Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,552
Critical939
High3,155
Medium11,241
Reset
Showing 1821-1840 of 15552 records
Threat Entry Updated 2026-06-17

CVE-2026-2722 - Stock Ticker Plugin

The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.26.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Stock Ticker

CVE-2026-2722

MEDIUM CVSS 4.8 2026-03-07
Threat Entry Updated 2026-06-17

CVE-2026-2020 - Jquery Archive List Widget Plugin

The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1.7 via the 'included' shortcode attribute. This is due to the deserialization of untrusted input supplied via the 'included' parameter of the plugin's shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could…

PLUGIN Jquery Archive List Widget

CVE-2026-2020

HIGH CVSS 7.5 2026-03-07
Threat Entry Updated 2026-06-17

CVE-2026-2431 - Cm Custom Reports Plugin

The CM Custom Reports plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_from' and 'date_to' parameters in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Cm Custom Reports

CVE-2026-2431

MEDIUM CVSS 6.1 2026-03-07
Threat Entry Updated 2026-06-17

CVE-2026-2429 - Community Events Plugin

The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'ce_venue_name' CSV field in the `on_save_changes_venues` function in all versions up to, and including, 1.5.8. This is due to insufficient escaping on the user-supplied CSV data and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database via a crafted CSV file upload.

PLUGIN Community Events

CVE-2026-2429

MEDIUM CVSS 4.9 2026-03-07
Threat Entry Updated 2026-06-17

CVE-2026-2721 - Mailarchiver Plugin

The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Mailarchiver

CVE-2026-2721

MEDIUM CVSS 4.8 2026-03-07
Threat Entry Updated 2026-06-17

CVE-2026-2494 - ProfileGrid – User Profiles, Groups and Communities Plugin

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.8.2. This is due to missing nonce validation on the membership request management page (approve and decline actions). This makes it possible for unauthenticated attackers to approve or deny group membership requests via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN ProfileGrid – User Profiles, Groups and Communities

CVE-2026-2494

MEDIUM CVSS 4.3 2026-03-07
Threat Entry Updated 2026-06-17

CVE-2026-2488 - ProfileGrid – User Profiles, Groups and Communities Plugin

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message deletion due to a missing capability check on the pg_delete_msg() function in all versions up to, and including, 5.9.8.1. This is due to the function not verifying that the requesting user has permission to delete the targeted message. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary messages belonging to any user by sending a direct request with a valid message ID (mid parameter).

PLUGIN ProfileGrid – User Profiles, Groups and Communities

CVE-2026-2488

MEDIUM CVSS 4.3 2026-03-07
Threat Entry Updated 2026-06-17

CVE-2026-1902 - Hammas Calendar Plugin

The Hammas Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'apix' parameter in the 'hp-calendar-manage-redirect' shortcode in all versions up to, and including, 1.5.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Hammas Calendar

CVE-2026-1902

MEDIUM CVSS 6.4 2026-03-07
Threat Entry Updated 2026-06-17

CVE-2026-1650 - Mdjm Event Management Plugin

The MDJM Event Management plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'custom_fields_controller' function in all versions up to, and including, 1.7.8.1. This makes it possible for unauthenticated attackers to delete arbitrary custom event fields via the 'delete_custom_field' and 'id' parameters.

PLUGIN Mdjm Event Management

CVE-2026-1650

MEDIUM CVSS 5.3 2026-03-07
Threat Entry Updated 2026-06-17

CVE-2026-2371 - Animation And Page Builder Blocks Plugin

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 12.8.3. This is due to missing authorization and post status validation in the `gspb_el_reusable_load()` AJAX handler. The handler accepts an arbitrary `post_id` parameter and renders the content of any `wp_block` post without checking `current_user_can('read_post', $post_id)` or verifying the post status. Combined with the nonce being exposed to unauthenticated users on any public page using the `[wp_reusable_render]` shortcode with `ajax="1"`, this makes it possible for unauthenticated…

PLUGIN Animation And Page Builder Blocks

CVE-2026-2371

MEDIUM CVSS 5.3 2026-03-07
Threat Entry Updated 2026-06-17

CVE-2026-1981 - HUMN-1 AI Website Scanner & Human Certification by Winston AI Plugin

The HUMN-1 AI Website Scanner & Human Certification by Winston AI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the winston_disconnect() function in all versions up to, and including, 0.0.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the plugin's API connection settings via the 'winston_disconnect' AJAX action.

