as 'onmouseenter', combined with the failure to escape the attribute key when building the gallery container HTML in foogallery_build_container_attributes_safe(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject…

PLUGIN Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

CVE-2026-9134

MEDIUM CVSS 6.4 2026-06-13
Threat Entry Updated 2026-06-17

CVE-2026-9109 - Automatically Translate Websites Plugin

The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Translation Storage in all versions up to, and including, 2.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The deterministically derived API key (sha256 of the site URL) is printed in the HTML source of every page via the JavaScript variable gptApiKey, meaning…

PLUGIN Automatically Translate Websites

CVE-2026-9109

HIGH CVSS 7.2 2026-06-13
Scroll to top