Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,552
Critical939
High3,155
Medium11,241
Reset
Showing 1901-1920 of 15552 records
Threat Entry Updated 2026-02-27

CVE-2025-14149 - Widgets For Elementor Plugin

The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Scroller widget box link attribute in all versions up to, and including, 1.4.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Widgets For Elementor

CVE-2025-14149

MEDIUM CVSS 6.4 2026-02-27
Threat Entry Updated 2026-06-17

CVE-2026-1558 - Wp Recipe Maker Plugin

The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, and including, 10.3.2. This is due to the /wp-json/wp-recipe-maker/v1/integrations/instacart REST API endpoint's permission_callback being set to __return_true and a lack of subsequent authorization or ownership checks on the user-supplied recipeId. This makes it possible for unauthenticated attackers to overwrite arbitrary post metadata (wprm_instacart_combinations) for any post ID on the site via the recipeId parameter.

PLUGIN Wp Recipe Maker

CVE-2026-1558

MEDIUM CVSS 5.3 2026-02-27
Threat Entry Updated 2026-06-17

CVE-2026-2428 - Fluent Forms Pro Add On Pack Plugin

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.1.17. This is due to the PayPal IPN (Instant Payment Notification) verification being disabled by default (`disable_ipn_verification` defaults to `'yes'` in `PayPalSettings.php`). This makes it possible for unauthenticated attackers to send forged PayPal IPN notifications to the publicly accessible IPN endpoint, marking unpaid form submissions as "paid" and triggering post-payment automation (emails, access grants, digital product delivery).

PLUGIN Fluent Forms Pro Add On Pack

CVE-2026-2428

HIGH CVSS 7.5 2026-02-27
Threat Entry Updated 2026-06-17

CVE-2026-1565 - User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration Plugin

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admin_Tools::check_filetype_and_ext' function in all versions up to, and including, 4.2.8. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration

CVE-2026-1565

HIGH CVSS 8.8 2026-02-26
Threat Entry Updated 2026-06-17

CVE-2026-28131 - Elementor Addon Elements Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder allows Retrieve Embedded Sensitive Data.This issue affects Elementor Addon Elements: from n/a through

PLUGIN Elementor Addon Elements

CVE-2026-28131

MEDIUM CVSS 6.5 2026-02-26
Threat Entry Updated 2026-06-17

CVE-2026-28132 - WooCommerce Plugin

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in villatheme WooCommerce Photo Reviews woocommerce-photo-reviews allows Code Injection.This issue affects WooCommerce Photo Reviews: from n/a through

PLUGIN WooCommerce

CVE-2026-28132

MEDIUM CVSS 5.3 2026-02-26
Threat Entry Updated 2026-06-17

CVE-2026-1311 - Worry Proof Backup Plugin

The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functionality. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload a malicious ZIP archive with path traversal sequences to write arbitrary files anywhere on the server, including executable PHP files. This can lead to remote code execution.

PLUGIN Worry Proof Backup

CVE-2026-1311

HIGH CVSS 8.8 2026-02-26
Threat Entry Updated 2026-06-17

CVE-2026-2356 - User Registration Plugin

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2 via the 'register_member' function, due to missing validation on the 'member_id' user controlled key. This makes it possible for unauthenticated attackers to delete arbitrary user accounts that newly registered on the site who has the 'urm_user_just_created' user meta set.

PLUGIN User Registration

CVE-2026-2356

MEDIUM CVSS 5.3 2026-02-26
Threat Entry Updated 2026-06-17

CVE-2026-1779 - User Registration Plugin

The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member' function. This makes it possible for unauthenticated attackers to log in a newly registered user on the site who has the 'urm_user_just_created' user meta set.

PLUGIN User Registration

CVE-2026-1779

HIGH CVSS 8.1 2026-02-26
Threat Entry Updated 2026-06-17

CVE-2026-2506 - Cost Calculator Plugin

The EM Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. This is due to the plugin storing attacker-controlled 'customer_name' data and rendering it in the admin customer list without output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the EMCC Customers page.

