Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,479
Critical934
High3,137
Medium11,193
Reset
Showing 801-820 of 15479 records
Threat Entry Updated 2026-06-17

CVE-2026-7052 - Ht Contactform Plugin

The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'file_upload' parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the 'Store Submissions' setting to be enabled, as this controls whether unsanitized field values are persisted to the database and subsequently rendered via…

PLUGIN Ht Contactform

CVE-2026-7052

HIGH CVSS 7.2 2026-05-28
Threat Entry Updated 2026-06-17

CVE-2026-6427 - A3 Lazy Load Plugin

The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.7.6 This is due to a regex bug in the _filter_videos() method that breaks HTML attribute quoting when processing crafted elements, combined with unescaped output in the admin/views/form-data.php template. An authenticated attacker with Contributor-level access can insert a crafted tag whose src attribute contains an embedded class=" substring that tricks the plugin's class-replacement regex into consuming an attribute-value closing quote. This shifts the HTML5 parser's quote boundary, promoting attacker-controlled text…

PLUGIN A3 Lazy Load

CVE-2026-6427

MEDIUM CVSS 6.4 2026-05-28
Threat Entry Updated 2026-06-17

CVE-2026-7552 - Geo Mashup Plugin

The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.13.19. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to expose sensitive plugin configuration data, including Google Maps API keys and GeoNames service credentials, to unauthenticated attackers.

PLUGIN Geo Mashup

CVE-2026-7552

MEDIUM CVSS 5.3 2026-05-28
Threat Entry Updated 2026-06-17

CVE-2026-7621 - Email Made Easy Plugin

The SMTP2GO for WordPress – Email Made Easy plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.16.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to truncate all SMTP2GO log records from the database or download a CSV export of all SMTP log data including recipient addresses, sender addresses, message subjects, and API response data.

PLUGIN Email Made Easy

CVE-2026-7621

MEDIUM CVSS 4.3 2026-05-28
Threat Entry Updated 2026-06-17

CVE-2026-9644 - Livesmart Video Chat Live Video Chat Plugin

The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livesmart_widget' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Livesmart Video Chat Live Video Chat

CVE-2026-9644

MEDIUM CVSS 6.4 2026-05-28
Threat Entry Updated 2026-06-17

CVE-2026-9009 - Crawlomatic Multipage Scraper Post Generator Plugin

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.2 via the filter_content function. This is due to passing the attacker-supplied 'callback_raw' shortcode attribute directly into call_user_func() with no sanitization or allowlist validation, relying solely on an is_callable() check that permits dangerous PHP built-ins such as system, shell_exec, exec, passthru, and assert. This makes it possible for authenticated attackers, with author-level access and above, to execute code on the server. An identical sink exists for the 'callback'…

PLUGIN Crawlomatic Multipage Scraper Post Generator

CVE-2026-9009

HIGH CVSS 8.8 2026-05-28
Threat Entry Updated 2026-06-17

CVE-2026-7533 - Easy Digital Downloads Plugin

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the `handle_oauth_redirect()` function, which is registered on the `admin_init` hook and processes Square OAuth tokens from a user-supplied GET parameter without any CSRF token validation. This makes it possible for unauthenticated attackers to overwrite the store's Square payment gateway credentials by tricking a logged-in administrator into clicking a crafted link, potentially resulting in payment account hijacking.

PLUGIN Easy Digital Downloads

CVE-2026-7533

MEDIUM CVSS 4.3 2026-05-28
Threat Entry Updated 2026-06-17

CVE-2026-3173 - Display A Meta Field As Block Plugin

The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.5.1. This is due to the plugin allowing users to specify arbitrary object IDs and object types via block attributes without validating whether the authenticated user has permission to access the requested object's metadata. This makes it possible for authenticated attackers, with Contributor-level access and above, to read arbitrary user meta, post meta, and term meta data from any object in the database. On sites using plugins that store…

PLUGIN Display A Meta Field As Block

CVE-2026-3173

MEDIUM CVSS 6.5 2026-05-28
Threat Entry Updated 2026-06-17

CVE-2026-9241 - Woocommerce Currency Switcher Plugin

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 1.4.6. This is due to the `get_value()` function in `classes/fixed/fixed_user_role.php` trusting the attacker-controlled `$_REQUEST['wooc_order_user_roles']` parameter to determine the user's role context for role-based price resolution without any validation, allowing it to override the legitimate role data derived from the authenticated user's session object via `$user->roles`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to impersonate higher-privileged roles — such as…

PLUGIN Woocommerce Currency Switcher

CVE-2026-9241

MEDIUM CVSS 4.3 2026-05-28
Threat Entry Updated 2026-06-17

CVE-2026-9228 - Mp Timetable Plugin

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 via the action_get_event_data due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to enumerate timeslot IDs and read the full WP_Post object — including post_content, post_excerpt, post_status, and post_author — of draft, pending, and private mp-event posts belonging to other users, along with their associated raw timeslot descriptions.

