Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,479
Critical934
High3,137
Medium11,193
Reset
Showing 661-680 of 15479 records
Threat Entry Updated 2026-06-17

CVE-2026-8613 - Athemes Addons For Elementor Lite Plugin

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This affects the Posts Timeline widget as well as the Posts Carousel widget across its default, Banner, and Modern skins, all of which omit the whitelist validation…

PLUGIN Athemes Addons For Elementor Lite

CVE-2026-8613

MEDIUM CVSS 6.4 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-8853 - Mw Wp Form Plugin

The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because the memo value is stored via update_post_meta() rather than wp_insert_post(), WordPress's built-in kses and unfiltered_html protections do not apply, allowing attackers to break out of the textarea…

PLUGIN Mw Wp Form

CVE-2026-8853

MEDIUM CVSS 4.4 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-9067 - Before 1 Plugin

The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the endpoint's intended media type, allowing unauthenticated users to upload any file type accepted by WordPress's media library through endpoints that should only accept images or videos.

PLUGIN Before 1

CVE-2026-9067

CRITICAL CVSS 9.1 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-8071 - Spam Protection Plugin

The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (including administrators) views the post.

PLUGIN Spam Protection

CVE-2026-8071

HIGH CVSS 8.8 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-9060 - Store Locator Plugin

The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin before 1.6.6 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network where the super admin visits the page).

PLUGIN Store Locator

CVE-2026-9060

LOW CVSS 3.5 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-53673 - Buddypress Plugin

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message threads by supplying a user_id parameter in the request. Attackers can pass another user's identifier to the get_item_permissions_check method, which validates the supplied user_id instead of the logged-in user and is reused by the update and delete handlers, to read, reply to, or delete any user's private messages.

PLUGIN Buddypress

CVE-2026-53673

HIGH CVSS 8.6 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-53674 - Buddypress Plugin

BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username compatibility mode is enabled, allows attackers to manipulate a REGEXP database clause by crafting mention names containing regex metacharacters. Attackers can submit @mentions whose metacharacters pass through esc_sql unescaped and are inserted into an unprepared REGEXP query against the users table, enabling boolean-based inference of usernames and denial of service through catastrophic backtracking.

PLUGIN Buddypress

CVE-2026-53674

HIGH CVSS 7.1 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-53675 - Buddypress Plugin

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list. Attackers can query the friends endpoint with an arbitrary user_id because the get_items_permissions_check method only verifies that the requester is logged in and never checks ownership of the requested list, resulting in disclosure of users' private social connections.

PLUGIN Buddypress

CVE-2026-53675

MEDIUM CVSS 5.3 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-4058 - User Registration Plugin

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_subscription_cancel() function in all versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to cancel any user's subscription pack, including administrators.

PLUGIN User Registration

CVE-2026-4058

MEDIUM CVSS 4.3 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8677 - Unlimited Elementor Inner Sections By Boomdevs Plugin

The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Widget HTML Tag Settings in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit succeeds even for users without the unfiltered_html capability because the payload (e.g., 'img src=x onerror=alert(document.domain)') contains no HTML…

PLUGIN Unlimited Elementor Inner Sections By Boomdevs

CVE-2026-8677

MEDIUM CVSS 6.4 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8599 - Woocommerce Emails Plugin

The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Campaign HTML Content Field in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The public-facing campaign preview endpoint (/mp-email/{id}-slug/) is not affected by this vulnerability, as it applies a Content-Security-Policy header blocking all…

PLUGIN Woocommerce Emails

CVE-2026-8599

MEDIUM CVSS 6.4 2026-06-09
Threat Entry Updated 2026-06-18

CVE-2026-7542 - Slider Revolution Plugin

The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to and including 7.0.10. This is due to three compounding design flaws: (1) the plugin leaks a valid backend AJAX nonce (revslider_actions) to all authenticated users including Subscribers via the admin_footer hook; (2) the wordpress.create.image_from_url action is explicitly allowlisted in the $user_allowed array, bypassing the administrator-only access control; (3) the create_wordpress_image_from_url() function accepts an attacker-controlled url parameter that is passed to import_media(), where path_or_url_exists() explicitly accepts local filesystem paths (file_exists() && is_readable()) with no restriction…