PLUGIN Cost Calculator

CVE-2026-2506

MEDIUM CVSS 6.1 2026-02-26
Threat Entry Updated 2026-06-17

CVE-2026-2499 - Custom Logo Plugin

The Custom Logo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Custom Logo

CVE-2026-2499

MEDIUM CVSS 4.4 2026-02-26
Threat Entry Updated 2026-06-17

CVE-2026-2498 - Wp Social Meta Plugin

The WP Social Meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Wp Social Meta

CVE-2026-2498

MEDIUM CVSS 4.4 2026-02-26
Threat Entry Updated 2026-06-17

CVE-2026-2029 - Addons For Beaver Builder Plugin

The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[labb_pricing_item]` shortcode's `title` and `value` attributes in all versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping. Specifically, the plugin uses `htmlspecialchars_decode()` after `wp_kses_post()`, which decodes HTML entities back into executable code after sanitization has occurred. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Addons For Beaver Builder

CVE-2026-2029

MEDIUM CVSS 6.4 2026-02-26
Threat Entry Updated 2026-06-17

CVE-2026-2489 - Tp2wp Importer Plugin

The TP2WP Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Watched domains' textarea on the attachment importer settings page in all versions up to, and including, 1.1. This is due to insufficient input sanitization and output escaping when domains are saved via AJAX and rendered with echo implode() without esc_textarea(). This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the attachment importer settings page.

PLUGIN Tp2wp Importer

CVE-2026-2489

MEDIUM CVSS 4.4 2026-02-26
Threat Entry Updated 2026-06-17

CVE-2026-27938 - Wp Graphql Plugin

WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository contains a GitHub Actions workflow (`release.yml`) vulnerable to OS command injection through direct use of `${{ github.event.pull_request.body }}` inside a `run:` shell block. When a pull request from `develop` to `master` is merged, the PR body is injected verbatim into a shell command, allowing arbitrary command execution on the Actions runner. Version 2.9.1 contains a fix for the vulnerability.

PLUGIN Wp Graphql

CVE-2026-27938

HIGH CVSS 7.7 2026-02-26
Threat Entry Updated 2026-06-17

CVE-2026-1557 - Wp Responsive Images Plugin

The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0 via the 'src' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Wp Responsive Images

CVE-2026-1557

HIGH CVSS 7.5 2026-02-26
Threat Entry Updated 2026-06-17

CVE-2026-2694 - The Events Calendar Plugin

The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all versions up to, and including, 6.15.16. This makes it possible for authenticated attackers, with Contributor-level access and above, to update or trash events, organizers and venues via REST API.

PLUGIN The Events Calendar

CVE-2026-2694

MEDIUM CVSS 5.4 2026-02-25
Threat Entry Updated 2026-06-17

CVE-2026-2367 - Secure Copy Content Protection Plugin

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ays_block' shortcode in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Secure Copy Content Protection

CVE-2026-2367

MEDIUM CVSS 6.4 2026-02-25
Threat Entry Updated 2026-06-17

CVE-2026-2410 - Disable Admin Notices Plugin

The Disable Admin Notices – Hide Dashboard Notifications plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing nonce validation in the `showPageContent()` function. This makes it possible for unauthenticated attackers to add arbitrary URLs to the blocked redirects list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Disable Admin Notices

CVE-2026-2410

MEDIUM CVSS 4.3 2026-02-25
Threat Entry Updated 2026-06-17

CVE-2026-2301 - Post Duplicator Plugin

The Post Duplicator plugin for WordPress is vulnerable to unauthorized arbitrary protected post meta insertion in all versions up to, and including, 3.0.8. This is due to the `duplicate_post()` function in `includes/api.php` using `$wpdb->insert()` directly to the `wp_postmeta` table instead of WordPress's standard `add_post_meta()` function, which would call `is_protected_meta()` to prevent lower-privileged users from setting protected meta keys (those starting with `_`). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary protected post meta keys such as `_wp_page_template`, `_wp_attached_file`, and other sensitive meta keys…

PLUGIN Post Duplicator

CVE-2026-2301

MEDIUM CVSS 4.3 2026-02-25
Scroll to top