PLUGIN Mp Timetable

CVE-2026-9228

MEDIUM CVSS 4.3 2026-05-28
Threat Entry Updated 2026-06-17

CVE-2026-7802 - Acf Frontend Form Element Plugin

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite an administrator's user_pass, user_email, first_name, last_name, and other profile fields by supplying an arbitrary ?user_id= value, enabling full administrator account takeover via direct password replacement or email-redirect password reset. Exploitation requires the targeted Edit-User form to have…

PLUGIN Acf Frontend Form Element

CVE-2026-7802

HIGH CVSS 8.8 2026-05-28
Threat Entry Updated 2026-06-17

CVE-2026-5737 - Independent Analytics Plugin

The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.14.9. This is due to a public tracking route at /wp-json/iawp/search that accepts attacker-controlled referrer_url values when the signature matches, combined with a scheduled favicon fetcher that performs unrestricted cURL requests to stored domains. The signature validation is insufficient because the signature is embedded in publicly-accessible JavaScript and the salt is static per site, allowing attackers to extract valid signatures. The favicon downloader uses raw cURL functions without any SSRF protection…

PLUGIN Independent Analytics

CVE-2026-5737

MEDIUM CVSS 6.5 2026-05-28
Threat Entry Updated 2026-06-17

CVE-2026-2374 - Login Recaptcha Plugin

The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_SELF']` superglobal in all versions up to, and including, 1.8.0. This is due to the `authenticate()` function storing the unsanitized output of `basename($_SERVER['PHP_SELF'])` in the `login_nocaptcha_error` WordPress option when a login attempt is made from a non-standard login page (e.g., xmlrpc.php). The `admin_notices()` function then echoes this stored value directly into the admin dashboard HTML without escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute when an administrator…

PLUGIN Login Recaptcha

CVE-2026-2374

HIGH CVSS 7.2 2026-05-28
Threat Entry Updated 2026-06-17

CVE-2026-4888 - Everest Forms Plugin

The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 3.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send test emails to arbitrary addresses from the server.

PLUGIN Everest Forms

CVE-2026-4888

MEDIUM CVSS 4.3 2026-05-28
Threat Entry Updated 2026-06-17

CVE-2026-49053 - Elementor Plugin

Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.

PLUGIN Elementor

CVE-2026-49053

MEDIUM CVSS 5.3 2026-05-27
Threat Entry Updated 2026-06-17

CVE-2026-49052 - Elementor Plugin

Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.

PLUGIN Elementor

CVE-2026-49052

MEDIUM CVSS 4.3 2026-05-27
Threat Entry Updated 2026-06-17

CVE-2026-42728 - Contact Form 7 Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Contact Form 7 ht-contactform allows Stored XSS.This issue affects HT Contact Form 7: from n/a through

PLUGIN Contact Form 7

CVE-2026-42728

HIGH CVSS 7.1 2026-05-27
Threat Entry Updated 2026-06-17

CVE-2026-3349 - Minhnhut Link Gateway Plugin

The MinhNhut Link Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter on the redirect page in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Minhnhut Link Gateway

CVE-2026-3349

MEDIUM CVSS 6.1 2026-05-27
Threat Entry Updated 2026-06-17

CVE-2026-3348 - Minhnhut Link Gateway Plugin

The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings (Description, Title, and other fields) in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the redirect page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Minhnhut Link Gateway

CVE-2026-3348

MEDIUM CVSS 4.4 2026-05-27
Threat Entry Updated 2026-06-17

CVE-2026-2288 - Mylinksdump Plugin

The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_title' parameter in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Mylinksdump

CVE-2026-2288

MEDIUM CVSS 4.8 2026-05-27
Scroll to top