PLUGIN Slider Revolution

CVE-2026-7542

MEDIUM CVSS 6.5 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-11616 - Events For Geodirectory Plugin

The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 2.3.28. This is due to the ajax_ayi_action() handler only applying strip_tags(esc_sql()) — with no allow-list — to the attacker-controlled $_POST['type'] and $_POST['postid'] values before forwarding them to update_ayi_data(), which calls update_user_meta($current_user->ID, $rsvp_args['type'], $posts). By passing type=wp_capabilities and postid=administrator, an attacker writes ['subscriber'=>true,'administrator'=>'administrator'] into their own wp_capabilities user meta; WP_User::get_role_caps() then treats the 'administrator' array key as an active role on the next request. This makes it possible for authenticated attackers, with…

PLUGIN Events For Geodirectory

CVE-2026-11616

HIGH CVSS 8.8 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8981 - Custom Block Builder Plugin

The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrators on multisite installations (or single-site installs with DISALLOW_UNFILTERED_HTML defined) to inject arbitrary JavaScript that executes for any visitor of pages embedding the affected block.

PLUGIN Custom Block Builder

CVE-2026-8981

LOW CVSS 3.5 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-4986 - Before 1 Plugin

The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.

PLUGIN Before 1

CVE-2026-4986

MEDIUM CVSS 5.3 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-9662 - Recoverexit For Woocommerce Plugin

The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1.0.3. This is due to insufficient validation and sanitization of the user-controlled `tpf` POST parameter before it is used in an `include()` path in the `recover_exit()` function. This makes it possible for unauthenticated attackers to perform path traversal and include unintended local PHP files, which can lead to sensitive information exposure and, in certain deployment chains, code execution.

PLUGIN Recoverexit For Woocommerce

CVE-2026-9662

HIGH CVSS 8.1 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-9185 - 6storage Rentals Plugin

The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.22.0 via the `userId` parameter of the `six_storage_get_user_info` and `six_storage_update_profile` AJAX actions. This is due to the `six_storage_getUserInfo()` and `six_storage_updateProfile()` functions being registered on `wp_ajax_nopriv_*` hooks and accepting a tenant identifier directly from `$_POST['userId']` without performing any ownership verification, session binding, or nonce validation to confirm the requester has a legitimate relationship to the supplied ID. This makes it possible for unauthenticated attackers to read and modify arbitrary tenants'…

PLUGIN 6storage Rentals

CVE-2026-9185

HIGH CVSS 7.5 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8977 - Wp Gdpr Cookie Consent Plugin

The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_actions' AJAX action in versions up to, and including, 1.0.0. This is due to missing capability and nonce checks on the handleAjaxCalls() function, combined with insufficient input sanitization on the gdprConfig values and missing output escaping in the generateCSS() function which echoes stored configuration values directly into a block rendered on wp_head. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute…

PLUGIN Wp Gdpr Cookie Consent

CVE-2026-8977

MEDIUM CVSS 6.4 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8895 - Kk Blog Card Plugin

The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blog-card' shortcode in all versions up to, and including, 1.3. This is due to insufficient input sanitization and output escaping on the shortcode's 'href' and 'type' attributes, which are concatenated directly into HTML attribute contexts in the shortcode callback registered in kk-blog-card-shortcode.php. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Kk Blog Card

CVE-2026-8895

MEDIUM CVSS 6.4 2026-06-09
Threat Entry Updated 2026-06-17

CVE-2026-8910 - Wp Emoticon Rating Plugin

The WP Emoticon Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Emoticon Rating

CVE-2026-8910

MEDIUM CVSS 6.1 2026-06-09
Scroll to top