Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,479
Critical934
High3,137
Medium11,193
Reset
Showing 961-980 of 15479 records
Threat Entry Updated 2026-06-17

CVE-2026-8912 - Contest Gallery Plugin

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query inside the unauthenticated 'post_cg_gallery_form_upload' AJAX action (specifically the 'cb' branch of the included users-upload-check.php, where $f_input_id is concatenated unquoted into 'SELECT Field_Content FROM ... WHERE id = $f_input_id'). The endpoint is gated only by a public frontend nonce ('cg1l_action' / 'cg_nonce') that is exposed in the page…

PLUGIN Contest Gallery

CVE-2026-8912

HIGH CVSS 7.5 2026-05-19
Threat Entry Updated 2026-06-17

CVE-2026-4883 - Piotnet Forms Plugin

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including, 2.1.40. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be uploaded. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The exploit can only be exploited if…

PLUGIN Piotnet Forms

CVE-2026-4883

CRITICAL CVSS 9.8 2026-05-19
Threat Entry Updated 2026-06-17

CVE-2026-4885 - Piotnet Addons For Elementor Pro Plugin

The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be uploaded. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The exploit can only…

PLUGIN Piotnet Addons For Elementor Pro

CVE-2026-4885

CRITICAL CVSS 9.8 2026-05-19
Threat Entry Updated 2026-06-17

CVE-2026-3220 - Clearfy Cache Plugin

The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.

PLUGIN Clearfy Cache

CVE-2026-3220

HIGH CVSS 8.8 2026-05-18
Threat Entry Updated 2026-06-17

CVE-2026-6379 - Wp Photo Album Plus Plugin

The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

PLUGIN Wp Photo Album Plus

CVE-2026-6379

HIGH CVSS 8.6 2026-05-18
Threat Entry Updated 2026-06-17

CVE-2026-6381 - Wp Maps Plugin

The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks.

PLUGIN Wp Maps

CVE-2026-6381

HIGH CVSS 7.5 2026-05-18
Threat Entry Updated 2026-06-17

CVE-2026-6495 - Ajax Load More Plugin

The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Ajax Load More

CVE-2026-6495

HIGH CVSS 7.1 2026-05-18
Threat Entry Updated 2026-06-17

CVE-2026-1631 - Before 2 Plugin

The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is vulnerable to unauthorized modification of the Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4's license key due to a missing capability check on the 'actions' function. This makes it possible for subscribers and above delete the license key.

PLUGIN Before 2

CVE-2026-1631

MEDIUM CVSS 5.4 2026-05-18
Threat Entry Updated 2026-06-17

CVE-2026-8719 - For Wordpress Is Vulnerable To Privilege Escalation In Version 3 Plugin

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be granted without verifying administrator privileges. This makes it possible for authenticated (Subscriber+) attackers to invoke admin-level MCP tools and escalate privileges to Administrator.

PLUGIN For Wordpress Is Vulnerable To Privilege Escalation In Version 3

CVE-2026-8719

HIGH CVSS 8.8 2026-05-17
Threat Entry Updated 2026-06-17

CVE-2026-8681 - Essential Chat Support Plugin

The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to reset all plugin configuration settings — including general settings, display rules, custom CSS, and WooCommerce tab settings — to their defaults by sending a POST request with ecs_reset_settings=1.

PLUGIN Essential Chat Support

CVE-2026-8681

MEDIUM CVSS 5.3 2026-05-16
Threat Entry Updated 2026-06-17

CVE-2026-6415 - Advanced Custom Fields Font Awesome Plugin

The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.0.2. This is due to insufficient input validation of JSON field values and unsafe client-side HTML construction in the update_preview() JavaScript function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Advanced Custom Fields Font Awesome

CVE-2026-6415

MEDIUM CVSS 6.4 2026-05-15
Threat Entry Updated 2026-06-17

CVE-2026-7046 - Nex Forms Express Wp Form Builder Plugin

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'table' parameter in all versions up to, and including, 9.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Nex Forms Express Wp Form Builder