PLUGIN HUMN-1 AI Website Scanner & Human Certification by Winston AI

CVE-2026-1981

MEDIUM CVSS 4.3 2026-03-07
Threat Entry Updated 2026-06-17

CVE-2026-1644 - Wp Front End Profile Plugin

The WP Frontend Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.8. This is due to missing nonce validation on the 'update_action' function. This makes it possible for unauthenticated attackers to approve or reject user account registrations via a forged request granted they can trick an administrator into performing an action such as clicking on a link.

PLUGIN Wp Front End Profile

CVE-2026-1644

MEDIUM CVSS 4.3 2026-03-07
Threat Entry Updated 2026-06-17

CVE-2026-3589 - From Versions 5 Plugin

The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allow unauthenticated users to make a logged in admin call non store/WC REST endpoints, and create arbitrary admin users via a CSRF attack for example.

PLUGIN From Versions 5

CVE-2026-3589

HIGH CVSS 7.5 2026-03-06
Threat Entry Updated 2026-06-17

CVE-2026-2830 - Google Sheets Plugin

The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filepath’ parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Google Sheets

CVE-2026-2830

MEDIUM CVSS 6.1 2026-03-06
Threat Entry Updated 2026-06-17

CVE-2026-2446 - Powerpack For Learndash Plugin

The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress options (such as default_role etc) and create arbitrary admin users

PLUGIN Powerpack For Learndash

CVE-2026-2446

CRITICAL CVSS 9.8 2026-03-06
Threat Entry Updated 2026-06-17

CVE-2026-1128 - Wp Ecommerce Plugin

The WP eCommerce WordPress plugin through 3.15.1 does not have CSRF check in place when deleting coupons, which could allow attackers to make a logged in admin remove them via a CSRF attack

PLUGIN Wp Ecommerce

CVE-2026-1128

MEDIUM CVSS 4.3 2026-03-06
Threat Entry Updated 2026-06-17

CVE-2026-2589 - Animation And Page Builder Blocks Plugin

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 12.8.3 via the automated Settings Backup stored in a publicly accessible file. This makes it possible for unauthenticated attackers to extract sensitive data including the configured OpenAI, Claude, Google Maps, Gemini, DeepSeek, and Cloudflare Turnstile API keys.

PLUGIN Animation And Page Builder Blocks

CVE-2026-2589

MEDIUM CVSS 5.3 2026-03-06
Threat Entry Updated 2026-06-17

CVE-2026-2593 - Greenshift – animation and page builder blocks Plugin

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_gspb_post_css` post meta value and the `dynamicAttributes` block attribute in all versions up to, and including, 12.8.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Greenshift – animation and page builder blocks

CVE-2026-2593

MEDIUM CVSS 6.4 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-3459 - Drag And Drop Multiple File Upload Contact Form 7 Plugin

The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. This can be exploited if the form includes a multiple file upload field with ‘*’ as the accepted file type.

PLUGIN Drag And Drop Multiple File Upload Contact Form 7

CVE-2026-3459

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-1720 - Create Stunning Popups And Optins For Lead Generation Plugin

The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the 'install_and_active_plugin' function in all versions up to, and including, 1.4.24. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins.

PLUGIN Create Stunning Popups And Optins For Lead Generation

CVE-2026-1720

HIGH CVSS 8.8 2026-03-05
Scroll to top