Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total15,556
Critical940
High3,160
Medium11,245
Reset
Showing 1921-1940 of 15556 records
Threat Entry Updated 2026-06-17

CVE-2026-2694 - The Events Calendar Plugin

The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all versions up to, and including, 6.15.16. This makes it possible for authenticated attackers, with Contributor-level access and above, to update or trash events, organizers and venues via REST API.

PLUGIN The Events Calendar

CVE-2026-2694

MEDIUM CVSS 5.4 2026-02-25
Threat Entry Updated 2026-06-17

CVE-2026-2367 - Secure Copy Content Protection Plugin

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ays_block' shortcode in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Secure Copy Content Protection

CVE-2026-2367

MEDIUM CVSS 6.4 2026-02-25
Threat Entry Updated 2026-06-17

CVE-2026-2410 - Disable Admin Notices Plugin

The Disable Admin Notices – Hide Dashboard Notifications plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing nonce validation in the `showPageContent()` function. This makes it possible for unauthenticated attackers to add arbitrary URLs to the blocked redirects list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Disable Admin Notices

CVE-2026-2410

MEDIUM CVSS 4.3 2026-02-25
Threat Entry Updated 2026-06-17

CVE-2026-2301 - Post Duplicator Plugin

The Post Duplicator plugin for WordPress is vulnerable to unauthorized arbitrary protected post meta insertion in all versions up to, and including, 3.0.8. This is due to the `duplicate_post()` function in `includes/api.php` using `$wpdb->insert()` directly to the `wp_postmeta` table instead of WordPress's standard `add_post_meta()` function, which would call `is_protected_meta()` to prevent lower-privileged users from setting protected meta keys (those starting with `_`). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary protected post meta keys such as `_wp_page_template`, `_wp_attached_file`, and other sensitive meta keys…

PLUGIN Post Duplicator

CVE-2026-2301

MEDIUM CVSS 4.3 2026-02-25
Threat Entry Updated 2026-02-25

CVE-2025-14742 - Wp Recipe Maker Plugin

The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ajax_search_recipes' and 'ajax_get_recipe' functions in all versions up to, and including, 10.2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive recipe information including draft, pending, and private recipes that they shouldn't be able to access.

PLUGIN Wp Recipe Maker

CVE-2025-14742

MEDIUM CVSS 4.3 2026-02-25
Threat Entry Updated 2026-06-17

CVE-2026-1929 - Advanced Woo Labels Plugin

The Advanced Woo Labels plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.37. This is due to the use of `call_user_func_array()` with user-controlled callback and parameters in the `get_select_option_values()` AJAX handler without an allowlist of permitted callbacks or a capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP functions and operating system commands on the server via the 'callback' parameter.

PLUGIN Advanced Woo Labels

CVE-2026-1929

HIGH CVSS 8.8 2026-02-25
Threat Entry Updated 2026-06-17

CVE-2026-2416 - Geo Mashup Plugin

The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Geo Mashup

CVE-2026-2416

HIGH CVSS 7.5 2026-02-25
Threat Entry Updated 2026-06-17

CVE-2026-2479 - Responsive Lightbox Plugin

The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.1. This is due to the use of `strpos()` for substring-based hostname validation instead of strict host comparison in the `ajax_upload_image()` function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application, which can be used to query and modify information from internal services.

PLUGIN Responsive Lightbox

CVE-2026-2479

MEDIUM CVSS 5.0 2026-02-25
Threat Entry Updated 2026-06-17

CVE-2026-1916 - Spreadsheet Integration Plugin

The WPGSI: Spreadsheet Integration plugin for WordPress is vulnerable to unauthorized modification and loss of data due to missing capability checks and an insecure authentication mechanism on the `wpgsi_callBackFuncAccept` and `wpgsi_callBackFuncUpdate` REST API functions in all versions up to, and including, 3.8.3. Both REST endpoints use `permission_callback => '__return_true'`, allowing unauthenticated access. The plugin's custom token-based validation relies on a Base64-encoded JSON object containing the user ID and email address, but is not cryptographically signed. This makes it possible for unauthenticated attackers to forge tokens using publicly enumerable information (admin…

PLUGIN Spreadsheet Integration

CVE-2026-1916

HIGH CVSS 7.5 2026-02-25
Threat Entry Updated 2026-06-17

CVE-2026-1614 - Rise Blocks Plugin

The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘logoTag’ Site Identity block attribute in all versions up to, and including, 3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Rise Blocks

CVE-2026-1614

MEDIUM CVSS 6.4 2026-02-25
Threat Entry Updated 2026-02-24

CVE-2025-15386 - Before 2 Plugin

The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved.