CVE-2026-7046

MEDIUM CVSS 4.9 2026-05-15
Threat Entry Updated 2026-06-17

CVE-2026-8425 - Notify Odoo Plugin

The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the _updateSettings function. This makes it possible for unauthenticated attackers to change the Notify Odoo URL to an attacker-controlled URL and modify notification, tracking image, and allowed IP address settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Notify Odoo

CVE-2026-8425

MEDIUM CVSS 4.3 2026-05-15
Threat Entry Updated 2026-06-17

CVE-2026-7563 - Business Directory Plugin

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.3.10. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to add arbitrary notes to any order and trigger unsolicited notification and moderation emails to listing owners without administrative authorization.

PLUGIN Business Directory

CVE-2026-7563

MEDIUM CVSS 4.3 2026-05-15
Threat Entry Updated 2026-06-17

CVE-2026-5229 - Form Notify Plugin

The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting user-controlled cookie data to determine which WordPress account to authenticate after a LINE OAuth login. When LINE doesn't provide an email address (which is common), the plugin falls back to reading the 'form_notify_line_email' cookie value without verifying that the LINE account is associated with that email address. This makes it possible for unauthenticated attackers to gain access to any user account on the site, including…

PLUGIN Form Notify

CVE-2026-5229

CRITICAL CVSS 9.8 2026-05-15
Threat Entry Updated 2026-06-17

CVE-2026-6228 - Acf Frontend Form Element Plugin

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to insufficient authorization checks in the role field update mechanism combined with overly permissive capabilities for the admin_form post type. The admin_form custom post type uses 'capability_type' => 'page', which grants editors the ability to create and edit forms. When an editor creates an edit_user form, they can manipulate the form configuration to include 'administrator' in the role_options array by directly submitting POST data to wp-admin/post.php, bypassing…

PLUGIN Acf Frontend Form Element

CVE-2026-6228

HIGH CVSS 8.8 2026-05-15
Threat Entry Updated 2026-06-17

CVE-2026-6403 - Quick Playground Plugin

The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is due to insufficient path validation in the qckply_zip_theme() function, which appends a user-controlled 'stylesheet' parameter directly to the theme root directory path without sanitizing directory traversal sequences. This makes it possible for unauthenticated attackers to trigger the creation of a ZIP archive containing arbitrary files from the server's filesystem — including wp-config.

PLUGIN Quick Playground

CVE-2026-6403

HIGH CVSS 7.5 2026-05-15
Threat Entry Updated 2026-06-17

CVE-2026-4683 - Smartcat Translator For Wpml Plugin

The Smartcat Translator for WPML plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'routeData' REST endpoint in all versions up to, and including, 3.1.77. This makes it possible for unauthenticated attackers to overwrite the plugin's Smartcat API credentials (account ID, API secret key, hub key, API host, and hub host), effectively hijacking the translation service or causing a denial of service.

PLUGIN Smartcat Translator For Wpml

CVE-2026-4683

MEDIUM CVSS 6.5 2026-05-15
Threat Entry Updated 2026-06-17

CVE-2026-4094 - Currency Switcher Professional For Woocommerce Plugin

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete the entire multi-currency configuration by visiting any wp-admin page with the `woocs_reset` parameter appended. Additionally, because no nonce is verified, this is also exploitable via Cross-Site Request Forgery against any administrator. The vulnerability may also be exploited by Subscriber-level users if…

PLUGIN Currency Switcher Professional For Woocommerce

CVE-2026-4094

HIGH CVSS 8.1 2026-05-15
Threat Entry Updated 2026-06-17

CVE-2026-6646 - Dt The7 Plugin

The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all versions up to, and including, 14.3.2. This is due to insufficient input sanitization and output escaping on the 'title' component of the 'link' shortcode parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Dt The7

CVE-2026-6646

MEDIUM CVSS 6.4 2026-05-15
Scroll to top