PLUGIN Before 2

CVE-2025-15386

HIGH CVSS 8.8 2026-02-24
Threat Entry Updated 2026-06-17

CVE-2026-23693 - Elementskit Lite Plugin

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe without authentication. The endpoint accepts client-supplied Mailchimp API credentials and insufficiently validates certain parameters, including the list parameter, when constructing upstream Mailchimp API requests. An unauthenticated attacker can abuse the endpoint as an open proxy to Mailchimp, potentially triggering unauthorized API calls, manipulating subscription data, exhausting API quotas, or causing resource consumption on the affected WordPress site.

PLUGIN Elementskit Lite

CVE-2026-23693

CRITICAL CVSS 9.3 2026-02-23
Threat Entry Updated 2026-06-17

CVE-2026-23694 - Aruba Hispeed Cache Plugin

Aruba HiSpeed Cache (aruba-hispeed-cache) WordPress plugin versions prior to 3.0.5 contain a cross-site request forgery (CSRF) vulnerability affecting multiple administrative AJAX actions. The handlers for ahsc_reset_options, ahsc_debug_status, and ahsc_enable_purge perform authentication and capability checks but do not verify a WordPress nonce for state-changing requests. An attacker can induce a logged-in administrator to visit a malicious webpage that submits forged requests to admin-ajax.php, resulting in unauthorized resetting of plugin settings, toggling of the WordPress WP_DEBUG configuration, or modification of cache purging behavior without the administrator’s intent.

PLUGIN Aruba Hispeed Cache

CVE-2026-23694

MEDIUM CVSS 5.1 2026-02-23
Threat Entry Updated 2026-06-17

CVE-2026-2385 - Woocommerce Plugin

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.4.7. This is due to the plugin decrypting and trusting attacker-controlled email_data in an unauthenticated AJAX handler without cryptographic authenticity guarantees. This makes it possible for unauthenticated attackers to tamper with form email routing and redirection values to trigger unauthorized email relay and attacker-controlled redirection via the 'email_data' parameter.

PLUGIN Woocommerce

CVE-2026-2385

MEDIUM CVSS 5.3 2026-02-22
Threat Entry Updated 2026-06-17

CVE-2026-1787 - LearnPress – Backup & Migration Tool Plugin

The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_migrated_data' function in all versions up to, and including, 4.1.0. This makes it possible for unauthenticated attackers to delete course that have been migrated from Tutor LMS. The Tutor LMS plugin must be installed and activated in order to exploit the vulnerability.

PLUGIN LearnPress – Backup & Migration Tool

CVE-2026-1787

MEDIUM CVSS 4.8 2026-02-21
Threat Entry Updated 2026-02-23

CVE-2025-14339 - And Automation Plugin

The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to unauthorized form deletion in all versions up to, and including, 2.0.7. This is due to the `Forms::permission()` callback only validating the `X-WP-Nonce` header without checking user capabilities. Since the REST nonce is exposed to unauthenticated visitors via the `weMail` JavaScript object on pages with weMail forms, any unauthenticated user can permanently delete all weMail forms by extracting the nonce from the page source and sending a DELETE request to…

PLUGIN And Automation

CVE-2025-14339

MEDIUM CVSS 6.5 2026-02-21
Threat Entry Updated 2026-06-17

CVE-2026-24956 - Download Manager Addons for Elementor Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada Download Manager Addons for Elementor wpdm-elementor allows Blind SQL Injection.This issue affects Download Manager Addons for Elementor: from n/a through

PLUGIN Download Manager Addons for Elementor

CVE-2026-24956

CRITICAL CVSS 9.3 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-24946 - Print Invoice & Delivery Notes for WooCommerce Plugin

Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through

PLUGIN Print Invoice & Delivery Notes for WooCommerce

CVE-2026-24946

MEDIUM CVSS 6.5 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22354 - Woocommerce Category Banner Management Plugin

Deserialization of Untrusted Data vulnerability in Dotstore Woocommerce Category Banner Management banner-management-for-woocommerce allows Object Injection.This issue affects Woocommerce Category Banner Management: from n/a through

PLUGIN Woocommerce Category Banner Management

CVE-2026-22354

HIGH CVSS 8.8 2026-02-20
Scroll to top